Regulation (EU) 2022/2554 / Applicable since 17 January 2025

DORA Compliance and the ICT Risk Management Function

DORA readiness for payment, investment, insurance and crypto entities, and the named, independent ICT risk management function Article 6(4) requires, held by a person who will sit in front of the supervisor with you.

Readiness from $15,000. The function from $4,500 per month. Fixed.

Named, independent functionRegister of information ownedSupervisor-facing
DORA compliance and ICT risk management function for EU financial entities by Atlant Security

Why Financial Entities Call Us About DORA

Your supervisor asked who owns ICT risk, not whether you ran a project

DORA has applied since 17 January 2025, and 2026 is the first full year of active supervision. Article 6(4) requires financial entities other than microenterprises to assign ICT risk management to a control function with the independence to challenge the business. A readiness deck does not answer that question. A named person does.

The register of information is due and nobody owns it

Every contractual arrangement with an ICT third-party provider has to be recorded in the register, kept current, and produced to the supervisor on request. Most mid-size entities have it half-built in a spreadsheet that nobody has updated since the first submission.

An ICT incident happened and the clock started

Major incidents must be classified and reported within DORA timelines, with initial, intermediate and final reports. If the classification matrix, the templates and the decision authority are not agreed in advance, the deadlines are missed while people argue about severity.

22,000 EU financial entities across 20 categories are supervised under DORA
DORA Article 6(4) requires an independent ICT risk management control function

The Five Pillars, and the One Nobody Can Delegate

DORA is organised around ICT risk management, incident management, resilience testing, third-party risk and information sharing. Over all five sits the management body, which approves the framework, oversees it, trains for it and stays accountable for it. Our function reports to that body; it does not replace it.

ICT risk management
Framework approved by the management body, reviewed at least annually
Incident management
Classification, reporting and lessons learned within the DORA timelines
Resilience testing
Annual testing programme; threat-led penetration testing for designated entities
Third-party risk
Register of information, contractual provisions, concentration risk, exit plans
Information sharing
Voluntary threat intelligence arrangements, properly governed
Management body
Ultimate responsibility, oversight and training obligations that cannot be delegated
What DORA supervisors are asking financial entities for in 2026
DORA has applied across the EU since 17 January 2025
Why a named ICT risk management function beats a DORA readiness project

A Named Function, Not a Finished Project

The question a supervisor asks in 2026 is not whether you ran a readiness project in 2024. It is who owns ICT risk today, how independent they are, what they reported to the management body last quarter, and whether the register is current.

We answer that by taking the seat. The appointment pack documents scope, independence, reporting line and escalation. Quarterly reports go to your management body. When the supervisor writes, we are in the room.

We do not take operational IT responsibility, and we say so, because an ICT risk function that also runs the systems is not independent.

Who Is in Scope?

Payment and e-money institutions supervised by the central bank
Investment firms, fund managers and insurers under the financial supervision authority
Crypto-asset service providers brought in scope under MiCA
ICT providers serving financial entities who must now evidence DORA-compliant contracts

Compared With the Usual DORA Offer

Atlant SecurityTypical offer
What you getA named, independent ICT risk management function with the artefacts to prove itA gap assessment deck and a policy template pack
Supervisor-facingWe stand in front of the BNB, FSC or your national authority with youThe consultant is gone by the time the supervisor writes
Incident readinessClassification, templates and decision rights agreed and drilled in advanceTemplates in a folder, untested
TestingTesting programme run by people who do penetration testing and OT assessment for a livingOutsourced twice with no one owning the results
PricingPublished fixed fees for the project and the functionQuoted after the free consultation

How the Engagement Runs

1

Scoping and proportionality

Entity type, size, supervisor and which simplified or full requirements apply. In Bulgaria that means the BNB or the FSC split and the TLPT attestation regime in force since July 2025.

2

Framework and register

ICT risk management framework and policy set built or corrected, register of information completed and reconciled to contracts, gaps remediated in priority order.

3

Incident and testing regime

Classification matrix, reporting templates, decision authority and drills. Resilience testing calendar, and TLPT scoping where you are designated.

