DORA doesn't end at implementation.
Neither should your compliance programme.
Most financial firms treated DORA as a 2024 project. Regulators are treating it as an ongoing operational standard. Your Register of Information needs updating every year. Your board needs quarterly ICT risk reviews. Your vendor contracts need monitoring as they renew. We run all of it.
Your 2024 consultants got you paper compliant. Paper compliance doesn't survive a 2026 supervisory audit.
The CSSF in Luxembourg, the Central Bank of Ireland, and BaFin have moved from reviewing policies to examining live operational evidence. They want your current Register of Information — not the one you filed in 2024. They want board minutes from this quarter showing ICT risk was reviewed. They want contract clause logs that reflect your current vendor estate.
For a 20-person AIF manager or a 45-person UCITS ManCo, maintaining all of this internally means dedicating 2-3 days of senior practitioner time per month to DORA — time that most small financial firms simply don't have. The alternative is an outsourced DORA Maintenance Office that handles it for you, at a fraction of what an internal hire would cost.
What we do for you, month by month and year by year.
DORA compliance is a calendar-driven obligation. Here is what the annual cycle looks like and what we handle at each stage.
Annual Register of Information submission
We update your Register to reflect all vendor changes since last year, validate it against the EBA ITS data model across all 15 required templates, and manage the submission to your national regulator before the 31 March deadline. We handle the data quality checks that caused 93.5% of firms to fail in the 2024 ESA dry-run.
Board ICT risk review pack
We prepare a concise, supervisor-ready board pack covering ICT risk status, any incidents since last quarter, vendor changes, contract renewals coming due, and regulatory updates. The board reviews, approves, and the minutes are documented. We draft the agenda and supporting materials.
Vendor estate monitoring
As you add new SaaS tools, migrate infrastructure, or change service providers, we update your Register and assess Article 30 clause compliance for any new or renewing contracts. No unmonitored changes to your ICT estate.
Regulatory intelligence
EBA, EIOPA, and ESMA issue DORA guidance, Q&As, and updated technical standards throughout the year. We track every publication relevant to your entity type and flag anything that requires action, so you never miss a regulatory development.
Incident support
If a major ICT incident occurs, DORA's reporting timelines are tight — 4 hours for initial notification, 72 hours for the intermediate report. We help your team classify the incident, prepare the NCA notification, and manage the reporting timeline so you meet your obligations under pressure.
Year-end Register accuracy verification
We verify your Register is accurate as of 31 December — the statutory reference date — before it is submitted in March. Any vendor changes in Q4 are captured and correctly classified before the year closes.
The real cost of running DORA maintenance yourself.
It's not just the time. It's knowing what you don't know that gets firms into trouble with regulators.
2-3 days per month of senior time
That's the realistic ongoing DORA maintenance load for a 20-50 person financial firm. Not junior compliance staff time — senior practitioner time that understands the EBA ITS data model, Article 30 clause requirements, and how supervisors evaluate evidence.
Hiring internally costs €80K-€150K per year
An experienced ICT risk manager or DORA compliance officer at a mid-size financial firm commands €80,000-€150,000 in base salary before benefits, employer taxes, and overhead. And they have other responsibilities beyond DORA.
Regulators ask questions your team can't answer
When the CSSF or CBI sends a supervisory request, the question is usually highly specific — "provide the subcontractor chain for your portfolio management software" or "show us the exit strategy clause in your cloud hosting contract." These require someone who knows exactly where to look and exactly what the standard requires.
Continuity. Expertise. No internal headcount.
An outsourced DORA Maintenance Office works because the same senior practitioner who knows your vendor estate, your contracts, and your board is also tracking every EBA guidance update and every supervisory trend across your entity type.
We know your firm already
Ongoing maintenance works because we build institutional knowledge of your specific vendor estate, your board, and your regulatory history. A new consultant every year means starting from scratch every year.
Decades in financial institutions
Operational risk, due diligence, third-party vetting — the disciplines that DORA ongoing maintenance is actually built on. Not theory. Experience from inside firms like yours.
Written outputs that stand up
Every quarterly board pack, every Register update, every incident report is documented and filed. When your regulator asks for evidence, you have a complete, auditable record.
Affordable for mid-size firms
Structured as affordable ongoing DORA maintenance — not a Big Four retainer, not a freelancer who disappears. Senior expertise at a price point that works for a 20-50 person financial firm.
John Smutniak
Managing Partner, Regulatory Compliance PracticeWith a background in quantitative measurement and financial institution operations, John helps mid-market firms navigate complex regulatory frameworks without the overhead of a Big Four engagement. BS, Massachusetts Institute of Technology.
Tell us where you are on DORA ongoing maintenance.
We'll come back within one business day with an honest view of what ongoing support would involve for your firm and what it would cost. No pitch. No obligation.
Questions about ongoing DORA maintenance
What does ongoing DORA maintenance actually involve month to month?
At minimum: monitoring your ICT vendor estate for changes, updating the Register of Information as vendors are added or changed, preparing quarterly board ICT risk review packs, tracking new regulatory guidance from EBA, EIOPA, and ESMA, reviewing vendor contract renewals for Article 30 compliance, and maintaining your incident reporting framework as your operations evolve.
Why can we not handle ongoing DORA maintenance internally?
For a 20-50 person financial firm, ongoing DORA maintenance realistically requires 2-3 days of senior practitioner time per month. Most small and mid-size firms do not have that capacity, and hiring a full-time ICT risk manager typically costs €80,000-€150,000 per year in salary alone.
What happens if we miss the annual Register of Information submission?
The Register must be accurate as of 31 December each year and submitted to your national regulator by 31 March. Missing the deadline or submitting an inaccurate Register is a compliance breach. In the 2024 ESA dry-run, entities with incomplete Registers received formal 60-day remediation notices. Repeated failures risk enforcement action and personal liability for senior management.
We already completed our initial DORA implementation. Why do we need ongoing support?
Your initial implementation produced a snapshot of your compliance posture at a point in time. Your vendor estate changes. Contracts renew. New tools get added. Regulatory guidance evolves. Without ongoing maintenance, your compliance posture degrades — and supervisors are examining current evidence, not 2024 documentation.
How is this different from hiring a freelance DORA consultant?
A freelancer typically delivers a project and moves on. Ongoing DORA maintenance requires continuity — someone who knows your vendor estate, your board, your contracts, and your regulatory history. Our model provides that continuity without the cost of a full-time hire or the risk of starting from scratch with a new consultant every time something changes.