DORA and the LEI number: who needs it, and when?

5 min read Updated July 2026
Server room with colourful network cables — DORA and the LEI number for ICT providers

DORA doesn’t mean every technology company has to apply for an LEI number. The need for an LEI number arises when a company must be uniquely identified in the DORA register of information.

DORA applies primarily to financial entities. Financial entities must keep a register of their information and communication technology (ICT) service contracts and providers. The register must state the provider’s official identifier.

For an ICT provider that is a legal entity registered in the EU, this identifier can be an LEI number or an EUID. For a legal entity registered outside the EU, an LEI number is assumed.

What is DORA?

DORA, the Digital Operational Resilience Act, is an EU regulation designed to strengthen the financial sector’s resilience to ICT risks. Such risks include, for example, cyberattacks, system failures, data breaches and service outages.

DORA entered into force on 16 January 2023 and has applied since 17 January 2025.

DORA doesn’t just deal with banks’ internal IT systems. It also covers providers whose services financial entities’ operations depend on.

Who does DORA affect?

The main obligations under DORA fall on financial entities. These include, for example, banks, insurers, investment firms, payment institutions, fund managers, trading venues and crypto-asset service providers.

Financial entities must manage their ICT risks, assess their providers and keep a DORA register of information covering all ICT service contracts.

ICT providers come into contact with DORA mainly through the client relationship. If a provider supplies an ICT service to a financial entity that falls within the scope of DORA, the financial entity may ask the provider for the identifier needed to complete the register. Such a provider might be, for example:

  • a cloud service provider;
  • a software service provider;
  • a data hosting or data processing provider;
  • a cybersecurity service provider;
  • an IT management or support service provider;
  • an intra-group IT service provider.

If an ICT provider is designated as a critical third-party provider under DORA, it may become subject to direct oversight by the European supervisory authorities. For a typical provider, the impact is usually that a client that is a financial entity asks for the data needed to complete its register.

What is the DORA register of information?

The DORA register of information is a financial entity’s register of ICT service contracts and providers. Among other things, the register records:

  • which ICT service is used;
  • who provides the service;
  • which function of the financial entity the service supports;
  • whether the service supports a critical or important function;
  • which country the provider is located in;
  • which identifier is used to identify the provider.

The register isn’t limited to the most critical IT services. A financial entity must record all its ICT service contracts. For critical and important functions, the scope of the register data can be more extensive and may also cover certain sub-contractors.

How is an ICT provider identified in the register?

In the DORA register of information, the identifier used depends on whether the provider is a legal entity or a sole trader, and where it’s registered.

  • The financial entity itself is identified in the register using an LEI number.
  • An ICT provider that is a legal entity registered in the EU can be identified using an LEI number or an EUID. The EUID is a unique European identifier used in the European system of business registers.
  • For an ICT provider that is a legal entity registered outside the EU, an LEI number is assumed. Without an LEI number, using another identifier can cause data quality problems. This makes the LEI number the most reliable solution for a third-country provider.
  • For a sole trader provider, other permitted identifiers can be used, such as a registration number, a VAT number or another equivalent identifier.

When is an LEI number needed because of DORA?

In the context of DORA, an LEI number is needed mainly in three situations.

First, a financial entity that falls within the scope of DORA needs an LEI number itself, since the register uses the LEI number to identify the financial entity.

Second, an LEI number is needed by an ICT provider that is a legal entity registered outside the EU, if it needs to be entered into an EU financial entity’s DORA register of information.

Third, an LEI number may also be needed by an ICT provider registered in the EU, if the client that is a financial entity specifically asks for the LEI number to be used in the register. Although an EUID may also work for an EU legal entity, the LEI number is an internationally usable and easily verifiable identifier.

When is an LEI number not needed?

DORA doesn’t require an LEI number from every company.

An LEI number isn’t needed because of DORA if the company isn’t a financial entity, doesn’t provide ICT services to a financial entity that falls within the scope of DORA, and no client that is a financial entity asks for the company’s identifier for its DORA register of information.

An ICT provider registered in the EU may also not need an LEI number if the financial entity uses an EUID in its register and there’s no other reason to need an LEI number.

Does the EUID replace the LEI number?

In the DORA register of information, an EUID can replace the LEI number for an ICT provider that is a legal entity registered in the EU. This doesn’t mean the EUID replaces the LEI number in every situation.

An LEI number may still be needed, for example, for securities transactions, derivatives reporting, operating with a bank or broker, or if an international client wants to use the LEI number specifically.

An EUID can’t be used for an ICT provider that is a legal entity registered outside the EU. In that case, an LEI number is needed for the DORA register of information.

The LEI number must be valid

The LEI number used in the DORA register of information must be valid and active. If the LEI number’s status has lapsed, it must be renewed before it’s used in the register or provided to a client.

A lapsed LEI number doesn’t need to be applied for again. The existing number must be renewed, and once confirmed, its status becomes active again. The number itself stays the same.

Read more: Renewing your LEI number

How do you apply for an LEI number?

You can apply for an LEI number online. For US and international organizations, existing LEI records can be matched against GLEIF; first-time applicants can enter their details manually.

  1. Choose a suitable package. Choose a 1-, 3- or 5-year package.
  2. Enter the company name or registration number. The system looks up the company’s details automatically.
  3. Check the details. Make sure the company name, registration number, address and contact details are correct.
  4. Submit the application and make the payment. Once the details have been checked, the LEI number is issued and sent to your email address.

If a company needs an LEI number for a DORA register of information, it’s worth applying for the number before the financial entity has to submit or update its register data. Read more: How to apply for an LEI number?

Frequently asked questions

Does DORA require an LEI number from every company?

No. DORA affects primarily financial entities and their ICT providers. DORA doesn’t create an LEI number requirement for other companies.

Does every ICT provider have to apply for an LEI number?

No. For an ICT provider that is a legal entity registered in the EU, an EUID may also work in the DORA register of information. An LEI number may still be needed if the provider is registered outside the EU or if a client that is a financial entity asks for the LEI number specifically.

Is the EUID the same as the LEI number?

No. The EUID is an identifier used in the European system of business registers. The LEI number is an international identifier for legal entities that’s widely used in the financial markets and in reporting.

Who’s responsible for maintaining the DORA register of information?

The financial entity is responsible for maintaining the register. The ICT provider usually has to give the financial entity the necessary data, including the LEI number or another suitable identifier.

Who’s responsible for an ICT provider’s LEI number?

The LEI number is the provider’s own identifier. The application is submitted by the provider or someone authorized by them. The financial entity uses this identifier in its DORA register of information, but the obligation to maintain the register stays with the financial entity.

What happens if an LEI number has lapsed?

A lapsed LEI number must be renewed. The LEI number used in the DORA register of information must be valid and active.

Does an ICT provider based outside the EU need an LEI number?

If it’s a legal entity and it needs to be entered into an EU financial entity’s DORA register of information, an LEI number is assumed for its identification.

Back to top