DORA Compliance and the ICT Risk Management Function
DORA readiness for payment, investment, insurance and crypto entities, and the named, independent ICT risk management function Article 6(4) requires, held by a person who will sit in front of the supervisor with you.
Readiness from $15,000. The function from $4,500 per month. Fixed.

Why Financial Entities Call Us About DORA
Your supervisor asked who owns ICT risk, not whether you ran a project
DORA has applied since 17 January 2025, and 2026 is the first full year of active supervision. Article 6(4) requires financial entities other than microenterprises to assign ICT risk management to a control function with the independence to challenge the business. A readiness deck does not answer that question. A named person does.
The register of information is due and nobody owns it
Every contractual arrangement with an ICT third-party provider has to be recorded in the register, kept current, and produced to the supervisor on request. Most mid-size entities have it half-built in a spreadsheet that nobody has updated since the first submission.
An ICT incident happened and the clock started
Major incidents must be classified and reported within DORA timelines, with initial, intermediate and final reports. If the classification matrix, the templates and the decision authority are not agreed in advance, the deadlines are missed while people argue about severity.


The Five Pillars, and the One Nobody Can Delegate
DORA is organised around ICT risk management, incident management, resilience testing, third-party risk and information sharing. Over all five sits the management body, which approves the framework, oversees it, trains for it and stays accountable for it. Our function reports to that body; it does not replace it.



A Named Function, Not a Finished Project
The question a supervisor asks in 2026 is not whether you ran a readiness project in 2024. It is who owns ICT risk today, how independent they are, what they reported to the management body last quarter, and whether the register is current.
We answer that by taking the seat. The appointment pack documents scope, independence, reporting line and escalation. Quarterly reports go to your management body. When the supervisor writes, we are in the room.
We do not take operational IT responsibility, and we say so, because an ICT risk function that also runs the systems is not independent.
Who Is in Scope?
Compared With the Usual DORA Offer
| Atlant Security | Typical offer | |
|---|---|---|
| What you get | A named, independent ICT risk management function with the artefacts to prove it | A gap assessment deck and a policy template pack |
| Supervisor-facing | We stand in front of the BNB, FSC or your national authority with you | The consultant is gone by the time the supervisor writes |
| Incident readiness | Classification, templates and decision rights agreed and drilled in advance | Templates in a folder, untested |
| Testing | Testing programme run by people who do penetration testing and OT assessment for a living | Outsourced twice with no one owning the results |
| Pricing | Published fixed fees for the project and the function | Quoted after the free consultation |
How the Engagement Runs
Scoping and proportionality
Entity type, size, supervisor and which simplified or full requirements apply. In Bulgaria that means the BNB or the FSC split and the TLPT attestation regime in force since July 2025.
Framework and register
ICT risk management framework and policy set built or corrected, register of information completed and reconciled to contracts, gaps remediated in priority order.
Incident and testing regime
Classification matrix, reporting templates, decision authority and drills. Resilience testing calendar, and TLPT scoping where you are designated.
The named function, ongoing
We hold the ICT risk management control function: quarterly reporting to the management body, register upkeep, testing oversight and the supervisor relationship, on a fixed monthly fee.


DORA Pricing
Published and fixed. The project gets you to a defensible state; the function keeps you there and gives the supervisor a name.
DORA Readiness Project
Single entity. Framework, register, incident regime and testing calendar.
- Scoping and proportionality assessment
- ICT risk management framework and policies
- Register of information built and reconciled
- Incident classification matrix and templates
- Resilience testing programme
- Management body training and reporting pack
ICT Risk Management Function
The named, independent function, held on an ongoing basis.
- Appointment pack: scope, independence, escalation
- Quarterly reporting to the management body
- Register of information kept current
- Incident classification decisions and reporting
- Testing programme oversight, TLPT control team
- Supervisory dialogue alongside you
12-month term with quarterly exit on the function. Groups and multi-entity structures are quoted in writing before we start.
Give the Supervisor a Name
One scoping call to confirm your entity type, supervisor and proportionality, then a fixed-price plan for the project and the function.
Book Your DORA Scoping Call