DORA Diagnosis
Feasibility assessment + gap analysis and a practical roadmap (30–60–90 days + 6–12 months) with evidence ready for supervision and audit.


confirmed (services, facilities and programme boundaries).

(ICT risk, incidents, testing, third-party ICT providers, evidence).

with owners, risk-based priorities and templates (Evidence Pack).
Ideal for teams in Compliance, Risk, IT, Security, Operations and Management who need to verify compliance obligations, mitigate risk quickly and prepare evidence (both for internal purposes and for regulatory authorities).

Objective confirmation of the scope: entities, services and Critical/Important Functions (CIFs), dependencies and programme boundaries.

Map of gaps and priorities by risk: governance & ICT risk, incidents & reporting, resilience testing, third-party ICT providers and evidence.

Critical actions, including responsible parties, deadlines and minimum evidence, to gain control and reduce exposure quickly.

A realistic sequence of implementation, testing and rectification — without excessive paperwork and with a focus on execution.

Templates for policies/procedures, incidents, reporting, third-party ICT providers, records and KPIs for supervision/auditing.

Guided presentation of the results, internal alignment and definition of the implementation plan (team, decisions and timetable).
Checklist + essential evidence by pillar (IT governance/risk, incidents, testing, third-party IT providers and threat intelligence).
A simple, guided and deliverable-focused process — with evidence and priorities based on risk and effort.

Critical functions/services and dependenciesSuppliers and cloud
Objectives and deadlines (30/60/90/180)

Questionnaire + minimum evidenceScope mapping and ICF codes
Initial inventory of third-party ICT providers

Lacunas por pilar DORARisco e impacto no negócio
Prioridades e quick wins

Report + 30–60–90-day plan
6–12-month roadmap
Templates and Evidence Pack
Actual scope (CIFs + dependencies), risk-based priorities, incident preparedness and reporting, control of third-party ICT providers (contracts, records, monitoring, exit plans) and organised documentation for supervision/audit.
Quick answers to the most common questions before you carry on.
Please fill in the form (recommended) and/or book a 30-minute call on Calendly now. We’ll get back to you within 24 working hours.