DORA compliance for mid-market financial firms.
Senior expertise. Without the Big Four bill.
More than 22,000 financial entities across the EU fall within DORA scope. Regulators in Luxembourg, Ireland, and Germany have stopped reviewing policies. They are demanding evidence. If your firm is in the half that still has gaps — or thinks it doesn't but hasn't checked recently — we should talk.
Your 2024 consultants and lawyers got you paper compliant. DORA requires an ongoing operational team.
In late 2024, hundreds of fund managers, ManCos, and insurers hired law firms and consultants to pull together a DORA policy manual before the January 2025 deadline. It worked — on paper. What they got was a policy folder and a bill. What they didn't get was anyone to run it year after year.
Regulators have moved on. The CSSF in Luxembourg, the Central Bank of Ireland, and BaFin in Germany are no longer reviewing policies. They want your 2026 Register of Information built to the EBA ITS data model — 15 interconnected templates, over 100 mandatory fields. They want board minutes showing ICT risk was reviewed this quarter. They want Article 30 contract clause logs for every critical vendor. A policy folder doesn't answer those questions. An operational team does.
You filed the paperwork. Now regulators want the evidence.
The CSSF, Central Bank of Ireland, and BaFin have moved from guidance mode to active supervisory audits. The EBA peer review on DORA implementation is scheduled for Q3 2026. Three questions your 2024 policy folder cannot answer.
Show us your Register of Information
Not last year's version. The current one, built to the EBA ITS data model, accurate as of 31 December 2025. If you built yours in Excel in 2024 and haven't touched it since, it almost certainly has errors. The ITS requires relational integrity across 15 interconnected templates that spreadsheets cannot maintain.
Show us your board minutes
DORA requires the board to review ICT risk logs quarterly. Not annually. Every quarter, documented, auditable. In November 2025 the ESAs designated 19 Critical ICT Third-Party Providers including AWS, Microsoft Azure, Google Cloud, and Bloomberg. If your board hasn't discussed this, that conversation is overdue.
Show us your vendor contract logs
Article 30 mandatory clauses — audit rights, exit strategies, subcontractor disclosure — must be in every critical ICT contract. Contracts signed before January 2025 are often not updated. Your renewals are coming. Are your contracts ready?
Built for the firms the Big Four won't take — and freelancers can't handle.
Mid-size financial institutions with real DORA obligations, small internal teams, and no appetite for a six-figure engagement that delivers methodology decks instead of compliance evidence.
AIF Managers
Hedge funds, private equity, real estate, infrastructure — historically lightly regulated, now fully in DORA scope. Among the highest-risk non-compliant segments in Europe right now. We know this space well.
DORA for AIF Managers →UCITS ManCos
UCITS management companies oversee dozens of funds with heavily outsourced tech stacks and small internal headcounts. That combination makes ongoing DORA maintenance genuinely difficult without outside help.
DORA for UCITS ManCos →Fintechs with EU Licences
Payment institutions and e-money institutions with live DORA obligations and typically no dedicated security function. We move fast for these clients.
DORA for Fintechs →Insurance Brokers & Regional Insurers
IT governance is often informal, vendor contracts lack Article 30 provisions, and the Register of Information was never properly built. High-risk, under-advised, and within our sweet spot.
From gap to compliant. And then keeping you there.
Every engagement produces written, supervisor-ready outputs — not slide decks. Things you can put in front of your regulator without flinching.
DORA Scoping Determination
A written memo confirming which DORA obligations apply to your firm — entity type, applicable articles, proportionality assessment, recommended next steps. Delivered within 3 business days. The sensible place to start if you're not sure where you stand.
DORA Diagnostic
Two to three days of structured review across all five DORA pillars. You get a gap register, a prioritised remediation roadmap, and a plain-English board summary. Fixed price. Fixed scope. No surprises. Designed for firms that implemented in 2024 and need to know where they actually stand in 2026.
Register of Information
We build your Register from scratch or fix an existing one — mapping every ICT vendor, critical function classification, and subcontractor chain against the EBA ITS data model across all 15 required templates. Validated and submission-ready.
About the Register of Information →ICT Contract Review (Article 30)
We review your vendor contracts against DORA's mandatory Article 30 provisions and deliver a gap matrix with negotiation language for every missing clause. Technical governance work — not legal advice. Essential before any contract renewal.
About Article 30 →Outsourced DORA Maintenance Office
Your Register needs to be accurate every 31 December and submitted by March 31. Your board needs quarterly ICT risk reviews. Your vendor contracts need monitoring as they renew. We run all of this as your outsourced DORA operational team — affordable ongoing DORA maintenance at a fraction of what an internal hire would cost.
