Next DORA deadlineCyprus CySEC 28 Feb 2027

Your DORA register, built once and kept ready - not rebuilt every year.

Treica structures your ICT providers, contracts, functions, sub-outsourcing chains and evidence into one connected record. It validates that record against DORA rules, flags what could still attract supervisory attention, and produces your submission package in the format your authority accepts - all 15 tables and all 120 columns of the official taxonomy, not a convenient subset.

  • Deterministic validation
  • Every finding linked to a rule and a regulatory source
  • EU-region hosting
  • Read-only, time-boxed access for your auditor
RegisterReference date 31 Dectaxonomy 4.0 · ruleset v2
A register drawn as a graph of entities, arrangements, providers and subcontractorsTwo legal entities connect through four contractual arrangements to three ICT providers, which in turn connect to two subcontractors. Two arrangements from different entities reach the same provider, and two different providers subcontract to the same fourth party - concentration that only appears once the relationships are drawn.EntitiesArrangementsProvidersSubcontractors

Validation run

  • E-B0502-011Subcontractor named in B_05.02 with no matching provider
  • W-CTP-001Designated critical provider, clause coverage not assessed
  • W-SUB-001Two providers converge on one fourth party
  • A-EXT-004Exit strategy documented, last tested 19 months ago
Submission held while 1 blocking error is open

Competent authorities and filing dates held per entity

  • CySEC
  • CSSF
  • CAA
  • Central Bank of Ireland
  • DNB
  • AFM
  • BaFin
  • ACPR
  • MFSA
  • Banca d'Italia
  • CONSOB
  • IVASS
  • Banco de Espana / CNMV
  • NBB / FSMA
  • FMA
  • Banco de Portugal / CMVM
  • KNF
  • Finansinspektionen
  • Finanstilsynet
  • FIN-FSA
  • Bank of Greece / HCMC

The register is not a document. It is a set of relationships that has to stay consistent.

Everything above the diagram in the hero is one record. Every line in it is a claim that has to agree with another one.

Your register connects legal entities, ICT providers, the services they deliver, contractual arrangements, the functions those arrangements support, and the sub-outsourcing chains beneath them. Each of those links has to agree with the others.

When the data lives in spreadsheets, contracts, shared drives and email, the links break quietly. A provider is renamed in one place and not another. An arrangement supports a function that no one classified. A subcontractor exists in a contract but not in the register.

None of this shows up as a missing cell. It shows up as an inconsistency between tables - the kind a supervisor cross-references and asks about.

Spreadsheets fail at the relationships, not the row count.

The failure is never loud. That is what makes it expensive.

A spreadsheet can hold a few hundred rows without complaint. That is not where it breaks. It breaks because it cannot enforce the links between tables.

Nothing stops a provider being listed under two spellings, which understates your concentration. Nothing checks that an arrangement supporting a critical function actually names that function. Nothing records why a function was classified critical, or who confirmed it, or when. Nothing preserves what you filed last year so you can prove what changed.

So the data can look complete and still be internally inconsistent. The work of finding those inconsistencies falls on one person, under deadline, once a year.

One provider, three spellings
  • Tab: ProvidersNorthwind Cloud Services Ltd
  • Tab: ArrangementsNorthwind Cloud Svcs.counted separately
  • Tab: SubcontractingNORTHWIND CLOUDcounted separately

Every cell is filled in. Every tab validates. Your concentration in this provider is reported as a third of what it is, and nothing in the file says so.

A connected record of your ICT third-party arrangements, with the register as its output.

You maintain the source records. The register is generated from them.

Treica holds your third-party operating model as a single connected structure: providers, the services they deliver, the arrangements that consume those services, the functions the arrangements support, the sub-outsourcing chains, and the evidence behind each assertion.

The Register of Information is projected from that structure. You maintain the source records once; the register is generated from them, with each field traceable back to where it is governed.

When you file, the exact submitted version is frozen and kept, so you can always reproduce what the authority received.

All 15 tables. All 120 columns. Not a subset.

15
reporting tables
120
columns delivered

Most registers are built from a hand-written column list that was correct on the day someone typed it. Ours is generated from the official EBA reporting dictionary that ships inside the product, so the columns are the standard's columns, and they cannot quietly drift away from it.

