Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

DORA Compliance Consulting

DORA Compliance: End-to-end, fixed-price

DORA has been in force since 17 January 2025. We support financial entities from gap analysis through ICT risk management build-out to the annual penetration test per Art. 25 - all from a single source, transparently priced.

ISO 27001 certified · Fixed-price commitment · DORA expertise since 2024

AWARE7 DORA Services

Regulation

Art. 5-16

Service

Gap Analysis & ICT Risk Management

Scope

Complete inventory and action plan

Regulation

Art. 17-23

Service

Incident Management & Reporting

Scope

Establish 4-hour and 72-hour reporting processes

Regulation

Art. 24-27

Service

Resilience Testing & TLPT

Scope

Annual pentests and TIBER-EU red-team tests

Regulation

Art. 28-44

Service

Third-Party Register & Contract Review

Scope

Build register, check contracts for DORA clauses

Trusted by our clients

500+
Security analyses conducted
8+
Years of experience
24h
To fixed-price quote
100%
Permanent staff experts

Our Services

The 5 DORA pillars - our services mapped

Each DORA requirement demands specific expertise. We cover all five pillars with concrete consulting services - from a single source.

01

Art. 5-16

ICT Risk Management

Build or extend the ICT risk management framework per Art. 5-16: asset inventory, risk assessment procedures, protective measures, and board-level anchoring. For ISO 27001 organisations: efficient delta mapping to DORA-specific requirements.

Gap analysis · Asset inventory · Risk management framework · Business continuity plan

02

Art. 17-23

Incident Reporting

Development and implementation of complete incident classification and reporting processes ensuring the 4-hour initial notification and 72-hour interim report to the relevant authority. Including EBA RTS-compliant reporting templates and escalation matrices.

Classification procedures · 4h/72h reporting processes · Regulatory reporting templates · SIEM integration (optional)

03

Art. 24-27

Resilience Testing

Annual penetration tests and vulnerability assessments per Art. 25 DORA for all affected financial entities. For significant institutions: preparation and conduct of Threat-Led Penetration Tests (TLPT) per TIBER-EU with OSCP-certified testers.

Annual penetration tests · Vulnerability assessments · TLPT per TIBER-EU · Supervisory coordination

04

Art. 28-44

ICT Third-Party Risks

Complete construction of the ICT third-party register per Art. 28: capture all service providers, criticality classification, concentration risk analysis. Contract analysis against DORA minimum clauses per Art. 30 and development of template contract clauses.

Third-party register (Art. 28) · Contract analysis (Art. 30) · Concentration risk analysis · Exit strategy templates

05

Art. 45

Information Sharing

Advisory on DORA-compliant build-out or joining of threat intelligence sharing communities per Art. 45. Data protection-compliant design of information exchange and connection to existing ISACs in the financial sector.

ISAC membership advisory · Data protection-compliant processes · Threat intelligence integration · Confidentiality framework

06

All Articles

Management Training

DORA requires the management body to take personal responsibility for ICT risk management and to demonstrate relevant knowledge. We offer compact DORA training for boards and senior management - practical and without unnecessary theory.

DORA overview for executives · Liability scenarios · Supervisory communication · Documentation obligations

Our approach

Our DORA consulting approach in 4 steps

Structured, transparent, and with clear milestones - this is how we guide you to demonstrable DORA compliance. All steps are calculable on a fixed-price basis.

01

Applicability analysis

Duration: 1-2 days

Clarification of your DORA category per Art. 2, scope of applicable requirements, and review of proportionality provisions for your organisation. Result: clear classification and prioritisation.

02

Gap analysis

Duration: 5-10 days

Structured review of all existing ICT risk management measures, incident processes, and third-party contracts against all DORA requirements. Result: prioritised action plan.

03

Third-party register

Duration: 3-8 days

Complete construction of the ICT third-party register per Art. 28: capture all service providers, classify criticality, review contracts for DORA compliance, identify concentration risks.

04

Penetration Testing Art. 25

Duration: annual / every 3 years

Conduct of annual resilience tests per Art. 25 DORA. For significant institutions: preparation and coordination of the TLPT process per TIBER-EU including alignment with the competent authority.

„DORA is not a paper exercise - supervisors review substantively. Financial entities that equate DORA compliance with a documentation package underestimate the requirements. Our strength is the combination of ISMS methodology and real penetration testing: we build DORA frameworks that can withstand a TLPT examination.“

Oskar Braun

ISO 27001 Lead Auditor (IRCA certified) · AWARE7 GmbH

Why AWARE7

DORA consulting from a single source

The combination of offensive security expertise and ISMS experience makes AWARE7 unique for DORA mandates - especially for the resilience testing requirements.

01

Offensive Security Expertise

AWARE7 has been conducting penetration tests for over 12 years. Our OSCP- and OSWA-certified testers know the attack techniques DORA resilience tests examine - and build your defences accordingly.

OSCP / OSWA / OSWP certificates · Red-team experience · TIBER-EU knowledge · 500+ penetration tests

02

ISMS & Compliance Experience

We are ourselves certified to ISO 27001 and ISO 9001. 20+ ISMS projects supported, all successfully certified, demonstrate our methodology. For DORA this means: no greenfield build, but efficient delta mapping based on existing ISMS structures.

