Services for your situation
Choose a specific first task, a broader assessment or ongoing support. Scope and price are confirmed in writing before work starts.
A customer has sent a questionnaire? Start with the response guide and Excel workbook. If the uncertainty is legal scope, the NIS2 applicability guide shows which facts to collect. For recurring work, see Compliance-as-a-Service: monthly compliance support. For a rejected register, see DORA register validation and correction.
Start with a specific task
You do not need to commission a large package. First we clarify the result you need.
Check which rules apply
A short written DORA / NIS2 applicability conclusion, its basis and the next actions.
3–5 working days
One legal entity; initial analysis, not a legal opinion.
Scope and outputs →Respond to a customer questionnaire
Draft answers, organised evidence and a list of missing items.
By written quotationUsually 5–15 working days
You approve the final answers; this is not certification.
Scope and outputs →Make a specific technical improvement
Investigate the problem and deliver agreed corrections, followed by verification.
By written quotationTimeline after scoping
Checks, changes and required access are set out in the quote.
Scope and outputs →Respond to a customer questionnaire
Completed draft answers, organised supporting evidence for reuse and a clear list of missing items.
When you need a broader assessment
Three services with a defined base scope. Assessment and implementation are commissioned separately.
DORA / NIS2 assessment and evidence
Get a gap assessment, a review of the agreed documents and an organised record of available evidence, with missing items and next actions clearly identified.
from €7 9003–5 weeks; DORA: 3–6
One regulation in the base scope. Implementation and independent certification are not included.
Scope and outputs →Business email and domain review
Get an assessment of the agreed domains and signals, prioritised actions and a report your team can use.
from €2 4005–10 business days
Assessment only; technical remediation is scoped separately.
Scope and outputs →AI use review
Get an inventory of identified uses, a risk register and rules for acceptable use and approval.
from €5 9003–4 weeks
Coverage depends on surveys, interviews and supplied records; this is not continuous technical monitoring.
Scope and outputs →Ongoing support
From €1 400 per month for 8 expert hours. Tasks, service window and response are agreed in advance; larger plans are on the service page.
Scope and outputs →Who we work with
Businesses facing customer requirements and financial organisations. We clarify applicable rules and the work already covered by your IT team.
Other services and specialist capabilities
Email and domain monitoring
Recurring checks of the agreed domains and sending services, selected authentication, blocklist, reputation and deliverability signals, with alerts and a concise report at the agreed frequency.
monthly subscription. By written quotation after scope and monitoring frequency are agreed. Coverage and response times are agreed in advance. Monitoring cannot guarantee inbox placement, immediate delisting or discovery of every impersonating domain; technical remediation is included only when stated in the plan.
Describe your problem →DORA register diagnostic
from €2 600 · Scope and outputs →
Training and human factors
Workplace wellbeing
A separate service for leaders and HR, with a practical action plan. Scope and outputs →
Make a specific technical improvement → · Prices and scope →
Specialist work is quoted after scope is clarified.
- Regulatory and compliance advisory
- DORA, NIS2, the EU AI Act, the Cyber Resilience Act, GDPR and MiCA: gap assessments, priority plans, supplier-contract review, Register of Information preparation, third-party risk programmes.
- Certification and attestation readiness
- ISO/IEC 27001, ISO/IEC 42001 and SOC 2 — control design, policy sets and evidence discipline before an auditor is engaged. The certification body stays independent, as it must.
- Email, domain and impersonation protection
- Analysis and agreed improvements to SPF, DKIM, DMARC, sending configuration, domain reputation and impersonation exposure. Delisting and inbox placement remain outside our control.
- Security questionnaires and vendor due diligence
- A recurring task for suppliers selling to regulated organisations. We prepare the responses and organise reusable supporting evidence.
- Product, cloud and DevSecOps security
- Architecture, access, secrets, cloud configuration, CI/CD, infrastructure as code, secure development practices and readiness for customer or audit scrutiny.
- AI security and governance
- Shadow-AI discovery, AI inventories and governance, ISO/IEC 42001 gap analysis, and risk review of AI agents and their connectors.
- Fractional security leadership
- Designated, accountable security leadership in clear monthly tiers; responsibility and independence are agreed for each engagement.
- Incident readiness and exercises
- Plans, roles, reporting templates and tabletop exercises for management and technical teams. Emergency response and forensics are arranged separately with confirmed specialists.
What to prepare for the first conversation
Describe the actual activity and licence, size and ownership information, and the request with its deadline. “40 employees” and “a services company” are not enough to decide. See how applicability is assessed.