4 ms·
There is so much consultancy FUD about DORA. It's not going to impact freelancers or most SMEs. The regulation mostly expands regulation - there are already EB
by com 2y ago
There is so much consultancy FUD about DORA. It's not going to impact freelancers or most SMEs.
The regulation mostly expands regulation - there are already EBA requirements around outsourcing for a smaller list of financial institutions - in the European Economic Area (EEA, sort of EU plus) to ensure financial institution operational resilience (ie to ensure they won't fall over when technical or operational issues occur internally or in their tech supply chains).
The regulation, amongst other things, is concerned with direct or indirect use of "ICT third party suppliers" and requires that financial institutions keep tabs on that, make sure that they've got the right contractual stuff in place, are doing risk management, and are testing their "digital operational resilience".
Most SMEs won't be hit by this at all.
If you are classified as a crypto asset manager, or are a critical supplier to a fairly generic list of financial institution types, you'll be in discussions already with your clients to help them rule you out of scope since you aren't going to be critical to their ongoing operations.
There will not be badges or accreditation any time soon as far as I understand. If you're in scope, it's all going to be contractual between you and your client, and mostly to ensure that you're doing risk management with YOUR suppliers and can do incident response and reporting. All stuff serious businesses should be doing already.
See the EBA's information page [0] and look for RTS on ICT TPP. Again, it's not going to be the SME's responsibility unless you're a DORA financial institution.
[0] https://www.eba.europa.eu/publications-and-media/press-releases/esas-publish-first-set-rules-under-dora-ict-and-third-party https://www.eba.europa.eu/publications-and-media/press-relea...