DORA doesn't end at implementation.
Neither should your compliance programme.

Most financial firms treated DORA as a 2024 project. Regulators are treating it as an ongoing operational standard. Your Register of Information needs updating every year. Your board needs quarterly ICT risk reviews. Your vendor contracts need monitoring as they renew. We run all of it.

Register of Information
Quarterly Board Reviews
Annual RoI Submission
Vendor Monitoring
Regulatory Updates

Your 2024 consultants got you paper compliant. Paper compliance doesn't survive a 2026 supervisory audit.

The CSSF in Luxembourg, the Central Bank of Ireland, and BaFin have moved from reviewing policies to examining live operational evidence. They want your current Register of Information — not the one you filed in 2024. They want board minutes from this quarter showing ICT risk was reviewed. They want contract clause logs that reflect your current vendor estate.

For a 20-person AIF manager or a 45-person UCITS ManCo, maintaining all of this internally means dedicating 2-3 days of senior practitioner time per month to DORA — time that most small financial firms simply don't have. The alternative is an outsourced DORA Maintenance Office that handles it for you, at a fraction of what an internal hire would cost.

31 Mar Annual Register of Information submission deadline. Every year. Miss it and you're in breach.
Quarterly Board ICT risk review frequency required by DORA. Not annually. Every quarter.
60 days Remediation window given to firms with inaccurate Registers in the first supervisory wave.
€1M Maximum personal fine for senior managers who fail to maintain DORA compliance.

What we do for you, month by month and year by year.

DORA compliance is a calendar-driven obligation. Here is what the annual cycle looks like and what we handle at each stage.

Jan–Mar

Annual Register of Information submission

We update your Register to reflect all vendor changes since last year, validate it against the EBA ITS data model across all 15 required templates, and manage the submission to your national regulator before the 31 March deadline. We handle the data quality checks that caused 93.5% of firms to fail in the 2024 ESA dry-run.

Every quarter

Board ICT risk review pack

We prepare a concise, supervisor-ready board pack covering ICT risk status, any incidents since last quarter, vendor changes, contract renewals coming due, and regulatory updates. The board reviews, approves, and the minutes are documented. We draft the agenda and supporting materials.

Ongoing

Vendor estate monitoring

As you add new SaaS tools, migrate infrastructure, or change service providers, we update your Register and assess Article 30 clause compliance for any new or renewing contracts. No unmonitored changes to your ICT estate.

Ongoing

Regulatory intelligence

EBA, EIOPA, and ESMA issue DORA guidance, Q&As, and updated technical standards throughout the year. We track every publication relevant to your entity type and flag anything that requires action, so you never miss a regulatory development.

As needed

Incident support

If a major ICT incident occurs, DORA's reporting timelines are tight — 4 hours for initial notification, 72 hours for the intermediate report. We help your team classify the incident, prepare the NCA notification, and manage the reporting timeline so you meet your obligations under pressure.

Dec 31

Year-end Register accuracy verification

We verify your Register is accurate as of 31 December — the statutory reference date — before it is submitted in March. Any vendor changes in Q4 are captured and correctly classified before the year closes.

The real cost of running DORA maintenance yourself.

It's not just the time. It's knowing what you don't know that gets firms into trouble with regulators.

2-3 days per month of senior time

That's the realistic ongoing DORA maintenance load for a 20-50 person financial firm. Not junior compliance staff time — senior practitioner time that understands the EBA ITS data model, Article 30 clause requirements, and how supervisors evaluate evidence.

Hiring internally costs €80K-€150K per year

An experienced ICT risk manager or DORA compliance officer at a mid-size financial firm commands €80,000-€150,000 in base salary before benefits, employer taxes, and overhead. And they have other responsibilities beyond DORA.

Regulators ask questions your team can't answer

When the CSSF or CBI sends a supervisory request, the question is usually highly specific — "provide the subcontractor chain for your portfolio management software" or "show us the exit strategy clause in your cloud hosting contract." These require someone who knows exactly where to look and exactly what the standard requires.

Continuity. Expertise. No internal headcount.

An outsourced DORA Maintenance Office works because the same senior practitioner who knows your vendor estate, your contracts, and your board is also tracking every EBA guidance update and every supervisory trend across your entity type.

We know your firm already

Ongoing maintenance works because we build institutional knowledge of your specific vendor estate, your board, and your regulatory history. A new consultant every year means starting from scratch every year.

Decades in financial institutions

Operational risk, due diligence, third-party vetting — the disciplines that DORA ongoing maintenance is actually built on. Not theory. Experience from inside firms like yours.

Written outputs that stand up

Every quarterly board pack, every Register update, every incident report is documented and filed. When your regulator asks for evidence, you have a complete, auditable record.

Affordable for mid-size firms

Structured as affordable ongoing DORA maintenance — not a Big Four retainer, not a freelancer who disappears. Senior expertise at a price point that works for a 20-50 person financial firm.

John Smutniak, Managing Partner

John Smutniak

Managing Partner, Regulatory Compliance Practice

With a background in quantitative measurement and financial institution operations, John helps mid-market firms navigate complex regulatory frameworks without the overhead of a Big Four engagement. BS, Massachusetts Institute of Technology.

Tell us where you are on DORA ongoing maintenance.

We'll come back within one business day with an honest view of what ongoing support would involve for your firm and what it would cost. No pitch. No obligation.

Response within one business day Confidential — NDA on request All EU financial entity types welcome No obligation to proceed

Your information is kept strictly confidential.

Thank you — we will be in touch within one business day.

Questions about ongoing DORA maintenance

What does ongoing DORA maintenance actually involve month to month?

At minimum: monitoring your ICT vendor estate for changes, updating the Register of Information as vendors are added or changed, preparing quarterly board ICT risk review packs, tracking new regulatory guidance from EBA, EIOPA, and ESMA, reviewing vendor contract renewals for Article 30 compliance, and maintaining your incident reporting framework as your operations evolve.

Why can we not handle ongoing DORA maintenance internally?

For a 20-50 person financial firm, ongoing DORA maintenance realistically requires 2-3 days of senior practitioner time per month. Most small and mid-size firms do not have that capacity, and hiring a full-time ICT risk manager typically costs €80,000-€150,000 per year in salary alone.

What happens if we miss the annual Register of Information submission?

The Register must be accurate as of 31 December each year and submitted to your national regulator by 31 March. Missing the deadline or submitting an inaccurate Register is a compliance breach. In the 2024 ESA dry-run, entities with incomplete Registers received formal 60-day remediation notices. Repeated failures risk enforcement action and personal liability for senior management.

We already completed our initial DORA implementation. Why do we need ongoing support?

Your initial implementation produced a snapshot of your compliance posture at a point in time. Your vendor estate changes. Contracts renew. New tools get added. Regulatory guidance evolves. Without ongoing maintenance, your compliance posture degrades — and supervisors are examining current evidence, not 2024 documentation.

How is this different from hiring a freelance DORA consultant?

A freelancer typically delivers a project and moves on. Ongoing DORA maintenance requires continuity — someone who knows your vendor estate, your board, your contracts, and your regulatory history. Our model provides that continuity without the cost of a full-time hire or the risk of starting from scratch with a new consultant every time something changes.

← Back to DORA Compliance overview