Pricing
The gap assessment carries a fixed published price. Larger engagements are scoped to your organisation and the fee is fixed in writing after a scoping call at no cost.
Gap Assessment
2-week engagement
Fixed price
Structured assessment of your compliance obligations, current state analysis, and prioritised roadmap. The essential first step.
Deliverables
- Regulatory scope assessment
- Current state analysis
- Detailed gap identification
- Prioritised remediation roadmap
- Effort & investment estimates
Ideal for: organisations seeking clarity on scope and obligations before committing to implementation.
Book a Scoping CallIndividual Module
1-2 week engagement
Scoped to the module
One CORA™ module delivered on its own, where a single obligation needs closing rather than a full programme.
Available modules
- ICT third-party risk register
- AI system inventory & classification
- DORA incident response procedure
- Board reporting pack
- Training & certification
Ideal for: organisations with one specific gap identified and internal capacity for the rest.
Book a Scoping CallProgramme Build
8-12 week engagement
Fixed fee, agreed before work begins
Complete compliance programme build covering policies, documentation, controls, and procedures. Morclear leads; your team learns and retains the knowledge.
Deliverables
- Complete framework architecture
- Full policy & documentation suite
- Internal team training
- Audit-ready sign-off
- 30 days post-launch support
Ideal for: mid-size organisations requiring an expert-led build against a live regulatory deadline.
Book a Scoping CallManaged Compliance
Monthly managed service
Cancel anytime, 30 days notice
Continuous compliance monitoring, gap detection, and audit readiness reporting. AI-powered with expert oversight. Your programme stays current.
Deliverables
- Continuous compliance monitoring
- Ongoing gap detection
- Board-ready compliance reporting
- Quarterly business reviews
- Expert incident support
Ideal for: organisations seeking ongoing managed compliance with continuous visibility and expert oversight.
Book a Scoping CallThe Gap Assessment is fixed price. Everything above it is scoped to your organisation and the fee is fixed in writing after the scoping call, with no commitment until you agree it. Regulatory Radar is available separately at €199/month.
Common Engagement Paths
Quick Assessment
Scenario: you need clarity on where you stand, with the resources to implement internally.
Targeted Module
Scenario: one specific obligation to close, such as an ICT third-party register or an AI system inventory.
Full Build
Scenario: expert-led build of the complete compliance programme for your framework.
Build + Ongoing
Scenario: build the programme, then hand ownership of it to us to run continuously.
Fees for scoped engagements are fixed in writing after the scoping call.
How Morclear Works
Fixed entry pricing
The assessment and gap assessment are fixed price. Larger engagements are scoped and confirmed before you commit.
Two-week assessment
Gap assessment delivered in two weeks. Programme build runs eight to twelve weeks.
Five frameworks only
DORA, EU AI Act, GDPR, NIS2 and ISO 27001:2022. We do not also do tax, audit or deal advisory.
Named sign-off
Every deliverable is reviewed and signed by a compliance professional, named on the document.
How Pricing Works
Scoping Call
Thirty minutes to establish what applies to you. No cost.
Written Scope
The engagement type and the fee, set out in writing.
Agreement
Engagement letter signed. Terms and timeline confirmed.
Delivery
Work begins against the agreed scope and the agreed fee.
What Determines Your Fee
The assessment and gap assessment are fixed price. Everything above that is scoped, and these are the factors that move the number.
Frameworks in scope
One framework costs less than four. Where obligations overlap, an ICT third-party register built for DORA carries into NIS2, and an AI system inventory carries into GDPR, so combined scopes cost less than the sum of their parts.
Systems and vendors in scope
The volume of AI systems to classify and ICT third parties to register drives most of the work. A firm with three critical vendors is a different engagement to one with sixty.
Starting position
An organisation with existing ISO 27001 certification starts further forward than one beginning from nothing. The gap assessment establishes which of the two you are before any larger fee is quoted.
Statutory penalty ceilings
These are the maximum administrative fines set out in the EU AI Act. They are ceilings rather than expected outcomes, and national competent authorities apply proportionality when setting any actual penalty.
Prohibited practices — Article 5
Up to €35m or 7% of global annual turnover
Whichever is higher. Enforceable since February 2025.
High-risk and other obligations
Up to €15m or 3% of global annual turnover
Applies to breaches of the operative obligations other than Article 5.
Incorrect or misleading information
Up to €7.5m or 1.5% of global annual turnover
For supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities.
Source: Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. Figures are statutory maxima and are stated here for reference only.
Who This Is For
Morclear is built for organisations of roughly 50 to 2,000 employees carrying a live EU regulatory obligation without a full compliance function to meet it.
Regulated financial services
Banks, insurers, investment firms, payment and e-money institutions, fintechs and crypto-asset service providers subject to DORA since January 2025.
Technology and SaaS
Providers and deployers of AI systems working out where they sit under the EU AI Act, including firms that became providers through a partner integration.
Healthcare and critical infrastructure
Essential and important entities under NIS2, and organisations with AI embedded in products that already carry their own conformity assessment.
Professional services and public sector
Organisations handling significant personal data volumes where GDPR and ISO 27001:2022 obligations overlap with a newer framework.
Where we are not the right fit
We do not provide statutory audit or independent assurance opinions, and we do not give legal advice. Where the question is one of legal interpretation, or where your board needs an assurance signature, a law firm or an audit practice is the correct instrument and we will say so on the call.
The gap assessment is fixed price. Scoped engagements are quoted after the scoping call, because the fee moves with organisation size, regulatory complexity and the number of frameworks involved. Whatever the number is, it is fixed in writing before any work begins and there is no commitment until you agree it.
Primary Regulatory Sources
Morclear resources are independently produced. They do not constitute legal, regulatory, financial, or professional advice.