Who we help

ICT and managed service providers

Your customers are regulated, so their requirements now reach you: contract clauses, security questionnaires, audit rights and evidence. We help you answer them once, properly, and reuse the work.

The first conversation is free. Scope and price are confirmed in writing before work starts.

Discuss your customer requirements

Is this you?

  • You provide IT, cloud, hosting, software, data or managed services to banks, insurers, investment firms, payment or crypto-asset service providers.
  • You are a managed service provider (MSP) or managed security service provider (MSSP) — a sector NIS2 itself names.
  • Your customers in energy, health, transport or manufacturing ask you for evidence because NIS2 makes them responsible for supply-chain security.

What your customers will ask for

DORA contract clauses

Financial entities must put specific terms in ICT contracts: service descriptions, data locations, incident assistance, cooperation with authorities, termination rights, and for critical functions service levels, audit and access rights and exit plans (DORA Art. 30).

The register of information

Your services, locations and subcontractors end up in your customer’s DORA register of information (Art. 28). Errors there come back to you as questions.

Security questionnaires and evidence

Questionnaires, audit requests and requests for policies, test results and certificates. A policy alone rarely satisfies them; records of operation do.

NIS2 supply-chain requirements

NIS2 requires covered entities to manage the security of their suppliers (Art. 21(2)(d)). As an MSP or MSSP of medium size or larger you may be covered directly.

How we help

StepWhat you receivePrice
Answer a questionnaireDraft answers, organised evidence and a list of what is missingby quotation
Review DORA clausesWhat is reasonable to accept, what to negotiate, what you must be able to evidenceby quotation
Assessment and evidence packOne regulation, gaps marked, evidence organised and reusable for the next customerfrom €7 900
External expert rolesA named specialist who keeps answers, evidence and registers currentfrom €1 400 / month

Read more

Boundaries

  • We are not a certification body and do not issue legal opinions; legal questions are commissioned separately from a lawyer.
  • We do not act as a statutory EU representative (under GDPR, NIS2 or the AI Act) — that is a separate legal role.
  • Responsibility for decisions and reporting stays with the organisation’s management.

Discuss your customer requirements

EU law first, national law where it applies. EU regulations such as DORA, the AI Act and the GDPR apply directly in every Member State. Directives such as NIS2 are transposed into national law, so scope details, authorities, reporting channels and deadlines depend on the Member State where you are established or operate. Examples on this site often use Bulgarian law; in each engagement we confirm the national law that applies to you and involve local counsel where needed.