Fixed entry price · Everything else scoped · Fee agreed before work begins

Pricing

The gap assessment carries a fixed published price. Larger engagements are scoped to your organisation and the fee is fixed in writing after a scoping call at no cost.

Gap Assessment

€999

Fixed price

Structured assessment of your compliance obligations, current state analysis, and prioritised roadmap. The essential first step.

Deliverables

  • Regulatory scope assessment
  • Current state analysis
  • Detailed gap identification
  • Prioritised remediation roadmap
  • Effort & investment estimates

Ideal for: organisations seeking clarity on scope and obligations before committing to implementation.

Book a Scoping Call

Individual Module

Quoted on request

Scoped to the module

One CORA™ module delivered on its own, where a single obligation needs closing rather than a full programme.

Available modules

  • ICT third-party risk register
  • AI system inventory & classification
  • DORA incident response procedure
  • Board reporting pack
  • Training & certification

Ideal for: organisations with one specific gap identified and internal capacity for the rest.

Book a Scoping Call

Managed Compliance

Quoted on request

Cancel anytime, 30 days notice

Continuous compliance monitoring, gap detection, and audit readiness reporting. AI-powered with expert oversight. Your programme stays current.

Deliverables

  • Continuous compliance monitoring
  • Ongoing gap detection
  • Board-ready compliance reporting
  • Quarterly business reviews
  • Expert incident support

Ideal for: organisations seeking ongoing managed compliance with continuous visibility and expert oversight.

Book a Scoping Call

The Gap Assessment is fixed price. Everything above it is scoped to your organisation and the fee is fixed in writing after the scoping call, with no commitment until you agree it. Regulatory Radar is available separately at €199/month.

Common Engagement Paths

1

Quick Assessment

Scenario: you need clarity on where you stand, with the resources to implement internally.

Gap Assessment €999
Duration 2 weeks
2

Targeted Module

Scenario: one specific obligation to close, such as an ICT third-party register or an AI system inventory.

Individual Module Quoted on request
Duration 1–2 weeks
3

Full Build

Scenario: expert-led build of the complete compliance programme for your framework.

Programme Build Quoted on request
Duration 8–12 weeks
4

Build + Ongoing

Scenario: build the programme, then hand ownership of it to us to run continuously.

Programme Build Quoted on request
Then Managed Compliance Quoted on request

Fees for scoped engagements are fixed in writing after the scoping call.

How Morclear Works

Fixed entry pricing

The assessment and gap assessment are fixed price. Larger engagements are scoped and confirmed before you commit.

Two-week assessment

Gap assessment delivered in two weeks. Programme build runs eight to twelve weeks.

Five frameworks only

DORA, EU AI Act, GDPR, NIS2 and ISO 27001:2022. We do not also do tax, audit or deal advisory.

Named sign-off

Every deliverable is reviewed and signed by a compliance professional, named on the document.

How Pricing Works

1

Scoping Call

Thirty minutes to establish what applies to you. No cost.

2

Written Scope

The engagement type and the fee, set out in writing.

3

Agreement

Engagement letter signed. Terms and timeline confirmed.

4

Delivery

Work begins against the agreed scope and the agreed fee.

What Determines Your Fee

The assessment and gap assessment are fixed price. Everything above that is scoped, and these are the factors that move the number.

Frameworks in scope

One framework costs less than four. Where obligations overlap, an ICT third-party register built for DORA carries into NIS2, and an AI system inventory carries into GDPR, so combined scopes cost less than the sum of their parts.

Systems and vendors in scope

The volume of AI systems to classify and ICT third parties to register drives most of the work. A firm with three critical vendors is a different engagement to one with sixty.

Starting position

An organisation with existing ISO 27001 certification starts further forward than one beginning from nothing. The gap assessment establishes which of the two you are before any larger fee is quoted.

Statutory penalty ceilings

These are the maximum administrative fines set out in the EU AI Act. They are ceilings rather than expected outcomes, and national competent authorities apply proportionality when setting any actual penalty.

Prohibited practices — Article 5

Up to €35m or 7% of global annual turnover

Whichever is higher. Enforceable since February 2025.

High-risk and other obligations

Up to €15m or 3% of global annual turnover

Applies to breaches of the operative obligations other than Article 5.

Incorrect or misleading information

Up to €7.5m or 1.5% of global annual turnover

For supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities.

Source: Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. Figures are statutory maxima and are stated here for reference only.

Who This Is For

Morclear is built for organisations of roughly 50 to 2,000 employees carrying a live EU regulatory obligation without a full compliance function to meet it.

Regulated financial services

Banks, insurers, investment firms, payment and e-money institutions, fintechs and crypto-asset service providers subject to DORA since January 2025.

Technology and SaaS

Providers and deployers of AI systems working out where they sit under the EU AI Act, including firms that became providers through a partner integration.

Healthcare and critical infrastructure

Essential and important entities under NIS2, and organisations with AI embedded in products that already carry their own conformity assessment.

Professional services and public sector

Organisations handling significant personal data volumes where GDPR and ISO 27001:2022 obligations overlap with a newer framework.

Where we are not the right fit

We do not provide statutory audit or independent assurance opinions, and we do not give legal advice. Where the question is one of legal interpretation, or where your board needs an assurance signature, a law firm or an audit practice is the correct instrument and we will say so on the call.

The gap assessment is fixed price. Scoped engagements are quoted after the scoping call, because the fee moves with organisation size, regulatory complexity and the number of frameworks involved. Whatever the number is, it is fixed in writing before any work begins and there is no commitment until you agree it.

Primary Regulatory Sources

EU AI Act — Reg. (EU) 2024/1689 DORA — Reg. (EU) 2022/2554 GDPR — Reg. (EU) 2016/679 NIS2 — Dir. (EU) 2022/2555 ISO 27001:2022

Morclear resources are independently produced. They do not constitute legal, regulatory, financial, or professional advice.