Services

DORA — the readiness and evidence pack for financial entities

The first conversation is free. Scope and price are agreed in writing before work starts.

For financial entities supervised by the Bulgarian National Bank (BNB) or the Financial Supervision Commission (FSC), or by the competent authority under your licence in another member state, and for the ICT providers they depend on. The readiness and evidence pack applied to DORA: assessment of the ICT-risk framework, the register of information and the agreed evidence.

from €7 9003–6 weeks
from €9 900implementation of the roadmap (assessment not included)

If the register is rejected, the worked validation example shows how to trace a broken reference and document the correction. You can commission a register-only validation and correction service; the format, outputs and submission responsibilities are agreed before work starts.

In plain language: If you are a financial entity, DORA requires you to show how you manage technology risk, incidents, testing and important suppliers. Some ICT providers are affected through their financial-sector customers. We identify the documents, records and technical measures your specific organisation needs.

For whom

One financial entity supervised by the Bulgarian National Bank (BNB) or the Financial Supervision Commission (FSC), or by the competent authority under its licence in another member state — and, indirectly, the ICT providers it depends on.

Typical trigger: A supervisory request, a register submission, a new ICT contract, or the management body asking where the entity stands.

What you receive

  • Gap assessment and prioritised roadmap
  • Review of supplier and ICT contracts against the regulation
  • Presentation of findings for management and auditors

The table shows how we connect each requirement to specific evidence, an owner and a next action. Unfamiliar terms have short explanations.

Illustrative example
RegulationRequirementControlEvidenceOwnerNext action
DORAICT risk framework approved by the management bodyAnnual framework review and approvalMinutes with the approval date; framework versionSecurity lead / board secretarySchedule the next review
DORARegister of ICT third-party arrangementsRegister kept current on every new contractDated register export; contract list reconciliationProcurementAdd the two arrangements found missing
DORAMajor ICT-related incidents are reported to the competent supervisory authority within the applicable deadlinesIncident classification and reporting procedure with deadlines and rolesTabletop exercise record; template notificationsIncident coordinatorRun one scenario this quarter
How requirements are traced to evidence. Columns show the structure; the rows are generic examples, not a client’s controls. Each row names the regulation it belongs to.

View a sample deliverable → (illustration of the structure, not a full DORA register)

What the price includes

  • 1 legal entity
  • 1 regulation — DORA
  • Up to 100 employees
  • Up to 15 supplier or ICT contracts reviewed
  • Up to 25 existing policies assessed
  • Register of Information covering up to 20 ICT arrangements
  • 1 supervisory authority (BNB, FSC or the competent authority under your licence)

Timeline and your input

The ICT contract list, existing policies, the register of information if one exists, and time from the ICT-risk owner. Typical timeline 3–6 weeks.

Starting price

The included 20 arrangements are a commercial limit, not a definition of a complete register. For 40 arrangements, the published increment for the additional 20 is 20 × €200 = €4 000, before other scope changes. Contract review and register processing are distinct activities. One quotation shows the full coverage and applicable increments, without charging twice for the same work.

from €7 900. Base-scope price. The exact price is fixed in writing before work starts. It changes only when the agreed number of entities, systems, domains, contracts, documents, interviews, languages or depth of review falls outside the base scope. No additional work is charged without prior agreement. Scope and prices.

Need both stages? Assessment €7 900 plus implementation from €9 900 — a combined starting budget of €17 800. The starting price does not cover an unlimited number of corrections; a suitable prior assessment is reviewed before a new engagement.
Beyond that scope · detailed terms
  • +€250 per additional supplier contract
  • +€1 900 per additional legal entity in the same group
  • 101–500 employees, or two regulations at once: from €13 900
  • +€200 per additional ICT arrangement in the register
  • Implementation of the roadmap: from €9 900 — after the assessment; the assessment is not included

Contract review and processing an ICT arrangement in the register are separate activities. If both are required beyond the included limits, the quotation lists each additional fee separately.

A larger scope is one quotation, not stacked add-ons. The extra for a second entity applies to shared systems, policies and governance — a genuinely separate environment is quoted individually. Limits do not multiply automatically; the from €13 900 figure is the starting price for the expanded project as a whole; its scope is described in one quotation.

Agreed separately

Implementation of the roadmap (from the published figure; it does not include the assessment); resilience testing; ongoing control-function work.

One product for DORA and NIS2: the readiness and evidence pack covers one regulation for one entity of up to 100 employees, including up to 15 contracts and 25 policies, and documents the evidence agreed in the statement of work. Applied to DORA it also covers the register of information (up to 20 ICT arrangements) and one supervisory authority — see the DORA page. Implementing controls is a separate project and does not include the assessment.
After the assessment you receive the agreed findings and next actions. Technical and organisational implementation can be commissioned separately from Dyasol or carried out by your chosen team. Practical improvements →

For small financial organisations: Financial services →

Independence. Where we support your ICT risk control function or perform outsourced compliance-verification tasks, we do not act as your ICT auditor; the financial entity retains the function, oversight and responsibility; where we build your management system, the certification or independent assessment is done by another body. Checking that our own fixes work remains part of accepting the work. We state the arrangement in writing before you engage us.