

It depends on where you are starting from. Some organisations only need a short readiness review, while others need help with implementation or ongoing support. We usually start by understanding your setup and then suggest a scope that fits your needs and budget.
They cover similar topics, but they are not the same. DORA is a mandatory regulation for the EU financial sector. NIS2 applies to a wider range of organisations, and ISO 27001 is a voluntary standard. If you already work with NIS2 or ISO 27001, you are part of the way there, but DORA still adds its own requirements.
DORA is about helping EU financial organisations stay operational during disruptions. It sets clear rules for ICT risk management, incident reporting, business continuity and recovery planning, resilience testing, and oversight of critical ICT suppliers.