DORA ICT TPRM • defensible outputs • fixed timelines

DORA-aligned supplier risk assessment

Expert-led supplier assessment aligned with the EU Digital Operational Resilience Act (DORA) for ICT and critical third-party providers.

L1 Essential is currently controlled/request-access. Its intended model uses scheduled public-source supplier monitoring with deterministic L1 OSINT only — no AI and no human review — where recurring execution is separately enabled. DORA Advanced and In-Depth are separate expert-led assessment services.

  • Focused on DORA-relevant supplier controls (security, resilience, governance)
  • DORA Advanced / In-Depth include human review of supplier answers & evidence
  • Clear scope and boundaries between automated L1 monitoring and expert-led DORA assessment

How the DORA assessment path works

Essential remains a separate controlled-access L1 monitoring capability. Supplier questionnaires, evidence review and expert findings begin only when you separately select DORA Advanced or In-Depth.

Step 1

Monitor with L1 Essential

Where separately enabled, deterministic L1 public-source scans establish the baseline, run scheduled comparisons and preserve traceable change history.

Step 2

Upgrade for supplier evidence

DORA Advanced / In-Depth can request structured questionnaires and supporting supplier evidence as a separate expert-led engagement.

Step 3

Receive expert-reviewed DORA findings

Advanced / In-Depth provide expert-reviewed findings, defined scope and decision-ready DORA documentation; these are outside the controlled Essential access scope.

Pricing plans

DORA preset pricing (excl. VAT). Each Advanced / In-Depth order covers one supplier and one DORA use case (preset). L1 Essential is a separate controlled-access monitoring capability; commercial terms and monitored-supplier scope are provided during access review.

DORA preset has a fixed scope (no extra modules). Custom assessments are priced per module.

VAT is applied based on customer location and VAT status. EU business customers with a valid VAT ID are typically charged 0% VAT under reverse charge.

L1 Essential

Controlled Supplier Monitoring

Best for: automated baseline and recurring public-source monitoring before or independently of a DORA expert assessment

Controlled access

Commercial terms and monitored-supplier scope are provided during access review; recurring execution is not open self-service.

  • Exact-L1 automated OSINT only — deterministic rules, no AI and no human review
  • Scheduled public-source supplier baseline and recurring monitoring where separately enabled
  • Supplier identity and objective trustworthiness-supporting public signals
  • Traceable before / after change history and updateable downloadable report
  • Provider-gated sources are identified with access limitations and official links where available
  • Decision-support indicators only — not a rating, certification, verdict, or assurance
Request Essential access

DORA questionnaires, supplier evidence review and expert assessment are outside the controlled Essential access scope.

Advanced (L2)

DORA Supplier Assessment

Best for: DORA-aligned ICT third-party risk assessment for important suppliers where an asynchronous expert assessment is sufficient

Price: €2,500 (excl. VAT)

Delivery timing starts after payment is confirmed and sufficient required inputs are received

  • DORA preset coverage across core domains (security, resilience, governance, regulatory practices)
  • Structured supplier questionnaire + evidence collection
  • Expert review of answers & evidence (manual validation)
  • Clarification follow-ups within the defined scope
  • Written findings (HTML/DOCX) + board-ready summary
Discuss DORA Advanced scopeⓘThe next step depends on your status: new users register, signed-out users sign in, unpaid assessments continue to review and payment, and already paid assessments continue directly.
In-Depth (L3)

DORA In-Depth Supplier Assessment

Best for: critical ICT and third-party providers where deeper evidence review and stronger decision support are required

Price: €4,000 (excl. VAT)

Indicative target: 10–15 business days after payment is confirmed and sufficient required inputs are received; timing may vary with supplier responsiveness, evidence quality, scheduling, and agreed scope changes

  • Everything in Advanced (L2), plus deeper evidence review and control-level findings
  • Interview workstream planned by default, with explicit disposition based on supplier availability and assessment needs
  • Clarification follow-ups + tracked evidence gaps within the defined scope
  • Traceable DORA risk narrative for defensible decisions (not certification / not assurance)
  • Written findings (HTML/DOCX) + decision-ready summary pack
  • Internal governance reuse focus (clear evidence trail within defined scope)
Request DORA In-Depth consultationⓘThe next step depends on your status: new users register, signed-out users sign in, unpaid assessments continue to review and payment, and already paid assessments continue directly.

What you pay for in the DORA Advanced (L2) plan

A defensible DORA-oriented decision summary — not more data.

  • DORA-focused risk narrative (what the supplier risk is, why it matters, and what to do next)
  • Evidence-backed findings (review of supplier responses & supporting materials within defined scope)
  • Clear boundaries: one supplier, one DORA use case; supports decision documentation (not certification)

Supports internal DORA ICT third-party risk management decisions and documentation. The sample report demonstrates DORA-specific mapping (Articles/RTS), supplier criticality context, and traceable evidence-based rationale. It does not constitute a compliance verdict, certification, legal advice, or regulatory assurance.

Discuss DORA Advanced scope Request DORA sample report

What you pay for in the DORA In-depth (L3) assessment

An in-depth, evidence-driven DORA assessment for critical ICT and third-party providers — when stronger internal decision support matters.

  • In-depth assessment (structured, evidence-driven assessment aligned to DORA expectations; suitable for internal governance, escalation, and documented follow-up)
  • Deep evidence review (manual review of supplier-provided documentation and artefacts; relevance, sufficiency, and applicability under DORA scope)
  • Control-level findings (clear conclusions at requirement/control level with explicit rationale — not just high-level scoring)
  • Traceable risk narrative (why the risk matters under DORA; what it means for ICT concentration, resilience, and operational continuity)
  • Defensible decision output (written for senior management escalation and documented internal review; reusable in risk committees and governance follow-up)
  • Clear boundaries: one supplier, one DORA use case (preset). Not certification, not assurance — maximum defensibility within defined scope.

In-depth (L3) is designed for critical suppliers and higher regulatory scrutiny scenarios. Written in a form suitable for documented internal review and governance reuse. It does not constitute legal advice, certification, or regulatory assurance.

Compare plans Request DORA In-Depth consultation

Talk to us

Tell us about your supplier and criticality. We’ll recommend the right assessment level and timeline.

Email

Email us

We typically reply within 1 business day.

Already know what you need?

You can start an assessment flow now — we’ll follow up if scope needs clarification.

Discuss DORA Advanced scope Request DORA In-Depth consultation