Add DORA compliance verification to your service catalogue
You already run infrastructure health checks, vendor reviews and resilience tests for financial-sector clients across Europe. The technical work covers more of DORA than you'd think — here's how to package it into a billable compliance verification service, with a credential and ready-made assessment tools.
Secure Stripe checkout · instant delivery by email · EU VAT invoice
Certification included Gap-analysis & reporting templates Reusable across every client
You're already doing more of this than you think.
DORA has five pillars. Two are fundamentally technical work — the kind you already deliver.
Pillar 1 · Art. 5–16
ICT risk management
Your infrastructure health checks already touch access control, network segmentation, patch management and configuration baselines — the exact control areas DORA requires documented, owned and tested.
Pillar 2 · Art. 17–23
Incident management
The monitoring and alerting data you already collect is the raw material for DORA's incident classification and its 4-hour / 72-hour / 1-month regulatory reporting timeline, once it's mapped to the right criteria.
Pillar 3 · Art. 24–25
Resilience testing
General resilience, failover and DR testing maps to DORA's basic testing programme. (Advanced threat-led testing — TLPT, Art. 26–27 — is a separate, specially authorised discipline this kit does not cover.)
Pillar 4 · Art. 28–30
Third-party risk
Vendor and supply-chain reviews you already run for clients are the starting point for DORA's Register of Information and third-party risk register requirements.
What your technical work doesn't cover yet
Regulatory scoping — is the client in scope, and what counts as a "critical or important function" for them
A verifiable credential a client can check before they trust you with a compliance engagement
The Register of Information itself, in the exact ITS 2024/2956 format supervisors expect
Documented policies with DORA article references, not just internal runbooks
Board-level reporting your technical findings can feed into
One purchase closes the gap.
The Consultant Kit bundles the credential and the deliverables. Same product used by independent DORA consultants — it works just as well from a technical starting point.
DORA Consultant Kit
Certified DORA Advisor course + 4 template packs
€349 excl. VAT one-off
Certified DORA Advisor course & exam (€149 value)
Gap Analysis Workbook, scored by pillar & article
Register of Information Pack (ITS 2024/2956 format)
10 editable policies with DORA article references
Board-reporting pack (deck + CRO letter + KPI scorecard)
We're an IT/infrastructure company, not a law firm. Can we really offer this? +
Yes, and it's often a natural fit. Two of DORA's five pillars (ICT risk management and third-party risk) are fundamentally technical work you likely already do in health checks and vendor reviews. What you're missing is the regulatory scoping, documentation and governance layer, which is exactly what the Certified DORA Advisor course and the Consultant Kit's templates provide.
Is this the same as the "DORA for ICT Providers & Vendors" course? +
No, they answer different questions. DORA for ICT Providers & Vendors is for when your own company must satisfy a financial-sector client's DORA due-diligence demands (Article 28 flow-down). This page is for when you want to sell DORA compliance verification as a service to your own clients. If you need both, the course and the kit complement each other.
Does this let us run TLPT (threat-led penetration testing)? +
No. TLPT under Articles 26–27 is a specialised, formally authorised testing discipline run by accredited testers under a competent authority's TIBER-EU framework. The kit covers DORA's general risk-management, incident and third-party assessment work, not TLPT engagements. See our TLPT guide if that's what a client is asking for.
Several people on our team would run these assessments. Is one licence enough? +
The Consultant Kit licence covers one named person using the materials across unlimited client engagements. If more than one team member needs to run assessments and pull from the document library, the DORA Firm Licence (€1,490/year) gives your whole firm access instead.
How fast can we actually start? +
Delivery is instant: the course and every template arrive by email right after checkout. Most firms run their first internal or pilot-client assessment within a week — the gap-analysis workbook and policy pack are ready to use, not built from scratch.
Is this legal advice or a substitute for a statutory audit? +
No. These are professional assessment tools and training, not legal advice, and they don't replace a statutory audit, TLPT, or a competent authority's own supervisory review. They give you a structured, citable way to assess and document a client's DORA readiness.
Prefer to receive referred clients instead of running assessments yourselves? See our free partner programme.
Prices excl. VAT; an EU VAT invoice is issued at checkout. Professional templates and training, not legal advice.
How Compliant Is Your Institution?
Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.