Back to Publications
Regulatory Brief · DORA

NexCyber DORA Register of Information — EBA ITS-compliant template (premium)

18 May 2026By NexCyber Editorial DORA

The Digital Operational Resilience Act (DORA) is reshaping the landscape for financial entities across the EU, mandating robust frameworks to withstand, respond to, and recover from ICT-related disruptions. A critical component of compliance is maintaining a comprehensive Register of Information on ICT third-party service providers, as outlined by the European Banking Authority's (EBA) Implementing Technical Standards (ITS). NexCyber offers a premium, fully populated DORA register template, meti

The Digital Operational Resilience Act (DORA) is reshaping the landscape for financial entities across the EU, mandating robust frameworks to withstand, respond to, and recover from ICT-related disruptions. A critical component of compliance is maintaining a comprehensive Register of Information on ICT third-party service providers, as outlined by the European Banking Authority's (EBA) Implementing Technical Standards (ITS). NexCyber offers a premium, fully populated DORA register template, meticulously crafted to align with the EBA ITS schema fields, complete with example entries for various supplier types and machine-readable export options.

Field-by-Field Guide to EBA ITS Required Fields

Understanding the intricacies of the EBA ITS schema is essential for creating a compliant Register of Information. This section provides a detailed guide to each required field, ensuring that financial entities can accurately populate their registers.

Identification and General Information

The register must include basic identification details for each ICT third-party service provider. This encompasses the provider's name, unique identifier, and contact information. Additionally, entities must specify the type of service provided, such as cloud services or data management.

Contractual Details

Entities are required to document the start and end dates of contracts, renewal terms, and any termination clauses. This information is crucial for understanding the duration and terms of the relationship with each provider.

Risk Assessment and Management

A comprehensive risk assessment for each provider must be included, detailing potential risks and the measures in place to mitigate them. This includes both inherent and residual risk ratings, as well as any risk mitigation strategies employed.

Performance and Incident Reporting

The register should capture performance metrics and incident reporting protocols. This involves documenting service level agreements (SLAs), performance indicators, and any historical incidents that have impacted service delivery.

Subcontracting Arrangements

When a provider uses subcontractors, entities must include details of these arrangements. This includes the names of subcontractors, the services they provide, and any associated risks.

Example Entries for Five Supplier Types

To facilitate a practical understanding of how to populate the register, we provide example entries for five common types of ICT third-party service providers: cloud services, SaaS, telecom, advisory, and data management.

Cloud Services Provider

For a cloud services provider, the register entry might include details such as the provider's name, the specific cloud services utilized (e.g., IaaS, PaaS), and the geographical location of data centers. Contractual terms, risk assessments, and SLAs should also be clearly documented.

SaaS Provider

A SaaS provider entry would detail the software applications in use, user access levels, and data protection measures. It is essential to include information on data residency and compliance with relevant data protection regulations.

Telecom Provider

Entries for telecom providers should specify the types of communication services provided, such as voice, data, or internet services. Contractual terms, network performance metrics, and incident response protocols are key components of this entry.

Advisory Services

For advisory services, the register should outline the scope of consultancy provided, including strategic, regulatory, or technical advice. Risk assessments should focus on the potential impact of advice on operational resilience.

Data Management Provider

A data management provider entry must include details on data storage solutions, data processing activities, and compliance with data protection laws. Risk assessments should address data integrity and availability.

Export Formats: JSON, XML, and Excel

NexCyber's DORA register template supports multiple export formats, ensuring compatibility with various systems and facilitating seamless data integration.

JSON Export

The JSON export format is ideal for entities looking to integrate their register data with other ICT systems. This machine-readable format supports automation and data analysis processes.

XML Export

XML export provides a structured format suitable for entities that require interoperability with legacy systems or specific regulatory reporting tools.

Excel Export

For those who prefer a more traditional approach, the Excel export format offers a user-friendly interface for reviewing and editing register data. This format is particularly useful for manual audits and reviews.

Submission Checklist: Pre-NCA Validation Steps

Before submitting the Register of Information to the National Competent Authority (NCA), financial entities must ensure compliance with several key validation steps.

Data Accuracy and Completeness

Verify that all required fields are accurately and completely filled out. Missing or incorrect data can lead to compliance issues and potential penalties.

Consistency with Internal Policies

Ensure that the register aligns with internal operational resilience policies and procedures. This includes verifying that risk assessments and mitigation strategies are consistent with organizational standards.

Review and Approval

Conduct a thorough review of the register by relevant stakeholders, such as the risk management and compliance teams. Obtain necessary approvals before submission to the NCA.

Technical Validation

Use NexCyber's pre-validation tools to check for technical compliance with the EBA ITS schema. This step helps identify and rectify any formatting or data integrity issues.

Next Step with NexCyber

To access the premium DORA register template, fully populated and pre-validated for NCA submission, financial entities can log in to their NexCyber account. Our platform provides seamless access to export options and ensures compliance with the latest regulatory standards. Visit [NexCyber](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=nexcyber-dora-register-template-2026) to download your template today.