About Ongoing Maintenance →ICT Vendor DORA Readiness
Your EU financial institution clients are asking you to sign DORA-compliant contract addenda. We review what they're asking you to sign, explain what each clause requires operationally, and identify where you have gaps. Technical governance — not legal advice.
For ICT Vendors →"Your 2024 law firm filed the paperwork. We keep the lights on."
Not a Big Four project. Not a freelancer.
Something that actually works for your size of firm.
| Factor | Big Four | Freelancer | MeasurementPros |
|---|---|---|---|
| Minimum engagement | €150,000+ | Variable | €399 |
| Takes mid-size fund managers | Rarely | Sometimes | Always |
| Ongoing maintenance | Extra project | Usually not | Core service |
| Named senior practitioner | No | Yes | Yes |
| Fixed price options | No | Sometimes | Yes |
| Supervisor-ready written outputs | Yes | Variable | Always |
We've done this work. Inside firms like yours.
The DORA advisory market has two modes — enormous engagements that treat a 20-person fund manager like a tier-one bank, and solo freelancers who disappear after the first deliverable. We sit in neither camp.
Decades inside financial institutions
Operational risk, due diligence, third-party vetting — the disciplines DORA is actually built around. We've done this work inside the kinds of firms we now advise. That matters when a regulator asks something that isn't in the textbook.
We work across frameworks
DORA, ISO 27001, GDPR, NIS2. Where your existing controls already satisfy DORA requirements, we document that and move on. No rebuilding what you already have.
Written outputs. Every time.
Gap registers. Contract review matrices. Board packs. Register builds. Not verbal advice. Documents that go in your compliance evidence file and stay there when a supervisor comes calling.
Accessible for mid-size firms
We work with firms the Big Four won't take as clients and that need more than a freelancer can provide. Engagements scoped to what you actually need — not padded for a partner's utilisation targets.
John Smutniak
Managing Partner, Regulatory Compliance Practice[2-sentence credential summary — your background in financial institution operational risk, due diligence, and regulatory compliance. You provide this.]
Free DORA gap review — written summary within 5 business days.
Tell us where you are on DORA. We'll come back with an honest picture of your gaps and what closing them actually involves. No pitch. No obligation. Just a straight answer from someone who has done this work.
Questions we get asked every week
Is DORA implementation really over for most firms?
The initial setup phase is largely done for firms that acted in 2024. But DORA is not a one-time project. The Register of Information must be updated and submitted every year. Board ICT risk reviews must happen every quarter. Vendor contracts must be monitored as they renew. Most firms that did the initial work are now discovering they have no one to run it on an ongoing basis. That is the real gap in 2026.
What is the Register of Information and why does it keep causing problems?
It is a mandatory inventory of every ICT vendor contract your firm holds, submitted to your national regulator in a specific EBA format every year by 31 March. The ITS data model specifies 15 interconnected templates with over 100 mandatory fields covering entities, contracts, functions, sub-outsourcing chains, and risk assessments. In the 2024 ESA dry-run exercise, only 6.5% of participating firms passed all data quality checks. Most built their first Register in a spreadsheet. That approach breaks at submission.
What does DORA actually require at board level?
The board must approve the ICT risk management framework, review ICT risk logs quarterly, and take personal accountability for DORA compliance. Individual senior managers can face personal fines of up to €1 million for serious breaches. Board members who assumed DORA was an IT department problem are being reminded otherwise by their regulators right now.
Do DORA obligations apply to AIF managers and UCITS ManCos?
Yes. Both are explicitly in scope under DORA Article 2. AIF managers — hedge funds, private equity, real estate, infrastructure funds — are among the highest-risk non-compliant segments in 2026. Historically lightly regulated, now fully subject to the same obligations as banks and insurers. UCITS ManCos face the same obligations and often have slightly more compliance infrastructure to build from.
What does ongoing DORA maintenance actually involve?
At minimum: keeping the Register of Information accurate and submitting it annually, running quarterly board ICT risk reviews, monitoring vendor contract renewals for Article 30 compliance, and tracking regulatory updates from EBA, EIOPA, and ESMA. For a 20-person fund manager this is realistically 2-3 days of senior practitioner time per month. Most firms do not have that capacity internally — which is exactly why the outsourced DORA Maintenance Office model exists.
We are an ICT vendor. Does DORA apply to us?
Not directly. DORA regulates financial entities, not their suppliers. But if your clients are EU financial institutions, their DORA obligations flow down to you contractually. Under Article 30, financial entities must include mandatory clauses in every ICT contract — audit rights, exit strategies, subcontractor disclosure, data location. Your clients are asking you to sign these addenda right now. We help ICT vendors understand what they are agreeing to and where they have operational gaps. This is technical governance work, not legal advice.