That includes the judgement fields firms most often leave blank because a spreadsheet never asked for them: how substitutable an arrangement is and why, the reason a function is critical or important, the licenced activity it supports, the level of reliance on the provider, and the impact of discontinuing the arrangement. Coded fields are checked against the real enumerations at entry, so a value that would be rejected on filing is rejected while you can still do something about it.

Official EBA dictionary, module 1.1.0, in force from 2025-03-31. The product checks for a newer taxonomy on a schedule and tells us when one appears.

Reporting tables covered, with the number of columns in each
TableWhat it reportsCols
Entity maintaining the register of information6
List of entities within the scope of the register of information11
List of branches4
Contractual arrangements - General Information5
Contractual arrangements - Specific information18
List of intra-group contractual arrangements3
Entities signing the Contractual arrangements for receiving ICT service(s) or on behalf of the entities making use of the ICT service(s)3
ICT third-party service providers signing the Contractual arrangements for providing ICT service(s)3
Entities signing the Contractual arrangements for providing ICT service(s) to other entity within the scope of consolidation3
Entities making use of the ICT services4
ICT third-party service providers12
ICT service supply chains7
Functions identification10
Assessment of the ICT services12
Definitions from Entities making use of the ICT Services19
Delivered120

Construct, validate, resolve, file - then keep it current.

Five steps, and the fifth feeds the first. That loop is the difference between a platform and an annual project.

  1. Construct

    Import your existing register or build it record by record - with likely duplicate providers detected and arrangements mapped to services and functions.

  2. Validate

    Run deterministic validation. Errors that would block a filing are separated from warnings that could attract supervisory attention.

  3. Resolve

    Assign findings, attach evidence, and record your position where you choose not to act. Every finding links to its rule and regulatory source.

  4. File

    Generate the xBRL-CSV package for your authority, checked against documented structural rejection conditions before it leaves the system.

  5. Maintain

    Between filings, the platform tracks expiries, reviews and changes - so the next cycle starts from a current register, not a rebuild.

Some registers pass file validation and still raise questions. We flag those first.

Three severities, and only one of them stops a filing. The other two are what a free validator never says.

A structurally valid file is the starting point, not the finish. Free validators and the published check set confirm the format. They do not tell you where your register is likely to attract a supervisor’s attention.

Treica’s warning tier does. It flags patterns that pass technical validation but read as gaps to an examiner. Each warning prompts you to record your position, with a justification - turning an open question into evidence of active management.

  1. Error

    Blocks the filing

    A structural or referential condition the authority's parser rejects. Generation stays closed while one is open.

  2. Warning

    Attracts supervisory attention

    Passes technical validation and still reads as a gap to an examiner. Record your position and it becomes evidence of active management.

  3. Advisory

    Worth knowing

    Nothing is wrong. Something is thinner than it could be, and you decide whether that matters.

Warnings the ruleset raises

W-SUB-001

A major cloud provider declared with no sub-outsourcing.

W-EXT-002

An exit strategy documented but never tested.

W-CTP-001

A designated critical provider with no clause coverage assessed.

W-DAT-001

An arrangement involving personal data that does not state where that data is located.

Depth where the register is thinnest.

Sub-outsourcing & fourth parties

Map the chain to multiple tiers, check it for cycles, and record what the provider disclosed - so a gap becomes a substantiated position.

Evidence that stays provable

Every document is hashed on upload, and a weekly sweep recomputes it from the stored file - each document at least monthly, and any document the moment you ask. Its identity, uploader and timestamp cannot be edited afterwards, so evidence is verified rather than merely claimed.

An audit log an auditor can work in

Every create, update, delete, privileged action and record view, with the fields that changed and the state before and after. Filter by entity, action, person and period; export the result as CSV that tells you if it was truncated.

Entities and branches

Report the entity maintaining the register, every entity in scope, and their branches - each maintained as a record, not assembled by hand at filing time.

Contract governance

A DORA Article 30 obligation library and a clause-coverage review per arrangement. A missing clause raises a finding; adding it resolves the finding, so the contract review and the issue list are the same thing rather than two documents that disagree.

