🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
DORANIS2ISO 27001CR-DORA-01

DORA ICT Risk Assessment

DORA-specific ICT risk assessment for financial sector. ICT asset inventory, risk framework, third-party dependencies, resilience strategy. Ready for financial regulator review. €539.

DORA ICT Risk Assessment by Optimum Web is a fixed-price compliance service covering DORA Chapter II — ICT Risk Management Framework. It costs €539 with 7–10 business days delivery by senior security engineers. ICT systems inventory and information asset classification. 14-day warranty included.

€539
Fixed price, VAT excluded
7–10 business daysSenior only
ICT systems inventory and information asset classification
ICT risk assessment per DORA Chapter II methodology
Third-party ICT provider dependency map and risk evaluation
Digital operational resilience strategy document
🛡️
14-Day Warranty
If the delivered pack does not match your ISMS scope and Statement of Applicability, we rework it at no cost, or refund in full within 14 days of delivery.

Secured by PayPal · 256-bit SSL encryption

or order without payment
+373 22 843569
PayPal · SSL
👨‍💻 Senior only
14-day warranty
🆔 CR-DORA-01

This Service Covers

DORAChapter II — ICT risk management framework
NIS2Article 21(2)(a) — Risk analysis
ISO 27001Clause 6.1.2 — Risk assessment

What You Get

ICT risk assessment specifically for financial sector entities subject to DORA (Digital Operational Resilience Act). We assess: ICT systems inventory, information asset classification, threat landscape specific to financial services, ICT risk identification and assessment per DORA Chapter II requirements, third-party ICT provider dependencies, and digital operational resilience strategy. Result: DORA-compliant ICT risk management framework documentation ready for financial regulator review.

Who Needs This

  • Banks, insurance companies, and payment firms subject to DORA
  • Fintech companies needing DORA compliance by January 2025
  • Financial sector IT service providers classified as critical third parties
  • Investment firms requiring ICT risk management documentation

How It Works

  1. 1
    ICT Inventory

    Catalogue all ICT systems, classify information assets, map dependencies

  2. 2
    Risk Assessment

    Identify ICT threats specific to financial services, assess risks per DORA

  3. 3
    Third-Party Analysis

    Map critical third-party ICT providers, assess concentration risk

  4. 4
    Framework Delivery

    DORA-compliant ICT risk management framework + resilience strategy

NEXT STEP

Ready to Implement the Findings?

After the assessment, our fixed-price implementation services cover every gap — from GDPR backup (€449) to incident response (€359). No surprises.

Browse Fix Services

Ready to Start?

€539 · 7–10 business days · 14-day warranty

Secured by PayPal · 256-bit SSL encryption

or order without payment

Ready to implement? Browse individual fix services

Learn more

Frequently Asked Questions

Who does DORA apply to?+
DORA (Digital Operational Resilience Act) applies to all EU-regulated financial entities: credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers, insurance undertakings, and — critically — their critical ICT third-party providers (cloud providers, SaaS vendors, data analytics providers). If you hold an EU financial license or are a critical ICT provider to a financial entity, DORA applies.
What is DORA operational resilience?+
DORA defines operational resilience as the ability to build, assure, and review operational integrity and reliability of ICT services. It requires: ICT risk management framework (Articles 5-15), ICT incident classification and reporting (Articles 17-23), digital operational resilience testing (Articles 24-25), ICT third-party risk management (Articles 28-44), and information sharing arrangements. Our assessment covers Articles 5-15.
Is DORA applicable to my company?+
DORA applies to all EU-regulated financial entities: banks, insurance, investment firms, payment institutions, crypto-asset service providers, and their critical ICT third-party providers. If you hold a financial license in the EU, DORA likely applies.
How does DORA differ from NIS2?+
DORA is sector-specific for financial services with stricter requirements: ICT-specific risk assessment, mandatory third-party risk management, and digital resilience testing including TLPT. NIS2 is broader and applies across critical sectors. Financial entities subject to DORA must comply with both; where they overlap, DORA takes precedence.
What are DORA Article 24-25 testing requirements?+
DORA Article 24 requires all financial entities to establish digital operational resilience testing including vulnerability assessments, network security assessments, gap analyses, physical security reviews, questionnaire-based assessments, and source code reviews. Articles 26–27 require advanced Threat-Led Penetration Testing (TLPT) — similar to TIBER-EU — for significant financial entities every 3 years. We cover Article 24 testing; TLPT/TIBER-EU requires accredited providers.
Do you assess third-party cloud providers (AWS, Azure, GCP)?+
Yes. DORA Article 28 requires financial entities to manage ICT third-party risk. We assess your dependency on cloud providers, SaaS tools, and critical ICT service providers — including concentration risk (over-reliance on a single provider).
Can this be combined with ISO 27001 risk assessment?+
Yes. DORA and ISO 27001 risk assessments share significant overlap. If pursuing both, we recommend doing them together — saves approximately 40% of effort and cost.
How much does DORA compliance cost?+
Our ICT risk assessment (€539) is the starting point. Depending on gaps found, remediation typically runs €3k–15k for a mid-size financial entity. For comparison, Big-4 DORA readiness assessments cost €15,000–50,000+. We deliver equivalent technical assessment at a fraction of the cost.

Service page last reviewed 11 August 2026 by the Optimum Web compliance team.

Secured by PayPal · 256-bit SSL encryption

or order without payment