Operational — continuous monitoring

Regulatory compliance · EU financial entities

DORA & NIS2 compliance, delivered — not explained

10-day flash audit, ICT third-party register, resilience testing and audit-ready documentation for EU financial entities.

15+ years auditing financial systems EU Regulation 2022/2554 NIS2 Directive Results in 10 days
Institutional towers — financial districts

2026 — the first full year of DORA enforcement

Sanctions of up to 10% of annual turnover. ACPR/EBA supervision is intensifying — the ICT third-party register (Art. 28-30) and incident classification (Art. 17-23) are the most frequent breaking points in organisations with lean compliance teams.

The firm

The firm in numbers

15 years of expertise serving your compliance.

15+
years of auditing and security for financial systems
100%
Independence — no vendor or integrator partnerships
10d
for a supervisor-ready DORA report
EU
covering France & the European Union

Services

Our 3 packages

Each package is self-contained, with published pricing and documented, supervisor-ready deliverables.

DORA Flash

Complete gap analysis in 3-4 weeks: gap mapping, ICT register (Art. 28-30), incident classification (Art. 17-23), supervisor-ready report.

From €14,000
3-4 weeks

NIS2 Express

Full compliance for critical entities: requirements mapping, ANSSI registration, incident management plan, actionable evidence.

From €25,000
5-8 weeks

DORA 360

Complete audit-ready program: ICT governance, aligned provider contracts, TLPT program, prioritized remediation roadmap.

From €45,000
8-12 weeks

Additional services

Regulatory Web Audit from €2,5005 business days Pay online →
Pentest on quoteafter scoping
ICT register only from €5,0002 weeks
Training from €2,500/day1 week
Audit document review — interviews and testing

Method

Our method — 4 steps

Sequential, dated, no grey areas.

01

Scoping (48h)

Entity, ICT perimeter, applicable obligations, roadmap.

02

Audit (10d)

Interviews, document review, testing. Risks ranked by supervisory exposure.

03

Deliverables

Report, ICT register, remediation plan. Enforceable before the supervisor.

04

Remediation

Implementation support, interview preparation.

Fees

Transparent pricing

Published prices, no surprises. Firm quote after a free 20-minute scoping call.

PackagePriceTimelineDeliverable
DORA FlashFrom €14,0003-4 wksGap analysis + ICT register + supervisor report
NIS2 ExpressFrom €25,0005-8 wksCompliance file + ANSSI + incident plan
DORA 360From €45,0008-12 wksFull audit-ready + TLPT + remediation
Regulatory Web Auditfrom €2,5005 dSecurity + GDPR + performance report
Penteston quoteafter scopingCVSS report
ICT register onlyfrom €5,0002 wksRegister Art. 28-30
Trainingfrom €2,500/day1 wkSessions + materials

FAQ

Frequently asked questions

Does DORA apply to my organisation?

DORA applies to financial entities (banks, insurers, CASPs, fintechs) operating in the EU. The initial scoping is free.

What are the risks of non-compliance?

Administrative sanctions, injunctions, and for large entities fines of up to 1% of average daily worldwide turnover. Supervision is intensifying in 2026.

What is the ICT register?

The critical ICT third-party provider register (Art. 28-30): cloud, hosting, payments. Each entity must maintain it and provide it on request.

How long does an audit take?

10 business days between scoping and delivery for the flash audit.

Are you independent?

Yes: no vendor or integrator partnerships. Our recommendations serve no product.

Signing a compliance engagement

Contact

Let's talk about your compliance

Free scoping within 48h. Firm quote within 24h after scoping.