DORA Resilience Testing Requirements: A Practical 2026 Guide
Date: 15 July 2024
The European Union's Digital Operational Resilience Act (DORA) has applied across the European Union since 17 January 2025. Financial entities are therefore no longer preparing for its digital operational resilience testing requirements; they must now be able to demonstrate that appropriate testing programmes are documented, risk-based, regularly performed and followed by effective remediation.
Digital operational resilience testing is one of DORA’s five core pillars. Its purpose is to assess whether ICT systems, processes and controls can withstand disruption, support critical or important functions and recover effectively when weaknesses or failures occur.
DORA does not impose the same testing programme on every organisation. The nature, frequency and depth of testing should be proportionate to the organisation’s size, risk profile, business activities and the criticality of the systems and services being tested. Certain financial entities may also be directed to conduct advanced threat-led penetration testing, or TLPT, at least every three years.
This updated guide explains the standard resilience testing requirements under Articles 24 and 25 of DORA, the advanced TLPT requirements under Articles 26 and 27, the final TLPT Regulatory Technical Standards and the practical evidence organisations should retain to demonstrate compliance.
What Tests Can Be Included in a DORA Resilience Testing Programme?
Article 25 of DORA identifies a range of assessments, methodologies and testing techniques that financial entities may use as part of their digital operational resilience testing programmes.
These include:
- Vulnerability assessments and scans
- Open-source analyses
- Network security assessments
- Gap analyses
- Physical security reviews
- Questionnaires and scanning software solutions
- Source code reviews, where feasible
- Scenario-based testing
- Compatibility testing
- Performance testing
- End-to-end testing
- Penetration testing
This is not a universal checklist requiring every financial entity to conduct every test. Organisations should select and combine testing activities according to their risk profile, operational complexity, exposure to ICT risk and the importance of the systems and services being assessed.
Tests should be conducted by independent parties, whether internal or external. Where internal testers are used, organisations must ensure that sufficient resources are allocated and that conflicts of interest are avoided throughout the design and execution of the test.
In the next few sections, we look at the DORA mandate for Threat-Led Penetration Testing. This is definitely the most critical component in Chapter IV with two dedicated chapters. If you’re interested in conducting a scenario-based resilience test, do read our detailed blog: EU DORA Regulation: Scenario-based Testing for Operational Resilience.
For detailed information on the ICT Risk Management Framework, Information Sharing and Third-party Risk Management mandates, read this blog: 5 Pillars of DORA.
What Testing Does DORA Actually Require?
DORA requires financial entities, other than microenterprises, to establish, maintain and regularly review a comprehensive digital operational resilience testing programme. The programme should form part of the organisation’s wider ICT risk-management framework and be designed to identify weaknesses, deficiencies and gaps in ICT systems, processes and controls.
The testing programme should:
- Follow a risk-based and proportionate approach;
- Cover the organisation’s ICT systems and applications supporting critical or important functions;
- Include appropriate tests conducted by independent internal or external parties;
- Establish procedures for prioritising, classifying and correcting issues identified through testing;
- Validate that weaknesses have been fully addressed; and
- Be reviewed and approved through the organisation’s governance arrangements.
Appropriate tests must be carried out on all ICT systems and applications supporting critical or important functions at least annually. This does not necessarily mean that every system must undergo the same type or depth of testing. The chosen methodology should reflect the risk presented by the system, the service it supports and the potential business impact of failure.
Testing should also extend beyond purely technical security controls. Scenario-based exercises, recovery testing, compatibility testing and end-to-end testing can help determine whether technology, people, decision-making processes and third-party dependencies work together during disruption.
Any weaknesses identified must lead to documented remediation. Organisations should record the finding, its severity, the responsible owner, agreed corrective action, target completion date and evidence that remediation has been validated.
DORA Threat-Led Penetration Testing Requirements
Threat-led penetration testing is DORA’s most advanced form of digital operational resilience testing. It is designed to simulate the tactics, techniques and procedures of realistic threat actors against the live production systems supporting a financial entity’s critical or important functions.
