Letzscale maps those ICT contracts to the register fields for you: drop the supplier PDFs in, get a ranked gap report plus a formatted export file. Every filled field is backed by a verifiable quote from your document.
Why the register is a contract problem
Article 28(3) of DORA requires financial entities to maintain and update a register of information covering all contractual arrangements for the use of ICT services, at entity level and at sub-consolidated and consolidated level where relevant. In Luxembourg that obligation is turned into an annual submission through Circular CSSF 25/882 (eDesk) and CAA Circular Letter 25/1 (SOFiE / E-File).
The templates want controlled values across interlocking tables — on our site we describe this as 101 fields across templates B_01.01 to B_07.01 under DORA reporting framework 4.0. Your contracts were written by lawyers and procurement. They were not written as a register. That mismatch is why firms fail validation, not because they lack a second spreadsheet.
In the ESAs' dry run, fewer than 7% of nearly a thousand participating firms passed all 116 data quality checks. The failure is structural: data scattered across documents, subcontracting chains that are not in the counterparty clause, and LEIs or coded fields entered by hand.
A contract-first method (do this before you open the filing tool)
1. Inventory contracts, not vendors
Start with every master agreement, SLA, order form, amendment and schedule that covers an ICT service. A vendor list guarantees you miss renewals, schedules and intragroup arrangements. The register is contract-level. Treat B_02.01 as the backbone: one unique contractual arrangement reference per arrangement, kept stable across every other template.
2. Qualify each arrangement
Classify ICT vs business process, and confirm whether the entity is in DORA scope. In Luxembourg that decides whether DORA and Circular CSSF 25/882 apply, or the amended Circular 22/806, or both.
3. Pull only what the documents state
For each arrangement, extract what the templates require when it is actually present: parties and LEIs, unique contract references, start and end dates, notice and termination, governing law, ICT service type, function supported and whether it is critical or important, data and processing locations, and — for critical or important functions — the subcontracting chain.
If the sentence is not in the pack, do not invent it. Mark the field Missing and name who to ask (provider, legal, IT, or the counterparty's account manager).
4. Reconcile across tables before you format
The tables have to agree with one another. A provider that appears in one table without a matching arrangement reference in another is a rejection waiting to happen. An arrangement in B_02.01 without a matching service row in B_02.02 is an orphan. Run consistency checks while the source documents are still open.
5. Export, validate, then file
Produce the formatted package your competent authority expects. Run the ESAs' validation checks at your desk. Then file through eDesk, SOFiE / E-File, or your ECB route. Letzscale stops at the export — it is not a filing tool.
What usually is not in the contract (and will sink you)
- Subcontracting chains behind critical or important functions — often in an annex, a service description, or a provider answer you never requested
- LEIs that do not match what the supervisor already holds
- Data location and processing location stated in different places, or only for the primary hosting region
- Notice periods and termination rights buried in schedules rather than the front of the master agreement
- Intragroup ICT arrangements treated as “not a vendor” and left out
Request chain information at onboarding and renewal. Asking in February is too late for a March window.
Where Letzscale fits
Letzscale is the DORA register-of-information tool that reads your actual ICT contracts and produces the register data behind them.
- Contract extraction, not data entry — including scanned documents
- Deterministic regulatory rules — not a chatbot guessing compliance answers
- Verbatim proof for every filled field
- Gap report per contract: what is missing, who to chase, what to ask
- Formatted export that plugs into the spreadsheet, adviser or GRC you already use
- Built for mid-sized Luxembourg ManCos, AIFMs, UCITS managers and payment institutions under CSSF or CAA supervision
- Stored and processed in the EU; contracts are never used to train AI models
What Letzscale does not do
- Not a filing tool. It stops at the export file. You file it.
- Not a replacement for your GRC, spreadsheet, or adviser — it feeds them.
- Not a chatbot. It answers the regulation's questions with quotes from your contracts.
Free starting point: upload one supplier's contracts. Get the ranked gap report and formatted export. If our software misses a required field that is clearly stated in your contract, our founders will manually audit your next three suppliers by hand, over the weekend, at no charge. Reply within one business day.
FAQ
Do I fill the register from policies or from contracts?
From contracts (and the supporting schedules and provider responses the contracts point to). Policies do not produce Article 28(3) rows.
Can I start from last year's xBRL-CSV?
You can use it as a baseline inventory, then re-check every arrangement against the current signed pack. Validation bars rise between cycles; a previously accepted file is not automatically safe.
Does Letzscale file to the CSSF for me?
No. Letzscale stops at the export file. You file it.
Start with one supplier
Upload one supplier's contracts. Get the ranked gap report and the formatted export file, free. If our software misses a required field that is clearly stated in your contract, our founders will manually audit your next three suppliers by hand, over the weekend, at no charge.
Run your free Gap AuditRelated reading
Contact: jonas.sampaio@letzscale.com
Letzscale S.à r.l. - S. — RCS Luxembourg B309937 — 19, Um Kalleksuewen, L-7480 Tuntange, Helperknapp
Letzscale is not a law firm and this page does not constitute legal advice. Deadlines and template versions should be verified against current CSSF, CAA and ESA publications.