DORA & NIS2 compliance, delivered — not explained

10-day flash audit, ICT third-party register, resilience testing and audit-ready documentation for EU financial entities.

EU Regulation 2022/2554 NIS2 Directive EU Financial Entities Results in 10 days
Flash audit — quote in 24h Create an account

Our 3 packages

Each package is self-contained, with published pricing and documented, supervisor-ready deliverables.

🔍

DORA Flash

Complete gap analysis in 3-4 weeks: gap mapping, ICT register (Art. 28-30), incident classification (Art. 17-23), supervisor-ready report.

From €14,000
3-4 weeks
🛡️

NIS2 Express

Full compliance for critical entities: requirements mapping, ANSSI registration, incident management plan, actionable evidence.

From €25,000
5-8 weeks
⚡

DORA 360

Complete audit-ready program: ICT governance, aligned provider contracts, TLPT program, prioritized remediation roadmap.

From €45,000
8-12 weeks

Additional services

🌐
Regulatory Web Audit
from €2,500
5 business days
Pay online →
🐛
Pentest
on quote
after scoping
📋
ICT Register only
from €5,000
2 weeks
🎓
Training
from €2,500/day
1 week

Our method — 4 steps

Sequential, dated, no grey areas.

1

Scoping (48h)

Entity, ICT perimeter, applicable obligations, roadmap.

2

Audit (10d)

Interviews, document review, testing. Risks ranked by supervisory exposure.

3

Deliverables

Report, ICT register, remediation plan. Enforceable before the supervisor.

4

Remediation

Implementation support, interview preparation.

Transparent pricing

Published prices, no surprises. Firm quote after a free 20-minute scoping call.

PackagePriceTimelineDeliverable
DORA FlashFrom €14,0003-4 wksGap analysis + ICT register + supervisor report
NIS2 ExpressFrom €25,0005-8 wksCompliance file + ANSSI + incident plan
DORA 360From €45,0008-12 wksFull audit-ready + TLPT + remediation
Regulatory Web Auditfrom €2,5005 dSecurity + GDPR + performance report
Penteston quoteafter scopingCVSS report
Trainingfrom €2,500/day1 wkSessions + materials

Frequently asked questions

Does DORA apply to my organisation?

DORA applies to financial entities (banks, insurers, CASPs, fintechs) operating in the EU. The initial scoping is free.

What are the risks of non-compliance?

Administrative sanctions, injunctions, and for large entities fines of up to 1% of average daily worldwide turnover. Supervision is intensifying in 2026.

What is the ICT register?

The critical ICT third-party provider register (Art. 28-30): cloud, hosting, payments. Each entity must maintain it and provide it on request.

How long does an audit take?

10 business days between scoping and delivery for the flash audit.

Are you independent?

Yes: no vendor or integrator partnerships. Our recommendations serve no product.

Let's talk about your compliance

Free 20-minute scoping. Firm quote within 24h after scoping.