DORA / NIS2 readiness and evidence pack
The first conversation is free. Scope and price are agreed in writing before work starts.
Need to show how your organisation meets DORA or NIS2 requirements? For one legal entity and one regulation, we assess gaps, review the agreed supplier and ICT contracts and organise the specified evidence for management and auditors. Includes a short executive fraud briefing. Implementing controls is quoted separately.
A policy and a record of its execution answer different questions. The control evidence guide shows how to connect a requirement to an owner and a verifiable result.
For whom
One legal entity that must show DORA or NIS2 evidence to a supervisor, bank, customer or auditor.
Typical trigger: A supervisory letter, a customer’s due-diligence request, an audit finding, or a management decision to close known gaps.
What you receive
- Gap assessment and prioritised roadmap
- Review of supplier and ICT contracts against the regulation
- Presentation of findings for management and auditors
The table shows how we connect each requirement to specific evidence, an owner and a next action. Unfamiliar terms have short explanations.
| Regulation | Requirement | Control | Evidence | Owner | Next action |
|---|---|---|---|---|---|
| DORA | ICT risk framework approved by the management body | Annual framework review and approval | Minutes with the approval date; framework version | Security lead / board secretary | Schedule the next review |
| DORA | Register of ICT third-party arrangements | Register kept current on every new contract | Dated register export; contract list reconciliation | Procurement | Add the two arrangements found missing |
| NIS2 | Supply-chain security for the suppliers that matter | Supplier register with contract clauses on security and incident cooperation | Dated register export; clause checklist | Procurement | Add clauses at the next contract change |
| NIS2 | Significant incidents reported to the sectoral CSIRT (24 h / 72 h / final report) | Incident procedure with deadlines and roles | Tabletop exercise record; template notifications | Incident coordinator | Run one scenario this quarter |
What the price includes
- 1 legal entity
- 1 regulation (DORA or NIS2)
- Up to 100 employees
- Up to 15 supplier or ICT contracts reviewed
- Up to 25 existing policies assessed
Timeline and your input
A contact who can provide policies, contracts and access to the people who own the controls; time from those owners. Typical timeline 3–5 weeks once inputs are available; the DORA track takes 3–6 weeks.
Starting price
from €7 900. Base-scope price. The exact price is fixed in writing before work starts. It changes only when the agreed number of entities, systems, domains, contracts, documents, interviews, languages or depth of review falls outside the base scope. No additional work is charged without prior agreement. Scope and prices.
Beyond that scope · detailed terms
- +€250 per additional supplier contract
- +€1 900 per additional legal entity in the same group
- 101–500 employees, or two regulations at once: from €13 900
Contract review and processing an ICT arrangement in the register are separate activities. If both are required beyond the included limits, the quotation lists each additional fee separately.
A larger scope is one quotation, not stacked add-ons. The extra for a second entity applies to shared systems, policies and governance — a genuinely separate environment is quoted individually. Limits do not multiply automatically; the from €13 900 figure is the starting price for the expanded project as a whole; its scope is described in one quotation.
Agreed separately
Implementing controls and remediation; a second regulation or a second entity (see extras); ongoing maintenance of the evidence.
What you prepare after we agree scope: available policies, a contract list and a responsible owner. A brief description is enough for the first conversation. Do not send passwords or health information through the form. Documents and technical information needed for the agreed work are exchanged through a secure channel arranged in advance.
We prepare the agreed materials and document the scope, findings and limitations. Decisions by regulators, auditors or clients remain theirs to make.
Specimens and preparation for commissioning
These specimens and worksheets show how outputs, your participation and acceptance are recorded. Specific terms are completed and agreed for the engagement.