DORA — the readiness and evidence pack for financial entities
The first conversation is free. Scope and price are agreed in writing before work starts.
For financial entities supervised by the Bulgarian National Bank (BNB) or the Financial Supervision Commission (FSC), or by the competent authority under your licence in another member state, and for the ICT providers they depend on. The readiness and evidence pack applied to DORA: assessment of the ICT-risk framework, the register of information and the agreed evidence.
If the register is rejected, the worked validation example shows how to trace a broken reference and document the correction. You can commission a register-only validation and correction service; the format, outputs and submission responsibilities are agreed before work starts.
For whom
One financial entity supervised by the Bulgarian National Bank (BNB) or the Financial Supervision Commission (FSC), or by the competent authority under its licence in another member state — and, indirectly, the ICT providers it depends on.
Typical trigger: A supervisory request, a register submission, a new ICT contract, or the management body asking where the entity stands.
What you receive
- Gap assessment and prioritised roadmap
- Review of supplier and ICT contracts against the regulation
- Presentation of findings for management and auditors
The table shows how we connect each requirement to specific evidence, an owner and a next action. Unfamiliar terms have short explanations.
| Regulation | Requirement | Control | Evidence | Owner | Next action |
|---|---|---|---|---|---|
| DORA | ICT risk framework approved by the management body | Annual framework review and approval | Minutes with the approval date; framework version | Security lead / board secretary | Schedule the next review |
| DORA | Register of ICT third-party arrangements | Register kept current on every new contract | Dated register export; contract list reconciliation | Procurement | Add the two arrangements found missing |
| DORA | Major ICT-related incidents are reported to the competent supervisory authority within the applicable deadlines | Incident classification and reporting procedure with deadlines and roles | Tabletop exercise record; template notifications | Incident coordinator | Run one scenario this quarter |
View a sample deliverable → (illustration of the structure, not a full DORA register)
What the price includes
- 1 legal entity
- 1 regulation — DORA
- Up to 100 employees
- Up to 15 supplier or ICT contracts reviewed
- Up to 25 existing policies assessed
- Register of Information covering up to 20 ICT arrangements
- 1 supervisory authority (BNB, FSC or the competent authority under your licence)
Timeline and your input
The ICT contract list, existing policies, the register of information if one exists, and time from the ICT-risk owner. Typical timeline 3–6 weeks.
Starting price
The included 20 arrangements are a commercial limit, not a definition of a complete register. For 40 arrangements, the published increment for the additional 20 is 20 × €200 = €4 000, before other scope changes. Contract review and register processing are distinct activities. One quotation shows the full coverage and applicable increments, without charging twice for the same work.
from €7 900. Base-scope price. The exact price is fixed in writing before work starts. It changes only when the agreed number of entities, systems, domains, contracts, documents, interviews, languages or depth of review falls outside the base scope. No additional work is charged without prior agreement. Scope and prices.
Beyond that scope · detailed terms
- +€250 per additional supplier contract
- +€1 900 per additional legal entity in the same group
- 101–500 employees, or two regulations at once: from €13 900
- +€200 per additional ICT arrangement in the register
- Implementation of the roadmap: from €9 900 — after the assessment; the assessment is not included
Contract review and processing an ICT arrangement in the register are separate activities. If both are required beyond the included limits, the quotation lists each additional fee separately.
A larger scope is one quotation, not stacked add-ons. The extra for a second entity applies to shared systems, policies and governance — a genuinely separate environment is quoted individually. Limits do not multiply automatically; the from €13 900 figure is the starting price for the expanded project as a whole; its scope is described in one quotation.
Agreed separately
Implementation of the roadmap (from the published figure; it does not include the assessment); resilience testing; ongoing control-function work.
For small financial organisations: Financial services →