TLPT is not simply another name for penetration testing. A conventional penetration test normally examines defined systems for technical vulnerabilities. A DORA TLPT exercise is intelligence-led, controlled by a dedicated team, overseen by the relevant TLPT authority and conducted through a structured process covering preparation, active testing, closure and remediation.
Commission Delegated Regulation (EU) 2025/1190 now provides the detailed Regulatory Technical Standards governing these tests.
Which financial entities must conduct TLPT?
Not every entity within DORA’s scope is automatically required to perform TLPT. The relevant TLPT authority identifies financial entities based on their systemic importance, impact on the financial sector, ICT risk profile and other quantitative and qualitative criteria.
Entities may also be included or excluded following an authority’s overall assessment of whether advanced testing is proportionate and justified.
Financial entities that are formally identified as subject to TLPT must generally perform the test at least once every three years. The competent authority may reduce or increase the frequency where this is justified by the entity’s risk profile and operational circumstances.
What must a DORA TLPT cover?
Each TLPT must cover several or all of the critical or important functions selected by the financial entity and validated by the TLPT authority.
The scope should identify:
- The critical or important functions being tested;
- The underlying ICT systems, processes and technologies;
- Relevant live production systems;
- ICT assets operated internally;
- Systems and services provided by ICT third parties; and
- The threat scenarios that will guide the test.
Testing should be conducted on live production systems. The process must therefore include controls designed to protect data, maintain service continuity and prevent the test itself from causing an operational incident.
How does third-party participation work?
Where an ICT third-party service provider supports a function included within the scope of the test, the financial entity remains responsible for ensuring that the provider participates appropriately.
Where direct participation could adversely affect the provider’s services or other customers, pooled testing may be considered. This can allow several financial entities relying on the same provider to participate in a coordinated test while managing operational and confidentiality risks.
Outsourcing the underlying technology does not transfer the financial entity’s responsibility for complying with DORA’s testing requirements.
What are the principal phases of TLPT?
A DORA TLPT follows a controlled lifecycle:
- Preparation: The financial entity establishes its control team, appoints a control-team lead, proposes the scope and engages with its TLPT authority.
- Testing: Threat intelligence and red-team providers develop realistic scenarios and execute controlled activity against the agreed systems.
- Closure: The red team and blue team review the exercise, compare activity with detection and response, and conduct a collaborative replay or purple-teaming exercise.
- Remediation: The financial entity documents identified weaknesses, prepares remediation plans and provides the required evidence to the TLPT authority.
- Attestation: Following satisfactory completion, the authority may issue an attestation to support supervisory recognition of the test.
A successful TLPT should therefore produce more than a penetration-test report. It should generate evidence about threat exposure, technical controls, detection capability, response performance, governance, communication and remediation.
DORA’s Requirements for Testers: Brief Overview
DORA establishes specific requirements for the internal and external testers involved in threat-led penetration testing. These requirements are intended to ensure that testing is credible, independent, secure and supported by appropriate expertise.
External TLPT testers should:
- demonstrate suitability and a strong professional reputation;
- possess specialist technical and organisational expertise in threat intelligence, penetration testing and red-team operations;
- hold recognised certifications or comply with appropriate professional and ethical frameworks;
- provide an independent assessment of the test;
- maintain professional indemnity insurance;
- protect confidential and commercially sensitive information;
- manage test data and results securely; and
- operate under contracts that clearly define responsibilities, safeguards and reporting requirements.
Financial entities may use internal testers where the relevant conditions are satisfied and the use of those testers has been approved by the TLPT authority.
Internal testers must have sufficient resources, capabilities and organisational independence. They should avoid involvement in the design, implementation or operation of the systems being tested where this would create a conflict of interest.
Where internal testers are used, DORA requires every third TLPT to be conducted by an external tester. The threat-intelligence provider supporting a test performed by internal testers must also remain external to the financial entity.
Selecting a testing provider should therefore involve more than comparing technical credentials. Financial entities should assess independence, sector experience, data-handling arrangements, insurance, reporting quality and the provider’s ability to operate within the formal DORA TLPT methodology.
What Evidence Should Organisations Retain?
