Regulation · DORA

DORA readiness, at a price you can read before you call us

The Digital Operational Resilience Act has applied since January 2025. Supervisors have moved from awareness to inspection, and the Register of Information is the trigger they scrutinise first. We have not found another consultancy in the region that publishes a DORA price at all — so here is ours.

€4,900readiness assessment
€12,500assessment + implementation
3–6 weeksfixed timeline

Who is in scope

Banks, payment and e-money institutions, investment firms, fund managers, insurers, pension providers and crypto-asset service providers — plus the ICT third parties who serve them and are pulled in contractually. In Bulgaria supervision sits with the БНБ for banking and with the КФН for the non-banking financial sector. In Cyprus it sits with CySEC.

Microenterprises and small non-interconnected investment firms qualify for the simplified framework under Art. 16 and may need considerably less than this. We will tell you that at scoping rather than after invoicing.

What the assessment covers

  • ICT risk management framework gap analysis against Arts. 5–16 and Delegated Regulation 2024/1774.
  • Register of Information — completeness review and submission readiness for the annual February deadline, in the required XBRL-CSV format.
  • Contractual review against Art. 30(2) and (3): service description, data locations, audit and inspection rights, exit strategies, subcontracting chains.
  • Incident classification and reporting — the 4-hour, 72-hour and one-month cascade, with classification rationale documented at detection rather than reconstructed later.
  • Resilience testing programme under Art. 24 — the at-least-annual independent testing obligation, and what satisfies it.
  • Governance — the Art. 6(4) independent control function, and who occupies it.
Cyprus: the seat on the form. CySEC Circular C751 (19 January 2026) requires non-microenterprise entities to designate an ICT Risk Control-Function Owner and an ICT Auditor in the CySEC Portal. DORA Art. 6(10) expressly permits appointing an external undertaking to the first of those. We can run the assessment and, separately, fill that seat — see roles we fill. We will not occupy both seats for the same client.
What we do not sell you. Threat-led penetration testing under DORA requires accredited providers, and only a small number of significant entities are in scope for it at all. If you are one of them we will say so and refer you. If you are not — and most firms are not — we will not sell you a test you do not owe. What we do offer is the Art. 24 annual testing obligation, which is real, recurring, and satisfiable by an independent external party.
Book a scoping call