More DORA, MiCA & NIS2 questions, answered
The homepage covers the questions most people ask first. These nine cover team capacity, jurisdiction, exit terms and continuity, the questions that come up once you are already comparing options.
Common worries (the fears)
We’re a small team. Can we actually implement all of DORA?
DORA is proportional, smaller firms have lighter requirements. We scope everything to your size. Most of the heavy lifting (policy writing, risk assessment, supplier mapping) is done by us. Your team reviews and approves, typically 2-4 hours per week.
What if our internal team does not cooperate?
We build ownership inside the organisation from day one: each artefact has a named internal owner, decision owner and review cadence. The 2-4 hours per week usually means short evidence reviews, owner interviews and approvals, not a second full-time project. If a team member is unresponsive, we surface the dependency in the remediation tracker so management can decide whether to escalate, accept the risk or change ownership.
Does NIS2 management-body accountability really apply to me as a CEO?
NIS2 management-body accountability is implemented through national law, and details vary by jurisdiction (penalties, scope, reporting routes are jurisdiction-specific). Where you operate, the core obligation (that board members hold accountability for cybersecurity governance) typically applies under the local transposition. The practical fix is named ownership of ICT risk and documented oversight, both of which we deliver.
Can you present to our board or management body directly?
Yes. Board and management-body reporting is included in the retainer. Delivery options: written report (board-approved template), slide deck, or a 30-minute working session. Most management-body members want three things: a named owner, a current status, and a clear next action. That is what the reporting delivers.
How it actually works (the constraints)
Is there an exit clause?
Yes, 30 days’ notice after month 3 on the retainer. No long lock-ins.
How much of our team’s time does this take?
2-4 hours per week for reviews and approvals. We do the heavy lifting; your team owns the decisions.
Which jurisdictions do you cover?
Primary: EU fintech jurisdictions. Engagements have been performed under EU financial-sector supervision. Other EU Member States on request.
What if our evidence is scattered and we keep rebuilding it before every review?
That’s exactly the problem we solve most often. We restructure evidence packs, establish ownership, and build control traceability, so you stop answering the same questions repeatedly under audit.
You’re one person. What if you’re unavailable when we have an incident?
CyAdviso is a registered company (SIA CyAdviso, Latvia), not a freelancer. For retainer clients, incident response access is defined in the service agreement with stated response times. On-call protocols for out-of-hours material incidents are part of the retainer scope. All client environments use shared, structured documentation. There is no tribal knowledge dependency on a single person’s memory.
Can’t find your question? Ask it, or book a 15-min call, or email info@cyadviso.com.
Still working out whether this fits your team?
15 minutes: walk through your entity type, current ICT-risk evidence and whether a single engagement or the 90-day programme fits your gap.
Or email info@cyadviso.com · No commitment.