DORA readiness, at a price you can read before you call us
The Digital Operational Resilience Act has applied since January 2025. Supervisors have moved from awareness to inspection, and the Register of Information is the trigger they scrutinise first. We have not found another consultancy in the region that publishes a DORA price at all — so here is ours.
Who is in scope
Banks, payment and e-money institutions, investment firms, fund managers, insurers, pension providers and crypto-asset service providers — plus the ICT third parties who serve them and are pulled in contractually. In Bulgaria supervision sits with the БНБ for banking and with the КФН for the non-banking financial sector. In Cyprus it sits with CySEC.
Microenterprises and small non-interconnected investment firms qualify for the simplified framework under Art. 16 and may need considerably less than this. We will tell you that at scoping rather than after invoicing.
What the assessment covers
- ICT risk management framework gap analysis against Arts. 5–16 and Delegated Regulation 2024/1774.
- Register of Information — completeness review and submission readiness for the annual February deadline, in the required XBRL-CSV format.
- Contractual review against Art. 30(2) and (3): service description, data locations, audit and inspection rights, exit strategies, subcontracting chains.
- Incident classification and reporting — the 4-hour, 72-hour and one-month cascade, with classification rationale documented at detection rather than reconstructed later.
- Resilience testing programme under Art. 24 — the at-least-annual independent testing obligation, and what satisfies it.
- Governance — the Art. 6(4) independent control function, and who occupies it.