Skip to main content
Client Proof

Three engagements. Three licence frameworks. The same operating pattern.

These are anonymised engagement notes from CyAdviso engagements with EU-licensed fintechs. Client names and jurisdictions are withheld by NDA. The pattern — trigger, work built, evidence at the next review — is the part that transfers.

3 case studies EMI · PI · CASP Names withheld by NDA
EMI DORA

90-day programme

Fragmented ICT evidence before a supervisory review

Situation
Security work existed, but ownership, board reporting and control evidence were scattered across teams and tools.
What we built
ICT risk framework, evidence index, board pack, supplier view and remediation tracker tied to named internal owners.
Outcome
The entity could explain the control story and point to current artefacts instead of rebuilding evidence manually.
“Within 90 days, our framework was documented, defensible, and the regulator stopped repeating the same control questions.”

CEO · EU-licensed EMI

Read the full case →
PI DORA · Incident Reporting

Single engagement

Incident reporting and supplier evidence cleanup

Situation
A payment institution needed one view across incident classification, ICT providers, contract gaps and review evidence.
What we built
DORA incident workflow, Register of Information cleanup, supplier criticality rationale and board-ready remediation view.
Outcome
The team could show how incidents, suppliers and remediation connected to licensed payment services.
“Zero ICT governance documentation to a board-approved framework and a regulator-ready evidence pack.”

Managing Director · Payment Institution

Read the full case →
CASP DORA + MiCA

Single engagement

MiCA authorisation work running beside DORA readiness

Situation
A CASP needed cybersecurity and operational-resilience evidence without mixing legal authorisation work and ICT-risk delivery.
What we built
Shared evidence model for governance, ICT risk, incidents, outsourcing, resilience and board reporting.
Outcome
The handover separated MiCA legal work from DORA operating evidence, with no dependency on one undocumented owner.
“Andrey handled the cybersecurity side; our law firm handled legal. We hit the deadline. No gaps in the handover.”

COO · Crypto Asset Service Provider

Read the full case →

Client names and company logos are withheld by NDA. Licence type, regulator category and engagement outcome are the parts that transfer. Direct references are available on a discovery call with mutual consent.

Next step

What does your DORA evidence baseline look like right now?

15 minutes — we’ll review your entity type, the current state of your ICT evidence, and tell you whether you need a 90-day programme or a focused single engagement.

Or email info@cyadviso.com · No commitment.