DORA resilience testing should create a clear evidence trail demonstrating that tests were properly planned, performed, reviewed and followed by remediation.
Depending on the type of test, the evidence may include:
- the approved digital operational resilience testing programme;
- inventories identifying systems supporting critical or important functions;
- risk assessments used to determine the testing scope and frequency;
- test plans, methodologies and agreed success criteria;
- evidence of tester competence, independence and approval;
- vulnerability, penetration-testing and scenario-exercise reports;
- technical logs, observations and supporting test data;
- documented findings and severity ratings;
- remediation plans with assigned owners and deadlines;
- evidence that corrective actions were completed and retested;
- management reports and governance approvals;
- records of third-party participation;
- tabletop-exercise reports and lessons-learned logs; and
- TLPT scope specifications, threat-intelligence reports, red-team reports, blue-team reports, remediation plans and supervisory attestations where applicable.
The evidence should show not only that testing occurred, but that identified weaknesses were understood, prioritised and resolved. A collection of disconnected technical reports is unlikely to demonstrate an effective testing programme if there is no governance, ownership or evidence of closure.
How we can help you with Operational Resilience Testing for DORA Compliance
The long list of tests, requirements for TLPT and compliance with other clauses of DORA can seem overwhelming. However, the good news is that it doesn’t have to be so.
Cyber Management Alliance offers a complete suite of services that can take care of all your DORA compliance requirements, especially those pertaining to Digital Operational Resilience Testing.
Take a quick look at how we can help:
- Scenario-Based Testing: Cyber Management Alliance is the world leader in conducting Cyber Tabletop Exercises. These exercises simulate cyber attack scenarios most relevant to your business. The carefully chosen participants for the exercise are coaxed to think and respond like they would in an actual attack scenario.
These exercises test the viability of your Cyber Incident Response Plans in the event of an ICT-related incident. They show you the gaps in your digital resilience posture, your strengths and weaknesses. Overall, they help you refine your maturity to respond to cybersecurity and digital disruptions. - Penetration Testing: Our Certified Penetration Testing Services stand out in the market for being cost-effective and customisable. Our expert team of pentesters, complemented by the leadership of our cybersecurity experts, help you identify the threats to your business before attackers do.
Our certified engineers conduct a thorough technical reconnaissance of your assets and identify all possible entry points. They then try to 'gain access' and exploit vulnerabilities to simulate a prolonged attack and assess potential damage. Based on the test, the vulnerabilities found, their characteristics and the possible damage, we created a detailed report. The findings are complemented by effective remediation steps, in order to help you address your vulnerabilities faster and achieve DORA compliance.
It’s worth noting, however, that regular pentests also help you achieve compliance with several other regulatory standards and frameworks including the GDPR, ISO 27001, PCI DSS and SOC 2 amongst many others. - Risk Assessment and Gap Analysis: Our Virtual Cyber Assistants can help you improve your digital operational resilience in nearly every way possible. In the most cost-effective and flexible package, you can get your cyber incident response plans, policies and playbooks in order.
They can also help you implement a robust Cybersecurity and/or Risk Management Framework. They’ll help you review your Business Continuity and Disaster Recovery plans. And in the context of DORA, they can assist you with conducting a Risk Assessment and/or Security Gap Analysis.
Common DORA Resilience Testing Mistakes
DORA testing programmes can fall short even where organisations already conduct vulnerability scanning and penetration testing. Common weaknesses include:
Treating penetration testing as the entire programme
Penetration testing is only one of several testing methods identified by DORA. A mature programme may also require vulnerability assessments, scenario exercises, recovery tests, compatibility testing, performance testing and end-to-end testing.
Assuming every penetration test is a TLPT
TLPT is a formal, authority-supervised and threat-intelligence-led exercise conducted against live production systems. A standard penetration test does not become a DORA TLPT simply because it uses realistic attack techniques.
Testing systems without mapping critical functions
The testing programme should be connected to the organisation’s critical or important functions. Testing isolated assets without understanding the services they support can leave significant operational dependencies unexamined.
Failing to test third-party dependencies
Financial entities remain accountable for resilience even where systems or services are delivered by ICT providers. Relevant third-party dependencies should be considered when setting testing scope and designing scenarios.
