EU DORA: Cyber Tabletop Testing for Operational Resilience in 2026

Date: 27 August 2026

Featured Image

The Digital Operational Resilience Act, often referred to as the EU DORA regulation, has applied since 17 January 2025. Financial entities are therefore no longer preparing for its requirements. They must be able to demonstrate that their ICT risks are managed through documented controls, realistic testing and evidence that weaknesses are addressed.

Digital operational resilience testing is one of DORA’s five core pillars. Article 25 includes scenario-based testing among the methods that financial entities may use to examine the resilience of their ICT tools and systems. Cyber Tabletop Exercises can support this requirement by testing how people, plans and decision-making processes perform during a realistic disruption.

EU DORA & Digital Operational Resilience Testing

Chapter IV of DORA covers digital operational resilience testing through Articles 24 to 27. Article 24 requires financial entities, other than microenterprises, to establish and maintain a comprehensive testing programme as part of their ICT risk-management framework. The programme must be proportionate, risk-based and designed to identify weaknesses before they contribute to a serious disruption.

Appropriate tests must be conducted at least annually on ICT systems and applications supporting critical or important functions. Testing may be performed by independent internal or external parties. Where internal testers are used, the organisation must allocate sufficient resources and prevent conflicts of interest during the design and execution of the test.

Article 25 identifies several testing methods that may be used according to the organisation’s risks and circumstances. These include vulnerability assessments, network security assessments, gap analyses, scenario-based tests, performance testing, end-to-end testing and penetration testing. The list is not a universal checklist requiring every entity to perform every test in the same way.

Articles 26 and 27 establish separate requirements for advanced Threat-Led Penetration Testing, or TLPT, for financial entities selected by the relevant authority. The detailed methodology is now set out in Commission Delegated Regulation (EU) 2025/1190. Organisations seeking a broader explanation of these requirements can consult our complete 2026 guide to DORA resilience testing.

How Cyber Crisis Tabletop Exercises Support DORA Compliance 

Article 25 expressly includes scenario-based tests within the range of testing methods available to financial entities. A Cyber Tabletop Exercise is one practical way to apply this approach because it places participants inside a realistic ICT incident without disrupting live systems.

During the exercise, participants must interpret incomplete information, follow incident response procedures and make decisions within realistic time constraints. The scenario can test technical escalation, executive authority, business continuity, regulatory considerations and communication with customers or other stakeholders.

The strongest exercises are built around the organisation’s critical or important functions. They examine the technology and third-party dependencies supporting those functions, while testing whether the organisation can contain disruption and maintain an acceptable level of service.

Here’s a quick look at the main benefits of Cyber Resilience Testing through tabletop exercises: 

  1. Scenario-based testing, if done right, opens the eyes of your staff to what risks the business actually faces.  
  2. It helps them understand their roles and responsibilities in the face of a cyber attack. 
  3. Even if they’re familiar with the Cyber Incident Response Plans and Incident Response Playbooks, they’re now able to actually rehearse them in a simulated attack environment. This builds muscle memory.  
  4. They are able to better understand the urgency of quick and effective response to cybersecurity incidents. 
  5. Your team members, especially the senior management and the executive, are able to practise decision making for a cyber crisis. 

When designed around relevant risks and followed by documented remediation, a Cyber Tabletop Exercise can provide meaningful evidence for a DORA testing programme. It should nevertheless be combined with the technical assessments, recovery tests and wider ICT controls required to demonstrate digital operational resilience.

Cyber Tabletop Exercises and TLPT Are Not the Same

A Cyber Tabletop Exercise is normally a discussion-based simulation that examines decision-making, coordination and the practical use of response plans. It does not attempt to compromise live production systems and can be conducted with executive, operational or technical participants.

Threat-Led Penetration Testing is an advanced and substantially more controlled form of testing. It uses threat intelligence and red-team activity to simulate realistic attackers against live production systems supporting critical or important functions. It is required only for financial entities identified by the relevant authority and is governed by Articles 26 and 27 of DORA.

The specialist tester requirements associated with TLPT should therefore not be presented as universal requirements for every tabletop exercise. A DORA-aligned tabletop exercise should still provide independent challenge and competent facilitation, but it does not need to follow the formal TLPT methodology unless it forms part of an authorised TLPT programme.

Back To Top

How to Run a DORA-Aligned Cyber Tabletop Exercise

Start with a critical or important function

The exercise should begin with a clearly defined business function and the ICT systems, information assets and external services supporting it. This prevents the scenario from becoming a generic cyber attack discussion and connects the exercise to DORA’s focus on operational impact.

