Entry product 02
DORA / NIS2 Evidence Sprint
When a regulator or auditor asks, intentions don't count — evidence does. In three to five weeks we produce the pack that lets a named director answer with proof. We call it an Evidence Sprint, not a readiness assessment, deliberately.
Who this is for
Financial entities under DORA (payment institutions, e-money issuers, asset managers, brokers, insurers, crypto-asset service providers), entities in scope of NIS2 — and the ICT/SaaS vendors contractually pulled into both. If management carries personal liability, this sprint is for management.
What you receive
- Gap assessment against your actual obligations — not a generic checklist.
- Prioritised remediation roadmap, ranked by regulatory weight and real risk.
- Supplier-contract review — the ICT third-party clauses regulators now read first.
- Policy gap analysis with a concrete adoption plan.
- Executive presentation — one deck your board and your auditor can both use.
- Executive fraud / BEC briefing — a two-hour leadership session on the single most expensive everyday threat, included.
Already working toward SOC 2 or ISO 27001? Say so at scoping. The same control evidence usually serves all of them, and we will map it once rather than letting you build three parallel sets of documentation. See frameworks.
Recurring follow-ons our clients choose
- Register of Information as-a-Service — the Q1 DORA submission season, handled annually.
- Vendor Passport — for ICT vendors: a maintained evidence set that clears client due diligence in hours instead of weeks.
- Fractional security leadership — the independent second-line oversight regulators expect, in clear monthly tiers.
Bulgarian administrations and municipalities: a dedicated fixed-price readiness assessment mapped to the Cybersecurity Act (ЗКС), delivered in Bulgarian, priced for public budgets — including the management-body training the law requires. Details.
Book a scoping call