DORA & NIS2 Compliance Providers in the EU

If NIS2 or DORA applies to your organisation, being in scope is rarely the problem. Finding the right firm to help you close the gap is, because the specialists who do this work are spread across hundreds of separate sites with no way to compare them side by side.

This directory brings them together. It lists specialist consultancies and advisory firms across the EU that work on NIS2, DORA, or both, and lets you filter by regulation, country, service type, and the size of client they serve. Every listing is checked against the provider’s own website before it goes in. Inclusion is editorial and free, so firms cannot pay to appear, only to be marked as featured.

It is built for the person inside a mid-sized or smaller organisation who has to handle compliance alongside other duties and has no time to search firm by firm. If you are not yet certain which regulation applies to you, confirm your position first with the free NIS2 Checker or DORA compliance assessment, then come back to shortlist a provider below.





Inclusion in this directory is free and editorial. Featured placements are paid and marked.
Are you a DORA or NIS2 provider?
Claim your free listing.

Find NIS2 and DORA Providers by Country

The directory covers providers based in 15 countries, with the deepest benches in Germany, the Netherlands, France, Spain, Ireland, Italy and Poland, alongside Nordic firms in Denmark, Sweden and Norway and DORA specialists in Luxembourg. Where your provider sits matters more under NIS2 than under DORA. NIS2 is a directive, so registration duties, deadlines and fine ceilings differ by member state, and a firm that already deals with your national competent authority saves you the translation work. DORA is a regulation and applies uniformly across the EU, which makes cross-border hiring the smaller risk. Use the country filter above, or jump straight to one:

What we check before a provider is listed

Each provider is included on the basis of a public service page that shows genuine NIS2 or DORA work. Regulation tags reflect what a firm markets, so a provider shown as covering both may lead with one in practice. The directory does not rank or endorse providers, and it does not verify certifications or delivery quality, so treat it as a shortlist to approach rather than a recommendation. Listings are reviewed periodically, since national transposition and provider offerings keep changing through 2026.

Questions to answer before you hire

How do I choose a NIS2 or DORA compliance provider? Start with scope: confirm which regulation applies and what you actually need, whether that is a one-off gap assessment or ongoing support. Then filter by country if you want a firm that knows your national authority, and by service type and client size to match your situation. Shortlist two or three and approach them directly for a scoped quote.

Which applies to my company, NIS2 or DORA? DORA applies to financial entities and their ICT providers. NIS2 applies across eighteen sectors, from energy and transport to digital infrastructure and public administration. Some organisations fall under both, though DORA takes precedence for the financial sector on ICT risk. If you are unsure whether you count as an essential or important entity under NIS2, the essential vs important entities guide explains the split, and the NIS2 Checker confirms your position in a couple of minutes.

Is this the official list of DORA critical ICT third-party providers (CTPPs)? No. This is a directory of firms you can hire to help with compliance, not the register of providers that the European Supervisory Authorities designate as critical under direct DORA oversight. Those designated CTPPs are a separate official supervisory matter and are not what this directory covers.

How much does NIS2 or DORA compliance consulting cost? Pricing is rarely published and depends on scope, sector, and company size. Public examples range from a few thousand euros for a scoped NIS2 project to monthly retainers for fractional CISO cover. Asking two or three providers for a scoped quote is the only reliable way to compare.

Are the providers in this directory vetted or certified? Each is checked against its own website to confirm it genuinely offers the service, but the directory does not audit certifications, references, or delivery quality. Verify credentials and ask for client references before you engage anyone.

What is a TLPT provider, and do I need one? Threat-led penetration testing (TLPT) is an advanced red-team exercise required under DORA for certain financial entities. If your entity is in scope, you need a qualified provider, and these are scarce across the EU, so it is worth booking well ahead of your testing window. Providers offering TLPT can be found through the service-type filter above.

Can one provider handle both NIS2 and DORA? Yes, many firms cover both, which helps if your group has entities under each regime. Filter regulation to “both” to see them. For a purely financial-sector ICT scope, a DORA specialist is often the better fit.

How do I get my firm listed? Listing is free and editorial. Email us with your firm name, the regulations you cover, and a link to your service page, and we will review it for inclusion.

Not sure where you stand yet? Check your scope with the NIS2 Checker and keep an eye on what is due when with the EU compliance deadline tracker, then come back here to build your shortlist.