DORA · Reg (EU) 2022/2554

Stay DORA Compliant & Avoid Penalties.

Regulator-accepted templates, a DORAi agent (coming soon) that tailors them to your exact ICT setup, and on-call experts who've already defended them in live EU license reviews. Built for microenterprises and CASPs — priced like it.

Built in-house. Audit-approved.
Refined in live EU regulatory reviews.

Aligned with
ESA RTS/ITS GDPR Built in the EU ISO 27001 ESMA · EBA · EIOPA
DORAi Consultant · Coming Soon

Full AI Consultant.
Coming soon.

The full DORAi agent — with document tailoring, deep workflow integration, and regulation-grounded answers across all DORA pillars — is launching soon. Try the preview below to get a feel for what's coming.

  • Trained on DORA regulation, RTS & ITS technical standards
  • Tailors your full documentation set to your exact ICT setup
  • Covers microenterprise thresholds, CASP obligations & audit prep
  • Preview available now — no account needed
DORAi Consultant — Preview Coming Soon
DORA AI Consultant
Hi, I'm your DORA Specialist. How can I help you?
Tokens used: 0 | Total available: -
The solution

Two paths to compliant. One standard of quality.

Documentation a regulator has already accepted, paired with experts who've defended it in live EU license reviews. Skip six weeks of drafting. Start audit-defensible on day one.

Regulator-accepted templates

The full DORA documentation set — ICT risk framework, incident workflow, resilience testing programme, third-party register, governance policies. Developed end-to-end in-house and already reviewed by EU regulators in live license proceedings.

  • Aligned to ESA RTS/ITS
  • Microenterprise-scoped
  • Continuously updated

Expert IT & legal guidance

On-call experts who've already defended these templates in live EU license reviews. A DORAi agent (beta) drafts your tailored version; our in-house IT and legal team reviews, refines, and stands behind it when the regulator calls.

  • DORAi agent tailoring (beta)
  • In-house IT + legal team
  • Defended in live reviews
The cost of getting it wrong

Non-compliance is no longer theoretical.

DORA entered full enforcement on January 17, 2025. National regulators across the EU are now actively reviewing ICT risk frameworks — and spreadsheets are not a defence.

2%

Of annual turnover

Maximum penalty for non-compliance with DORA obligations — per infringement.

5

Pillars to cover

Risk management, incident reporting, resilience testing, third-party risk, information sharing.

14

Days to audit-ready

From zero documentation to a defensible, tailored framework — not six weeks of drafting.

The roadmap

From zero to audit-ready in four steps.

A predictable sequence that takes you from "we have nothing on paper" to "we can walk into a regulator review with confidence" — in two weeks, not two quarters.

I.

Score your readiness

A short self-check tells you exactly where your ICT framework stands against DORA's five pillars.

II.

Ship the templates

Get the full regulator-accepted documentation set delivered the moment you start — no waiting.

III.

Tailor with DORAi

Our AI agent (coming soon) will adapt each document to your exact ICT setup, vendors, and risk profile.

IV.

Walk in audit-ready

Our in-house IT and legal team reviews the final package and stands behind it in live reviews.

Pricing

Simple pricing. Fabulous value.

Priced for microenterprises and CASPs. No seat fees, no hidden retainers, no six-figure consultancy invoice at the end.

Essentials

€199 one-time

The regulator-accepted template set. Everything you need to build a defensible DORA framework, on day one.

  • Full DORA documentation set
  • Microenterprise-scoped
  • Lifetime updates

Expert Support

Let's talk

On-call IT & legal experts who've already defended these templates in live EU license reviews. For when you need a defender, not just a document.

  • Named in-house experts
  • Live regulator review support
  • Custom scope engagements
Book a call
FAQ

Common questions. Straight answers.

Everything you need to know before you buy — or before your auditor asks.

What exactly is DORA, and does it apply to me?

The Digital Operational Resilience Act (EU 2022/2554) is binding EU law requiring all financial entities — banks, payment institutions, crypto asset service providers (CASPs), investment firms, and more — to prove their ICT systems can withstand disruptions. It has been fully applicable since 17 January 2025.

If you hold or are applying for an EU financial services or crypto licence, DORA applies to you regardless of company size.

Is my company a microenterprise under DORA?

DORA defines a microenterprise as a financial entity with fewer than 10 employees and annual turnover or balance sheet total under €2 million. Microenterprises benefit from proportionality provisions — simplified resilience testing, lighter reporting requirements — and our templates are specifically scoped to these thresholds.

What's included in the documentation set?

The Essentials bundle covers all five DORA pillars:

ICT risk management policy · Incident classification & reporting procedures · Digital operational resilience testing plan · ICT third-party provider register · Business continuity & disaster recovery runbook.

Every document is mapped directly to the relevant RTS/ITS article so you can show your regulator exactly where each requirement is addressed.

Will my national regulator accept these templates?

Yes. The templates are built from the DORA RTS/ITS texts themselves, not generic risk frameworks, and have been reviewed in live EU licensing processes. They are principle-based by design — you fill them in to reflect your actual operations, so the result is genuinely defensible rather than checkbox theatre.

What's the difference between Essentials and Compliance+?

Essentials is a one-time purchase. You get the full documentation set, lifetime updates to the templates themselves, and nothing more.

Compliance+ adds a monthly subscription: continuous updates as the RTS/ITS evolve, DORAi agent tailoring (beta), and priority email support. It's the right choice if you have an audit on the calendar or want someone watching the regulatory horizon for you.

I'm already late — is it too late to start now?

DORA has been enforceable since January 2025, so technically yes — but regulators are far more sympathetic to entities that can demonstrate a credible, documented framework, even if recently implemented, than to those with nothing at all. Starting today with a solid set of templates is still the right call.

See your score. Then decide.

Your DORA audit won't wait. Run a two-minute self-check, see exactly where you stand against the five pillars, and decide from there. No spam. No newsletter drip. GDPR-compliant.

Get the Free Checklist!

See what out templates have to offer for your business. Customize it by using your personal Agent