Build a credible scenario around current risks

The scenario should reflect the organisation’s threat landscape and plausible causes of disruption. It may involve ransomware, data compromise, cloud failure or the loss of an important technology provider. The timeline should force participants to balance containment with continuity and recovery.

Involve the people who would make the real decisions

A useful exercise requires more than the cybersecurity team. Depending on its objectives, participants may include executive management, IT, security operations, business continuity, legal, compliance, communications and representatives of important ICT providers. Each participant should exercise the authority and responsibilities assigned to them during a genuine incident.

Test third-party dependencies

The exercise should examine what happens when an ICT provider cannot deliver the information, access or support the organisation expects. Participants should understand how the provider is contacted, what contractual support is available and how the business will continue if the dependency remains unavailable.

Create a defensible evidence trail

The organisation should retain the approved scope, objectives, scenario rationale and participant record. Exercise evidence should also capture material decisions, escalation gaps, communication failures and assumptions that could not be verified during the session.

Remediate and validate the findings

DORA requires organisations to prioritise and address weaknesses identified through testing. The post-exercise report should therefore assign each material finding to an accountable owner, define the required improvement and establish a target completion date. Significant remediations should be validated through a subsequent exercise or another appropriate test.

Cyber Management Alliance’s bespoke Cyber Tabletop Exercises include realistic scenario development, expert facilitation and a detailed management report. The findings can help financial entities strengthen incident response while creating evidence that supports their wider DORA testing programme.

Final Word

In 2026, DORA compliance depends on more than having testing policies or scheduling an annual exercise. Financial entities must be able to show how testing priorities were selected, what weaknesses were identified and whether the resulting improvements were completed and validated.

Cyber Tabletop Exercises provide a controlled way to test the human and organisational elements of digital operational resilience. They can reveal whether incident response plans are practical and whether critical decisions can be made under pressure. They also demonstrate whether technical, operational and executive teams can work together when an ICT incident threatens an important service.

The exercise delivers its greatest value when it is connected to the wider testing programme and followed by disciplined remediation. This turns scenario-based testing from a compliance activity into a practical mechanism for strengthening operational resilience.

FAQs about Operational Resilience Testing and DORA 

1. Does DORA require Cyber Tabletop Exercises?

DORA Article 25 includes scenario-based tests among the testing methods financial entities may use within their digital operational resilience programmes. It does not prescribe one identical tabletop exercise for every organisation. The chosen exercises should reflect the entity’s risk profile, critical functions and operational complexity.

2. Which DORA Article covers scenario-based testing?

Scenario-based testing is identified in Article 25, which covers the testing of ICT tools and systems. Article 25 forms part of the wider testing framework established by Articles 24 to 27 of DORA.

3. How do tabletop exercises support DORA operational resilience?

Tabletop exercises test whether people can apply incident response, business continuity and recovery arrangements during a realistic disruption. They can expose weaknesses in governance, escalation, communication and decision-making that may not be visible during a document review.

4. How often should a DORA tabletop exercise be conducted?

DORA requires appropriate testing of ICT systems and applications supporting critical or important functions at least annually, subject to the relevant proportionality provisions. This does not mean every system requires a separate annual tabletop exercise. The tabletop schedule should reflect risk, organisational change, previous findings and the role of each exercise within the wider testing programme.

5. Is a Cyber Tabletop Exercise the same as TLPT?

No. A tabletop exercise is generally a discussion-based simulation that tests people, plans and decisions without attacking live systems. TLPT is an advanced, intelligence-led test conducted against live production environments under a formal methodology and supervisory framework.

6. Who should participate in a DORA Cyber Tabletop Exercise?

Participation should reflect the scenario and the function being tested. A cross-functional exercise may include cybersecurity, IT, operations, business continuity, legal, compliance, communications, executive management and relevant ICT third-party providers.

7. What evidence should be retained after a tabletop exercise?

Organisations should retain the exercise scope, objectives, scenario basis and participant record. They should also preserve material decisions, identified gaps, the post-exercise report, remediation actions, accountable owners, target dates and evidence that important improvements were subsequently validated.

8. Should ICT third-party providers participate in DORA exercises?

Relevant providers should be considered where their services support critical or important functions. They may participate directly or be represented through realistic scenario injects. The exercise should test whether escalation routes, contractual support and continuity arrangements remain effective when the provider is affected or unavailable.