4

The named function, ongoing

We hold the ICT risk management control function: quarterly reporting to the management body, register upkeep, testing oversight and the supervisor relationship, on a fixed monthly fee.

How the DORA engagement runs in four steps
DORA deliverables: framework, register of information, incident templates, testing plan

DORA Pricing

Published and fixed. The project gets you to a defensible state; the function keeps you there and gives the supervisor a name.

DORA Readiness Project

Single entity. Framework, register, incident regime and testing calendar.

From $15,000fixed
  • Scoping and proportionality assessment
  • ICT risk management framework and policies
  • Register of information built and reconciled
  • Incident classification matrix and templates
  • Resilience testing programme
  • Management body training and reporting pack
Book Free Scoping Call
Article 6(4)

ICT Risk Management Function

The named, independent function, held on an ongoing basis.

From $4,500per month
  • Appointment pack: scope, independence, escalation
  • Quarterly reporting to the management body
  • Register of information kept current
  • Incident classification decisions and reporting
  • Testing programme oversight, TLPT control team
  • Supervisory dialogue alongside you
Book Free Scoping Call

12-month term with quarterly exit on the function. Groups and multi-entity structures are quoted in writing before we start.

Give the Supervisor a Name

One scoping call to confirm your entity type, supervisor and proportionality, then a fixed-price plan for the project and the function.

Book Your DORA Scoping Call

Schedule Your Free DORA Scoping Call

DORA FAQ

Who does DORA apply to?
Regulation (EU) 2022/2554 applies to roughly 22,000 financial entities across 20 categories, including credit institutions, payment and e-money institutions, investment firms, fund managers, insurers and reinsurers, crypto-asset service providers and trading venues, plus the ICT third-party providers that serve them. It has applied since 17 January 2025 and is enforced by the national competent authorities, in Bulgaria the BNB and the FSC depending on the entity.
What is the ICT risk management function under Article 6(4)?
DORA requires financial entities other than microenterprises to assign responsibility for managing and overseeing ICT risk to a control function, and to ensure an appropriate level of independence for it to avoid conflicts of interest. It can be held internally or, for many entities, by an external appointee, provided the independence and reporting line to the management body are real and documented. The management body remains ultimately accountable and cannot delegate that.
Can Atlant Security hold the function for us?
For small and mid-size entities, yes. We take the seat, produce the artefacts the supervisor expects, report quarterly to your management body, and sit alongside you in supervisory dialogue. We do not take operational IT responsibility, which is what keeps the function independent. The appointment, scope, independence and escalation path are written into an appointment pack.
What is in the register of information?
A structured record of all contractual arrangements with ICT third-party providers, including the services provided, whether they support critical or important functions, subcontracting chains, contract terms and exit provisions. It must be kept current and produced to the supervisor on request, and it is the basis for the concentration risk and exit-plan work DORA also requires.
What are the incident reporting timelines?
Major ICT-related incidents must be classified against the DORA criteria and reported to the competent authority with an initial notification, an intermediate report and a final report within the deadlines set by the regulatory technical standards. In practice the classification decision has to be made within hours, which is why the matrix and the decision authority must be agreed in advance.
Do we need threat-led penetration testing?
Only entities designated by their competent authority must perform TLPT, at least every three years, using the TIBER-EU based framework. All entities need a proportionate digital operational resilience testing programme every year. We run the programme and, where you are designated, scope the TLPT and act as your control team alongside the external testers.
How much does it cost?
The DORA readiness project, covering framework, register, incident regime and testing calendar for a single entity, starts at $15,000 fixed. The ongoing ICT risk management function starts at $4,500 per month on a 12-month term with quarterly exit. Groups and multi-entity structures are quoted in writing before we start.
We already have ISO 27001. Does that cover DORA?
It covers a large part of the ICT risk management pillar and gives you the governance skeleton, but DORA adds the register of information, specific incident classification and reporting, the resilience testing programme, contractual requirements for ICT providers and explicit management body obligations. We map your ISMS to DORA so the overlap is used and the gaps are precise.

Related Services