DORA Register of Information Reporting: MFSA Sets 2026 Supervisory Deadlines

The Malta Financial Services Authority (“MFSA”) has issued a Circular establishing mandatory reporting timelines and procedural requirements for financial entities in scope of Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector (“DORA”) in relation to the Register of Information (“RoI”) on ICT third-party arrangements.

This marks a significant step in the practical implementation of DORA and reinforces that digital operational resilience is now a structured, data-driven supervisory obligation, not simply a high-level governance principle.

The Register of Information

Under Article 28(3) of the DORA Regulation, financial entities must maintain a comprehensive RoI covering all contractual arrangements with ICT third-party service providers. This register is a core input into the EU framework that allows the European Supervisory Authorities (“ESAs”) to designate Critical ICT Third-Party Providers subject to direct EU oversight.

The RoI is therefore not just an internal outsourcing inventory, it is a structured regulatory dataset. Its preparation increasingly requires the type of data governance, system mapping and digital control environments typically delivered through specialist digital resilience and governance solutions, including platforms such as those developed by ODIT, alongside legal and compliance oversight.

Scope of Application

The RoI applies to all MFSA-authorised financial entities within the scope of DORA. Significant credit institutions directly supervised by the European Central Bank (“ECB”) are to follow ECB guidance for RoI submissions.

For many firms, this means that ICT risk, outsourcing, cloud arrangements and SaaS dependencies must now be captured in a way that is legally accurate, technically structured and reporting-ready – a convergence of legal interpretation and digital operational capability.

Key Reporting Timelines

From reporting year 2026 and onwards, in-scope entities must:

  • Submit the full RoI annually to the MFSA (entity or consolidated level);
  • Report within the annual reporting window: 1st January – 21st March (or the next working day where applicable); and
  • Use 31st December of the preceding year as the reference date (e.g. 31st December 2025 for the 2026 reporting year).

 The Register of Information Submissions

RoI submissions must be made via the MFSA LH Portal, and a submission is only DORA-compliant once it achieves “Accepted” status. Rejected submissions must be corrected and resubmitted.

The MFSA makes clear that:

  • It is not an XBRL provider;
  • Responsibility for creating, maintaining and converting the RoI into the required DORA-compliant plain-CSV format rests entirely with the financial entity; and
  • The RoI must align with the latest ESAs Reporting Technical Package, which may be updated over time.

This highlights a key reality of DORA: regulatory compliance now depends on technical data capability. Legal teams ensure contractual and regulatory alignment, while RegTech and digital governance specialists – including providers such as ODIT support the structuring, traceability and integrity of the underlying ICT third-party data.

Regulatory Consequences of Non-Compliance

Failure to submit a fully validated and accepted RoI within the reporting window constitutes a breach of the DORA reporting obligation and may result in regulatory action by the MFSA. This elevates RoI management from an operational task to a board-level issue spanning regulatory risk, operational resilience and digital governance.

What Firms Should Be Doing Now

In practical terms, this requires financial entities to move beyond static outsourcing registers and towards a living ICT third-party governance framework, including:

  • A centralised and continuously updated inventory of ICT third-party arrangements;
  • Clear classification of ICT services and criticality;
  • Contractual terms that support DORA information, audit and oversight requirements;
  • Integration of legal, compliance, risk, IT and procurement functions; and
  • Systems and controls that allow RoI data to be structured, validated and reportable on demand.

This is where the intersection of legal advisory and digital resilience infrastructure becomes critical. Legal advisors support regulatory interpretation, policy frameworks and contractual alignment, while digital governance and operational resilience specialists such as ODIT help translate those requirements into operational tools, structured data environments and scalable reporting capability.

Financial entities should treat the 2026 cycle as the start of a continuous DORA reporting lifecycle, embedding legal compliance, ICT governance and digital resilience capabilities into their core operating model, rather than approaching the RoI as a one-off regulatory filing.

The full MFSA Circular can be accessed here.