Due diligence, not a questionnaire graveyard

Versioned, scored assessment templates with reviewer approval, plus questionnaires you send to a provider and evidence requests you can chase - all landing on the record they belong to.

Findings and remediation

One findings model fed by validation, assessments, contract reviews and monitoring, with owned remediation actions and a recorded position where you decide not to act.

Submission generation

Generate the xBRL-CSV package against the correct taxonomy version, gated while any blocking error is open, and checked against structural rejection conditions.

Continuous maintenance

An attention dashboard surfaces expiries, overdue reviews and stale classifications, so the next cycle is maintenance, not reconstruction.

Multi-entity & group

Every entity's validation, filing and findings on one page, concentration analysed across the group, and each entity limited to the people who run it.

Built to be examined

Give your auditor read-only, time-boxed access and a 14-section evidence pack that assembles in under a minute, in the order a reviewer works.

One regulation. Not always one supervisor.

DORA applies identically in every member state, so the register itself does not change: the same 15 tables and 120 columns everywhere. What changes is who receives it, through which channel, and by when.

In 3 markets that is not a single answer. Italy, Luxembourg, Netherlands each have more than one authority taking a filing, split by what a firm is authorised as - and a register sent to the wrong supervisor is not a register that was filed. Treica holds the competent authority and the reporting date per entity, so a group filing in several countries keeps one connected picture.

Where a national authority sets no specific date, the ESA backstop of 31 March applies. Each country page states how well sourced its date is rather than presenting all of them as settled. Firms outside the EU and EEA, such as those in Switzerland or the United Kingdom, are not subject to DORA directly, but commonly appear inside an EU entity’s register as ICT third-party service providers.

Built to pass a demanding third-party review, because you will run one on us.

Every dependency we add becomes an entry in your own register. We treat that as a cost.

Every dependency we add becomes an entry in your own register. We treat that as a cost, and keep our external surface small.

Data is hosted in the EU. Access control is enforced at the data layer, not only in the interface, and each tenant is isolated in several layers. Sign-in uses a magic link with TOTP two-factor authentication. Evidence and generated packages are served through time-limited, non-guessable links. Administrative access is limited to a named allowlist of platform administrators and requires two-factor authentication.

The parts a reviewer usually has to ask for are published instead. Every sub-processor is listed with exactly what it receives. The rate limits are stated as numbers rather than as "reasonable use". And AI is off by default, requires an owner to switch it on, only ever suggests, and never writes to your register.

Hosting
EU region, for records, evidence and generated packages alike
Access control
Enforced at the data layer, not only in the interface
Tenant isolation
Several independent layers, not one check
Sign-in
Magic link with TOTP two-factor authentication
File delivery
Time-limited, non-guessable links
Platform admin
A named allowlist, two-factor required

Built for every EU financial entity that files a DORA register.

The people accountable for the register, and the groups filing for several entities at once.

Treica is for the teams accountable for the register: Heads of Compliance, Heads of Risk, Chief Risk Officers, DORA programme owners, and the operational and ICT risk people who maintain the data.

DORA applies the same way in every member state, so Treica is built for the whole obligation rather than one market: banks, investment firms, payment and electronic money institutions, insurers and reinsurers, fund managers, crypto-asset service providers and the other entity types in scope. What differs by country is the supervisor, the filing channel and the date - Treica holds those per entity, from BaFin and ACPR to Banca d’Italia, CONSOB, MFSA, CSSF, the Central Bank of Ireland, CNMV, KNF and CySEC.

Groups filing for several entities across several countries keep one connected picture and switch between entity registers, each with its own competent authority and deadline.

Advisory firms can construct a client’s register inside the platform and hand it over through a permission change alone - no export, no re-import, full history retained.

Priced by how many entities you report, not by what we withhold.

Every plan carries the whole of what makes a filing correct. What separates them is how many reporting entities you have, and how much governance you run around the register.

Register is the entry point: one regulated entity, complete and submission-ready. Governance is what the register is for - the continuous third-party work that keeps it ready between filings. Group consolidates that across entities and authorities.