ISO 27001 certified ourselves · 20+ ISMS projects · All projects successfully certified · NIS-2 synergies utilised

03

Everything from one source

Gap analysis, ICT risk management, third-party register, incident processes, and annual penetration tests - all from a single source. No coordination overhead between multiple providers, clear points of contact, consistent quality.

Unified methodology · Fixed-price quotes · 24h to quote · 100% permanent staff experts

Why AWARE7 for DORA consulting

What sets us apart from other providers

Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.

01

Research and teaching as our foundation

20 %

Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.

02

Digital sovereignty: no compromises

100 %

From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.

More on digital sovereignty
03

Fixed price within 24h: predictable project timelines

24 h

Within 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.

04

Your dedicated contact

1:1

A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.

Peer-reviewed publications

First page of the paper: Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

ACM AsiaCCS 2025

Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: A Platform for Physiological and Behavioral Security

A Platform for Physiological and Behavioral Security

NSPW 2025

Jan Hörnemann

First page of the paper: Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

IEEE/IFIP DSN 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: Understanding Regional Filter Lists: Efficacy and Impact

Understanding Regional Filter Lists: Efficacy and Impact

PoPETS 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

Who is AWARE7 the right partner for?

Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.

Your DORA experts

Our certified consultants know the regulatory requirements of the financial sector.

Affected organisations

Who does DORA apply to?

DORA applies to all financial entities per Art. 2 DORA and to critical ICT third-party providers. We support all affected entity types with tailored consulting offerings.

01

Banks & Credit Institutions

Art. 2(1)(a) DORA

Since 17 January 2025 all credit institutions - from major banks to cooperative banks - are subject to the full DORA requirements. Particularly critical: the third-party register obligation and TLPT for systemically important institutions.

02

Insurance Companies

Art. 2(1)(c) DORA

Insurance undertakings and reinsurers are fully captured by DORA. Alongside ICT risk management, requirements on engaging ICT third-party service providers and incident reporting to the competent authority are practically relevant.

03

Investment Firms

Art. 2(1)(b) DORA

Investment firms and trading venues regulated under MiFID II fall under DORA. The overlap with MiFID II operational resilience and the Market Abuse Regulation requires a coordinated compliance approach.

04

Payment Service Providers

Art. 2(1)(e/f) DORA

PSPs, e-money institutions, and payment system operators are particularly exposed: high transaction volumes, real-time settlement requirements, and distributed ICT architectures increase the risk profile.

05

ICT Third-Party Providers

Art. 31 ff. DORA

Cloud providers, data centre service providers, and software vendors classified as critical ICT third-party service providers are subject to their own DORA supervisory obligations. We support preparation for supervisory reviews.

06

Asset Managers & Fund Administrators

Art. 2(1)(d) DORA

AIFMs and investment management companies are captured by DORA and face the challenge of systematically capturing their often heterogeneous ICT landscapes. We bring experience from comparable ISMS projects in the financial sector.

Frequently asked questions

Frequently asked questions about DORA consulting

Answers to the most common questions about our DORA consulting offering, the process, and costs.

A complete DORA gap analysis typically takes 5-10 working days, depending on the size of the organisation, the number of ICT systems, and the scope of existing ICT risk management. The result is a prioritised action plan with effort estimates and a realistic implementation roadmap. We provide a transparent fixed-price quote - no open consultant days.
Yes. AWARE7 conducts Threat-Led Penetration Tests per the TIBER-EU framework. Our OSCP-certified penetration testers are experienced in demanding red-team operations against complex financial infrastructure. We coordinate the entire TLPT process: from alignment with the supervisory authority through the threat intelligence phase to the final report. For initial TLPTs we recommend a lead time of at least 6 months.
Yes. We support the complete construction of the ICT third-party register per Art. 28 DORA: capturing all ICT service providers, criticality classification, contract analysis against DORA minimum requirements, and identification of concentration risks. We also review existing contracts for DORA compliance and create template clauses for new contracts meeting DORA minimum requirements per Art. 30.
Costs depend on scope, organisational size, and existing maturity level. We work on a fixed-price basis - after the initial gap analysis we can calculate all further services concretely. For an initial orientation: a gap analysis for a mid-sized financial institution typically falls between EUR 8,000 and EUR 20,000. Contact us for an individual quote.
An existing ISO 27001 ISMS is an excellent foundation for DORA compliance and significantly reduces the implementation effort. Many DORA requirements on ICT risk management (Art. 5-16) are already covered by an ISO 27001 ISMS. The DORA-specific requirements - particularly the third-party register, TLPT, the 4-hour reporting obligation, and the financial sector-specific contract clauses - are however additional elements that must be implemented in any case.
Yes. Setting up incident classification and reporting processes that ensure the 4-hour initial notification and 72-hour deadline is part of our DORA consulting services. We develop pragmatic escalation matrices, reporting templates meeting EBA RTS requirements, and train your teams on the new processes. Optionally we implement SIEM integration for automated initial detection of major ICT incidents.

Request DORA consulting

We will prepare a transparent fixed-price quote for your DORA gap analysis within 24 hours - straight to the point.

Free · 30 minutes · No obligation

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen