DORA Package
FlagshipOur flagship engagement. A complete, article-mapped documentation set of 50+ deliverables — ICT risk management, security policies, business continuity, incident reporting, resilience testing, and third-party risk.
We have written the documentation inside full authorisation packs for FCA and EU-regulated firms. We bring that experience to your DORA, business continuity, and data protection documentation — clear and audit-ready.
DORA documentation pack
Contents
…and the rest of the set, tailored to your entity.
Each package is a complete, article-mapped documentation set. Buy the one that closes your gap — or combine them.
Our flagship engagement. A complete, article-mapped documentation set of 50+ deliverables — ICT risk management, security policies, business continuity, incident reporting, resilience testing, and third-party risk.
The policy documentation required for EMI and PI licence applications — programme of operations, governance, risk, and ICT policies. Drafted to the regulator's requirements; you or your counsel handle the submission.
A structured review of where you stand today against DORA and adjacent regulations, with a prioritised remediation roadmap.
Information security policy suite, ICT risk controls, and incident classification and response procedures mapped to regulatory expectations.
Board-ready governance frameworks, management responsibilities, reporting lines, and control libraries written to be understood and audited.
Supplier security policy, contractual controls, supplier directory requirements, and exit strategies for material outsourcing and critical ICT providers.
Recovery objectives, response procedures, and roles that keep critical functions running through disruption — separate from the DORA ICT continuity requirements under Art. 11.
A structured assessment mapping important business services against impact tolerances and vulnerabilities.
GDPR-aligned frameworks: records of processing, DPIAs, data-subject procedures, and breach playbooks tailored to your operations.
One engagement, 50+ deliverables across 15+ sections — from board governance and risk methodology through to internal audit and corrective actions.
Risk management methodology, asset register, risk assessment and treatment tables, and a business impact analysis with per-activity questionnaires.
An information security policy and a suite of supporting policies — access control, encryption, logging, backup, change management, and more.
ICT business continuity policy, crisis management plan, business continuity plan, disaster recovery plan, and per-activity recovery plans.
Classification, escalation, incident logging, and a reporting procedure mapped to the Article 19 notification deadlines.
A testing policy and programme, plus an exercising and testing plan with vulnerability and patch management.
Supplier security policy, contractual requirements, supplier directory specification, and ICT service exit strategies.
A ready-to-use documentation set, each item mapped to the relevant DORA articles.
Most compliance packs are written document by document. The individual policies look fine — until a reviewer notices the recovery times contradict each other. Before delivery, every pack runs through our own conformance tooling.
RTO and RPO values are compared across the BIA, BCP, and DRP. If the BIA says four hours and the recovery plan says eight, you hear it from us — not from the supervisor.
Every document reference is checked for collisions and broken cross-references, so the pack indexes cleanly as one set.
Each deliverable is traced back to the provision it satisfies, so gaps surface before delivery rather than during review.
$ check pack --full
Illustrative output. Findings are resolved before the pack reaches you.
Fixed scope, transparent milestones, and no jargon. You always know where you stand.
A short discovery call and gap assessment to understand your entity, its size, and exactly which obligations apply.
We adapt our proven templates to your operations — no generic boilerplate, every document reflects how you actually work.
We walk your team through each deliverable, align with your risk appetite, and refine until everyone is confident.
You get an audit-ready set plus a maintenance plan, so your documentation stays current as the regulation evolves.
Our team has written the documentation inside full authorisation packs for FCA and EU-regulated firms. We know what reviewers expect and where packs fall short — so your documentation is precise, transparent, and built to withstand scrutiny.
We have written the documentation inside full authorisation packs for FCA and EU-regulated firms — the same rigour applied to every engagement.
We translate dense regulation into documents your whole organisation can actually read and use.
Every deliverable traces back to a specific regulatory requirement, so audits are straightforward.
Regulation changes. Our documentation is structured to be maintained, not rewritten from scratch.
A sample of recent engagements, anonymised.
| 160-document authorisation pack | Full regulatory documentation set assembled for an EMI licence application, covering all DORA-aligned pillars. |
| FCA Full API authorisation | Documentation supporting a Full API authorisation submission to the FCA. |
| ICT & outsourcing | ICT risk management framework and third-party outsourcing register for a regulated entity. |
| GDPR review | End-to-end GDPR compliance review with a prioritised remediation plan. |
DORA (Regulation (EU) 2022/2554) applies to a broad range of financial entities — from banks, investment firms, and insurers to crypto-asset service providers — as well as the critical ICT third parties that serve them. It sets requirements across ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing. We help you determine which provisions apply to your specific entity type and scale them accordingly.
Yes. Each of the nine packages stands on its own, so you can close a specific gap — say, business continuity or third-party risk — without committing to everything. Many clients start with a gap analysis or a single package and expand once they see the quality and structure.
Each package is priced as a fixed-scope engagement, with tailoring to your organisation included in that price. Combining packages is offered at a bundled rate that works out lower than taking them separately. Anything beyond the agreed scope is quoted up front on a fixed-fee basis, so there are no open-ended hourly bills. Book a scoping call and we will send a clear, itemised quote.
Absolutely. We run a structured gap assessment against your existing documentation, mapping each item back to the relevant DORA articles and adjacent obligations. You receive a prioritised findings report showing what is covered, what is missing, and what needs strengthening — plus the specific documents required to close the gaps.
Yes, and that is included in the package price — there is no separate customisation fee. Every package is built on regulator-tested structures and then adapted to your entity type, size, and operating model. The goal is documentation that reflects how your organisation actually runs — not generic templates an auditor will see straight through.
That is the whole point. Every deliverable traces back to a specific regulatory requirement, which is precisely what reviewers look for. We have written the documentation inside full authorisation packs for FCA and EU-regulated firms, so the structure and evidence trail are built to withstand that level of scrutiny.
Tell us where you are and we’ll map out exactly what your entity needs — no obligation, no jargon.
We reply within one business day. Advyco provides consulting and documentation services. We are not a law firm and do not provide legal advice.
A few details are enough to get a useful first answer.