Register

Entry point

€333/ month

€4,000 billed annually

About €11 a day

A complete, submission-ready DORA Register of Information for one regulated entity.

  • All 15 tables and all 120 columns
  • Full validation, submission package and filing history
  • Evidence with integrity verification
  • The complete audit trail

Governance

Recommended

€750/ month

€9,000 billed annually

About €25 a day

Continuous third-party governance around the register: assessments, contract coverage, remediation and monitoring.

  • Everything in Register
  • Assessments, questionnaires and evidence requests
  • Article 30 contract governance
  • Unified findings, remediation and risk acceptance
  • Concentration reporting, audit pack and the public API

Group

from€1,667/ month

From €20,000 billed annually

About €55 a day

Consolidated DORA governance and reporting across multiple regulated entities and authorities.

  • Everything in Governance
  • Consolidated status across every entity: validation, filing and findings
  • Concentration analysed across entities
  • Entities under more than one competent authority, each with its own filing convention
  • Delegated entity administration: limit a colleague to the entities they run

How a customer arrives

  1. Discovery call

    Thirty minutes on your entities, your supervisor and where the register stands today.

  2. Demonstration

    The real product against your situation, not a slide deck.

  3. Proposal

    Plan, entity count and implementation scope, priced and written down.

  4. Subscription

    Twelve months minimum, because DORA is an annual cycle.

  5. Implementation

    Import, mapping, duplicate detection, validation, findings review, remediation guidance and first filing setup.

What moves the number.

The figures above are floors, not quotes. What moves a real number is how many reporting entities you have and how much governance you run around the register, which is what the ladder is priced on. Implementation is quoted separately at €2,000 to €8,000, once, against a written scope - never bundled invisibly into a subscription and never open-ended.

Subscriptions run for a minimum of 12 months; DORA is an annual cycle, and a register that can be cancelled the month after a filing is not a register anybody maintains.

Implementation is where your existing register is imported and mapped, duplicate providers are found, the whole thing is validated, the findings are worked through with you, and the first filing is set up. We do that once you are a customer, not as a service sold beforehand.

Treica Assist, the optional AI add-on, is quoted separately and is available with Governance and Group. Regulatory validation and submission generation are deterministic and stay that way; Assist only ever suggests.

Straight answers before you commit time to a demonstration.

Including the ones where the answer is no.

Does Treica guarantee my submission will be accepted?

No, and no tool honestly can. We check your package against the documented structural conditions that authority parsers reject, and block generation while any blocking error is open. The filing decision, and its acceptance, remain with you and your authority.

Is this legal or regulatory advice?

No. Treica is software. It applies a versioned rule set with each finding linked to a regulatory source, so your own advisors and auditors can review the reasoning. It does not replace them.

Do you really deliver every column, or the ones that are easy?

All 120, across all 15 reporting tables. The exporter is generated from the official EBA dictionary that ships inside the product rather than from a hand-written list, so the columns are the standard's columns. That deliberately includes the judgement fields - substitutability and its reason, why a function is critical or important, the licenced activity it supports - which are the ones a supervisor reads first and a spreadsheet never asks for.

How do we know a piece of evidence has not been altered?

Each document is hashed when it is uploaded, and the hash is recomputed from the stored file on a weekly sweep and whenever you ask for it. A check reports one of three things, never two: verified, altered, or unreadable. Treating a storage outage as tampering would be a false alarm, and treating it as a pass would be worse. File identity, uploader and timestamp cannot be edited after upload.

How is this different from a free validator?

Free validators confirm file structure. Treica does that, and adds a warning tier that flags patterns which pass format validation but tend to attract supervisory questions. You can run the same register through both and see the additional findings.

Where is our data stored?

In the EU. Evidence documents and generated packages are stored in an EU region and served through time-limited, non-guessable links.

What happens to old submissions when the data changes?

Each filed package is frozen with its hash, taxonomy version and the validation run behind it. Later changes to your records never alter what was filed.

See the register the way a supervisor would.

A thirty-minute call to understand your entities and where your register stands today, then a demonstration against the real product. If it fits, a proposal - and implementation builds your register with you.