Standardized inventory of every contractual arrangement for information technology services, maintained by each financial entity and filed with its supervisor, the basis of the European dependency map.
You cannot supervise a concentration you cannot see. Before DORA, no supervisor knew how many European insurers depended on the same cloud provider for the same critical function, and each entity often did not know it for its own subcontracting chain beyond the first tier. The register of information corrects that through a prescribed-format inventory: identification of the provider by a standardized code, function served, whether that function is critical or important, country of provision and of data storage, subcontracting chain, contract end date, exit strategy. Each entity keeps it current and files it with its competent authority, which forwards it to the European supervisory authorities. That flow feeds the designation of critical providers placed under direct oversight. The practical difficulty treated as secondary turned out to be central: correctly identifying each provider by a unique identifier, and reconstructing second-tier and deeper subcontractors, presupposes contractual information many entities had never collected.
Regulation (EU) 2022/2554, applicable since January 17, 2025, supplemented by an implementing technical standard setting the register's format. The first 2025 filings confirmed what the text set out to measure: a large share of the European financial sector's critical functions rests on a very small number of hosting providers, and the second-tier subcontracting chain remains the least well documented part of the returns.
register of information, registre des accords contractuels TIC, cartographie des prestataires, registre DORA