2026-04-02
Added · Updated
The National Bank of Belgium requires financial entities under its supervision to submit the register of information regarding ICT services provided by third-party providers, as mandated by Article 28(3) of DORA. This submission is made available upon request via the OneGate portal and primarily pertains to the highest level of consolidation under the Bank's supervision. The circular clarifies that registers should only contain information for entities falling under the Bank's direct supervisory powers and allows parent companies to submit consolidated registers on behalf of supervised subsidiaries. This document replaces circular NBB_2025_03 and applies with immediate effect.
Public NBB_2026_05 – 31 March 2026 Circular - Page 1/4 14 Boulevard de Berlaimont - 1000 Brussels Tel. +32 2 221 23 88 Company number: 0203.201.340 Brussels RLE www.nbb.be Circular Public Brussels, 31 March 2026 Reference: NBB_2026_05 Your correspondent: Thomas Plomteux Tel. +32 2 221 21 97 - Mobile +32 489 97 32 27 thomas.plomteux@nbb.be Submission of the register of information required by DORA Scope credit institutions governed by Belgian law not subject to direct supervision by the European Central Bank (hereinafter, the “ECB”) under the SSM Regulation1 and branches established in Belgium of credit institutions governed by the law of a third country; stockbroking firms governed by Belgian law and branches established in Belgium of stockbroking firms governed by the law of a third country; payment institutions and electronic money institutions governed by Belgian law, including payment institutions of limited size registered in accordance Article 82 of the Act of 11 March 2018,2 payment institutions offering account aggregation services within the meaning of Article 2(17) of the same legislation and electronic money institutions of limited size registered in accordance with Article 200 of the same act; insurance and reinsurance companies governed by Belgian law, except for those referred to in Article 275, 276 or 294 of the Act of 13 March 20163 and branches established in Belgium of insurance and reinsurance companies governed by the law of a third country; central securities depositories governed by Belgian law; central counterparties governed by Belgian law; providers of crypto-asset services governed by Belgian law authorised under the MiCA Regulation4 and issuers of asset-referenced tokens governed by Belgian law, subject to supervision by the National Bank of Belgium (hereinafter, the “Bank”).5 1 Council Regulation (EU) No 1024/2013 of 15 October 2013 conferring specific tasks on the European Central Bank concerning policies relating to the prudential supervision of credit institutions. 2 Act of 11 March 2018 on the legal status and supervision of payment institutions and electronic money institutions and access to the activity of payment service provider, to the activity of issuing electronic money and to payment systems. 3 Act of 13 March 2016 on the legal status and supervision of insurance companies and reinsurance companies. 4 Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937. 5 More specifically, to the extent the supervision of compliance with DORA falls within the Bank’s supervisory powers over these entities.
Public NBB_2026_05 – 31 March 2026 Circular - Page 2/4 These entities are hereinafter referred to as “financial entities”. Summary/objectives This circular constitutes a revision of circular NBB_2025_03 on the same subject, in order to extend its scope to branches established in Belgium of credit institutions, stockbroking firms and insurance and reinsurance companies governed by the law of a third country.6 This circular implements the fourth subparagraph of Article 28(3) of DORA7 relating to the obligation to make available to the competent authority a register of information. 6 For more information, reference is made to Q&A DORA102 - 3097 - European Insurance and Occupational Pensions Authority. 7 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (https://eur-lex.europa.eu/eli/reg/2022/2554/oj).
Public NBB_2026_05 – 31 March 2026 Circular - Page 3/4 Dear Sir, Madam, The first subparagraph of Article 28(3) of DORA requires financial entities to maintain and update at entity level, and at sub-consolidated and consolidated levels, a register of information in relation to all contractual agreements on the use of ICT services provided by third-party providers. Pursuant to the fourth subparagraph of Article 28(3), financial entities shall make available to the Bank, upon its request, the full register of information or specified sections thereof, along with any information deemed necessary to enable the effective supervision of the financial entity. The Bank wishes to stress that the receipt of this register is crucial to enable it to fulfil the tasks conferred on it, in particular ensuring the operational resilience and financial stability of the Belgian financial sector. The scope, content and format of the register of information are specified in Implementing Regulation (EU) 2024/29568. By means of this circular, the Bank wishes to clarify the following: the register and other requested information can be submitted via OneGate. To this end, the Bank will post on its website (https://www.nbb.be/OneGate → “documentation” → “domain-dor”9) practical information on how to fulfil the reporting requirement and answers to frequently asked questions; while in principle the Bank has the possibility to request that registers of information be submitted to the Bank for all supervised levels of consolidation, it will, as a rule, limit its requests to registers of information pertaining to the highest level of (sub-)consolidation under its supervision; registers of information transmitted to the Bank should contain only information pertaining to financial entities within the meaning of Article 2(2) of DORA falling under the Bank’s supervision (on a standalone, sub-consolidated or consolidated basis). For example, in the case of a financial services group to which a significant credit institution belongs, the group should submit the registers of information for its banking entities to the ECB and send the Bank only the register(s) of information for the entities it supervises (e.g. insurance companies); the Bank will transfer these registers to the European Supervisory Authorities (in the context of identifying critical third-party ICT service providers) only if the financial entity does not have a higher level of consolidation in another EU Member State, in order to avoid overlapping reporting to the European Supervisory Authorities; although the obligation to submit a register of information under DORA rests with financial entities subject to the Bank's supervision, it accepts that registers of information relating to the (sub- )consolidated level of a group to which these financial entities belong may be submitted to the Bank by the parent company of the group, on behalf of these financial entities; 8 Commission Implementing Regulation (EU) 2024/2956 of 29 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to standard templates for the register of information (https://eur-lex.europa.eu/eli/reg/2024/2956/oj). 9 At the publication of this circular, this results in the following URL: Domain DOR | nbb.be
Public NBB_2026_05 – 31 March 2026 Circular - Page 4/4 the Bank acknowledges that, in addition to the reporting required by DORA, it has set out supervisory expectations (in circulars, guidelines, etc.) regarding the submission of registers of outsourcing arrangements10 which, while somewhat different in scope, overlap to a significant extent with this new statutory reporting obligation. To the extent that reporting of such dependencies is provided for in the applicable regulations, the Bank aims to eventually request all information on third-party dependencies (whether relating to ICT services or not) through a single, unified register and portal. In the meantime, when responding to questions relating to these expectations, financial entities may limit themselves to those dependencies that they have not yet reported on via the register of information, in order to avoid having to provide the same information more than once. This circular replaces circular NBB_2025_03 on the submission of the register of information required by DORA and is applicable with immediate effect. A copy of this circular will be sent to your institution’s accredited auditor/audit firm or accredited statutory auditor/audit firm. Yours faithfully, Pierre Wunsch Governor 10 For example, linked to the European Banking Authority (EBA) Guidelines on outsourcing arrangements of 25 February 2019 (https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/internalgovernance/guidelines-outsourcing) and the accompanying NBB circular (NBB_2019_19) (https://www.nbb.be/en/articles/circulaire-nbb201919-orientations-de-lautorite-bancaire-europeenne-abe-du-25- fevrier-2019).