Recording findings without validating remediation
Closing a finding in a spreadsheet is not the same as confirming that the weakness has been corrected. Organisations should retain evidence of remediation and, where appropriate, conduct follow-up testing.
Excluding management and business teams
Digital operational resilience is not purely a technical matter. Scenario-based tests should examine escalation, executive decisions, communications, legal considerations and business continuity alongside technical response.
Running disconnected exercises
Individual security tests may create useful findings but still fail to constitute a coherent DORA programme. Testing should follow an approved methodology, reflect risk priorities and feed into governance, remediation and continual improvement.
Final Word
DORA has moved digital operational resilience testing from good practice to an explicit regulatory expectation for the European financial sector. Compliance does not depend on performing every possible security test. It requires a proportionate, risk-based and documented programme that covers the systems supporting critical or important functions, identifies weaknesses and follows those weaknesses through to verified remediation.
For most financial entities, the priority should be to connect existing vulnerability assessments, penetration tests, recovery exercises and scenario-based tests into one coherent programme supported by clear governance and evidence.
Entities selected for TLPT face an additional level of scrutiny. They must follow the formal methodology, oversight, tester, scope, closure and remediation requirements established by DORA and Commission Delegated Regulation (EU) 2025/1190.
The real value of this work extends beyond regulatory compliance. Regular and realistic testing gives organisations the opportunity to identify weaknesses under controlled conditions, before a cyber incident or major technology failure tests them for real.
Frequently Asked Questions About DORA Resilience Testing
1. What is digital operational resilience testing under DORA?
Digital operational resilience testing is the structured assessment of whether a financial entity’s ICT systems, processes, controls and response arrangements can withstand, respond to and recover from disruption. DORA requires organisations to maintain a risk-based testing programme that identifies weaknesses and ensures that those weaknesses are remediated and validated.
2. How often must financial entities conduct DORA resilience testing?
Financial entities should conduct appropriate testing of all ICT systems and applications supporting critical or important functions at least annually. The precise type, depth and frequency of individual tests should be proportionate to the organisation’s size, risk profile, operational complexity and the criticality of the system being assessed.
3. Which types of resilience tests does DORA recognise?
DORA identifies testing methods including vulnerability assessments, open-source analysis, network security assessments, gap analysis, physical security reviews, source-code reviews, scenario-based testing, compatibility testing, performance testing, end-to-end testing and penetration testing. Organisations should select an appropriate combination rather than treating the list as a requirement to perform every test.
4. Is penetration testing mandatory under DORA?
Penetration testing is one of the testing methods identified by DORA, but the Regulation does not state that every financial entity must perform the same penetration test at the same frequency. Testing should be selected according to risk, proportionality and the criticality of the systems involved. Certain selected entities are separately required to conduct formal threat-led penetration testing.
5. What is the difference between penetration testing and DORA TLPT?
A conventional penetration test generally examines a defined technical environment for exploitable vulnerabilities. DORA TLPT is a controlled, intelligence-led simulation of realistic threat actors against live production systems supporting critical or important functions. It follows a prescribed methodology, involves supervisory oversight and includes formal preparation, testing, closure and remediation stages.
6. Which financial entities must perform TLPT under DORA?
TLPT is required only for financial entities identified by the relevant TLPT authority. Identification is based on factors such as systemic importance, impact on the financial sector, the entity’s ICT risk profile and the quantitative and qualitative criteria established by Commission Delegated Regulation (EU) 2025/1190.
7. How often must DORA TLPT be performed?
Financial entities identified as subject to TLPT must generally conduct it at least once every three years. The relevant competent authority may increase or reduce this frequency where justified by the financial entity’s risk profile, operational circumstances and other supervisory considerations.
8. Does DORA testing have to include ICT third-party providers?
Testing should consider ICT third-party systems and services where they support the financial entity’s critical or important functions. For TLPT, the financial entity is responsible for ensuring the appropriate participation of relevant providers included within the approved scope. Outsourcing an ICT service does not remove the financial entity’s responsibility for complying with DORA.



