The European Union's Digital Operational Resilience Act (DORA) has applied across the European Union since 17 January 2025. Financial entities are therefore no longer preparing for its digital operational resilience testing requirements; they must now be able to demonstrate that appropriate testing programmes are documented, risk-based, regularly performed and followed by effective remediation.
Digital operational resilience testing is one of DORA’s five core pillars. Its purpose is to assess whether ICT systems, processes and controls can withstand disruption, support critical or important functions and recover effectively when weaknesses or failures occur.
DORA does not impose the same testing programme on every organisation. The nature, frequency and depth of testing should be proportionate to the organisation’s size, risk profile, business activities and the criticality of the systems and services being tested. Certain financial entities may also be directed to conduct advanced threat-led penetration testing, or TLPT, at least every three years.
This updated guide explains the standard resilience testing requirements under Articles 24 and 25 of DORA, the advanced TLPT requirements under Articles 26 and 27, the final TLPT Regulatory Technical Standards and the practical evidence organisations should retain to demonstrate compliance.
Article 25 of DORA identifies a range of assessments, methodologies and testing techniques that financial entities may use as part of their digital operational resilience testing programmes.
These include:
This is not a universal checklist requiring every financial entity to conduct every test. Organisations should select and combine testing activities according to their risk profile, operational complexity, exposure to ICT risk and the importance of the systems and services being assessed.
Tests should be conducted by independent parties, whether internal or external. Where internal testers are used, organisations must ensure that sufficient resources are allocated and that conflicts of interest are avoided throughout the design and execution of the test.
In the next few sections, we look at the DORA mandate for Threat-Led Penetration Testing. This is definitely the most critical component in Chapter IV with two dedicated chapters. If you’re interested in conducting a scenario-based resilience test, do read our detailed blog: EU DORA Regulation: Scenario-based Testing for Operational Resilience.
For detailed information on the ICT Risk Management Framework, Information Sharing and Third-party Risk Management mandates, read this blog: 5 Pillars of DORA.
DORA requires financial entities, other than microenterprises, to establish, maintain and regularly review a comprehensive digital operational resilience testing programme. The programme should form part of the organisation’s wider ICT risk-management framework and be designed to identify weaknesses, deficiencies and gaps in ICT systems, processes and controls.
The testing programme should:
Appropriate tests must be carried out on all ICT systems and applications supporting critical or important functions at least annually. This does not necessarily mean that every system must undergo the same type or depth of testing. The chosen methodology should reflect the risk presented by the system, the service it supports and the potential business impact of failure.
Testing should also extend beyond purely technical security controls. Scenario-based exercises, recovery testing, compatibility testing and end-to-end testing can help determine whether technology, people, decision-making processes and third-party dependencies work together during disruption.
Any weaknesses identified must lead to documented remediation. Organisations should record the finding, its severity, the responsible owner, agreed corrective action, target completion date and evidence that remediation has been validated.
Threat-led penetration testing is DORA’s most advanced form of digital operational resilience testing. It is designed to simulate the tactics, techniques and procedures of realistic threat actors against the live production systems supporting a financial entity’s critical or important functions.
TLPT is not simply another name for penetration testing. A conventional penetration test normally examines defined systems for technical vulnerabilities. A DORA TLPT exercise is intelligence-led, controlled by a dedicated team, overseen by the relevant TLPT authority and conducted through a structured process covering preparation, active testing, closure and remediation.
Commission Delegated Regulation (EU) 2025/1190 now provides the detailed Regulatory Technical Standards governing these tests.
Not every entity within DORA’s scope is automatically required to perform TLPT. The relevant TLPT authority identifies financial entities based on their systemic importance, impact on the financial sector, ICT risk profile and other quantitative and qualitative criteria.
Entities may also be included or excluded following an authority’s overall assessment of whether advanced testing is proportionate and justified.
Financial entities that are formally identified as subject to TLPT must generally perform the test at least once every three years. The competent authority may reduce or increase the frequency where this is justified by the entity’s risk profile and operational circumstances.
Each TLPT must cover several or all of the critical or important functions selected by the financial entity and validated by the TLPT authority.
The scope should identify:
Testing should be conducted on live production systems. The process must therefore include controls designed to protect data, maintain service continuity and prevent the test itself from causing an operational incident.
Where an ICT third-party service provider supports a function included within the scope of the test, the financial entity remains responsible for ensuring that the provider participates appropriately.
Where direct participation could adversely affect the provider’s services or other customers, pooled testing may be considered. This can allow several financial entities relying on the same provider to participate in a coordinated test while managing operational and confidentiality risks.
Outsourcing the underlying technology does not transfer the financial entity’s responsibility for complying with DORA’s testing requirements.
A DORA TLPT follows a controlled lifecycle:
A successful TLPT should therefore produce more than a penetration-test report. It should generate evidence about threat exposure, technical controls, detection capability, response performance, governance, communication and remediation.
DORA establishes specific requirements for the internal and external testers involved in threat-led penetration testing. These requirements are intended to ensure that testing is credible, independent, secure and supported by appropriate expertise.
External TLPT testers should:
Financial entities may use internal testers where the relevant conditions are satisfied and the use of those testers has been approved by the TLPT authority.
Internal testers must have sufficient resources, capabilities and organisational independence. They should avoid involvement in the design, implementation or operation of the systems being tested where this would create a conflict of interest.
Where internal testers are used, DORA requires every third TLPT to be conducted by an external tester. The threat-intelligence provider supporting a test performed by internal testers must also remain external to the financial entity.
