Anyone who doesn’t know their ICT landscape can’t report on anything else.

Article 8 of the DORA regulation requires identifying and classifying all ICT assets that support business functions, including their roles and dependencies. With appropriate documentation. Configuration and connections must be captured, third-party dependencies documented. The inventory must be updated regularly and whenever a material change occurs. The minimum review happens annually.

Anyone who doesn’t satisfy Article 8 also can’t correctly classify incidents (Art. 18) or reliably report third-party dependencies (Art. 28). LOGINventory provides the technical layer: hardware, software, and configuration data, agentlessly and updated daily. You keep the contract and risk layer for third parties on top of that in your GRC system.

Article 50 obliges member states to impose effective, proportionate, and dissuasive sanctions. BaFin fines can reach up to €5 million. Or, if higher, 10% of annual revenue.