DORA Flash
Complete gap analysis in 3-4 weeks: gap mapping, ICT register (Art. 28-30), incident classification (Art. 17-23), supervisor-ready report.
Operational — continuous monitoring
Regulatory compliance · EU financial entities
10-day flash audit, ICT third-party register, resilience testing and audit-ready documentation for EU financial entities.

Sanctions of up to 10% of annual turnover. ACPR/EBA supervision is intensifying — the ICT third-party register (Art. 28-30) and incident classification (Art. 17-23) are the most frequent breaking points in organisations with lean compliance teams.
The firm
15 years of expertise serving your compliance.
Services
Each package is self-contained, with published pricing and documented, supervisor-ready deliverables.
Complete gap analysis in 3-4 weeks: gap mapping, ICT register (Art. 28-30), incident classification (Art. 17-23), supervisor-ready report.
Full compliance for critical entities: requirements mapping, ANSSI registration, incident management plan, actionable evidence.
Complete audit-ready program: ICT governance, aligned provider contracts, TLPT program, prioritized remediation roadmap.
Method
Sequential, dated, no grey areas.
Entity, ICT perimeter, applicable obligations, roadmap.
Interviews, document review, testing. Risks ranked by supervisory exposure.
Report, ICT register, remediation plan. Enforceable before the supervisor.
Implementation support, interview preparation.
Fees
Published prices, no surprises. Firm quote after a free 20-minute scoping call.
| Package | Price | Timeline | Deliverable |
|---|---|---|---|
| DORA Flash | From €14,000 | 3-4 wks | Gap analysis + ICT register + supervisor report |
| NIS2 Express | From €25,000 | 5-8 wks | Compliance file + ANSSI + incident plan |
| DORA 360 | From €45,000 | 8-12 wks | Full audit-ready + TLPT + remediation |
| Regulatory Web Audit | from €2,500 | 5 d | Security + GDPR + performance report |
| Pentest | on quote | after scoping | CVSS report |
| ICT register only | from €5,000 | 2 wks | Register Art. 28-30 |
| Training | from €2,500/day | 1 wk | Sessions + materials |
FAQ
DORA applies to financial entities (banks, insurers, CASPs, fintechs) operating in the EU. The initial scoping is free.
Administrative sanctions, injunctions, and for large entities fines of up to 1% of average daily worldwide turnover. Supervision is intensifying in 2026.
The critical ICT third-party provider register (Art. 28-30): cloud, hosting, payments. Each entity must maintain it and provide it on request.
10 business days between scoping and delivery for the flash audit.
Yes: no vendor or integrator partnerships. Our recommendations serve no product.
Contact
Free scoping within 48h. Firm quote within 24h after scoping.