Selecting a testing provider should therefore involve more than comparing technical credentials. Financial entities should assess independence, sector experience, data-handling arrangements, insurance, reporting quality and the provider’s ability to operate within the formal DORA TLPT methodology.
DORA resilience testing should create a clear evidence trail demonstrating that tests were properly planned, performed, reviewed and followed by remediation.
Depending on the type of test, the evidence may include:
The evidence should show not only that testing occurred, but that identified weaknesses were understood, prioritised and resolved. A collection of disconnected technical reports is unlikely to demonstrate an effective testing programme if there is no governance, ownership or evidence of closure.
The long list of tests, requirements for TLPT and compliance with other clauses of DORA can seem overwhelming. However, the good news is that it doesn’t have to be so.
Cyber Management Alliance offers a complete suite of services that can take care of all your DORA compliance requirements, especially those pertaining to Digital Operational Resilience Testing.
Take a quick look at how we can help:
DORA testing programmes can fall short even where organisations already conduct vulnerability scanning and penetration testing. Common weaknesses include:
Penetration testing is only one of several testing methods identified by DORA. A mature programme may also require vulnerability assessments, scenario exercises, recovery tests, compatibility testing, performance testing and end-to-end testing.
TLPT is a formal, authority-supervised and threat-intelligence-led exercise conducted against live production systems. A standard penetration test does not become a DORA TLPT simply because it uses realistic attack techniques.
The testing programme should be connected to the organisation’s critical or important functions. Testing isolated assets without understanding the services they support can leave significant operational dependencies unexamined.
Financial entities remain accountable for resilience even where systems or services are delivered by ICT providers. Relevant third-party dependencies should be considered when setting testing scope and designing scenarios.
Closing a finding in a spreadsheet is not the same as confirming that the weakness has been corrected. Organisations should retain evidence of remediation and, where appropriate, conduct follow-up testing.
Digital operational resilience is not purely a technical matter. Scenario-based tests should examine escalation, executive decisions, communications, legal considerations and business continuity alongside technical response.
Individual security tests may create useful findings but still fail to constitute a coherent DORA programme. Testing should follow an approved methodology, reflect risk priorities and feed into governance, remediation and continual improvement.
DORA has moved digital operational resilience testing from good practice to an explicit regulatory expectation for the European financial sector. Compliance does not depend on performing every possible security test. It requires a proportionate, risk-based and documented programme that covers the systems supporting critical or important functions, identifies weaknesses and follows those weaknesses through to verified remediation.
For most financial entities, the priority should be to connect existing vulnerability assessments, penetration tests, recovery exercises and scenario-based tests into one coherent programme supported by clear governance and evidence.
Entities selected for TLPT face an additional level of scrutiny. They must follow the formal methodology, oversight, tester, scope, closure and remediation requirements established by DORA and Commission Delegated Regulation (EU) 2025/1190.
The real value of this work extends beyond regulatory compliance. Regular and realistic testing gives organisations the opportunity to identify weaknesses under controlled conditions, before a cyber incident or major technology failure tests them for real.
1. What is digital operational resilience testing under DORA?
Digital operational resilience testing is the structured assessment of whether a financial entity’s ICT systems, processes, controls and response arrangements can withstand, respond to and recover from disruption. DORA requires organisations to maintain a risk-based testing programme that identifies weaknesses and ensures that those weaknesses are remediated and validated.
2. How often must financial entities conduct DORA resilience testing?
Financial entities should conduct appropriate testing of all ICT systems and applications supporting critical or important functions at least annually. The precise type, depth and frequency of individual tests should be proportionate to the organisation’s size, risk profile, operational complexity and the criticality of the system being assessed.
3. Which types of resilience tests does DORA recognise?
DORA identifies testing methods including vulnerability assessments, open-source analysis, network security assessments, gap analysis, physical security reviews, source-code reviews, scenario-based testing, compatibility testing, performance testing, end-to-end testing and penetration testing. Organisations should select an appropriate combination rather than treating the list as a requirement to perform every test.
4. Is penetration testing mandatory under DORA?
Penetration testing is one of the testing methods identified by DORA, but the Regulation does not state that every financial entity must perform the same penetration test at the same frequency. Testing should be selected according to risk, proportionality and the criticality of the systems involved. Certain selected entities are separately required to conduct formal threat-led penetration testing.
5. What is the difference between penetration testing and DORA TLPT?
A conventional penetration test generally examines a defined technical environment for exploitable vulnerabilities. DORA TLPT is a controlled, intelligence-led simulation of realistic threat actors against live production systems supporting critical or important functions. It follows a prescribed methodology, involves supervisory oversight and includes formal preparation, testing, closure and remediation stages.
6. Which financial entities must perform TLPT under DORA?
TLPT is required only for financial entities identified by the relevant TLPT authority. Identification is based on factors such as systemic importance, impact on the financial sector, the entity’s ICT risk profile and the quantitative and qualitative criteria established by Commission Delegated Regulation (EU) 2025/1190.
7. How often must DORA TLPT be performed?
Financial entities identified as subject to TLPT must generally conduct it at least once every three years. The relevant competent authority may increase or reduce this frequency where justified by the financial entity’s risk profile, operational circumstances and other supervisory considerations.
8. Does DORA testing have to include ICT third-party providers?
Testing should consider ICT third-party systems and services where they support the financial entity’s critical or important functions. For TLPT, the financial entity is responsible for ensuring the appropriate participation of relevant providers included within the approved scope. Outsourcing an ICT service does not remove the financial entity’s responsibility for complying with DORA.