DORA resilience testing
The Digital Operational Resilience Act asks EU financial entities to test their ICT every year, fix what they find, and prove it. Here is what it requires, what it means for UK firms, and where testing fits.
What DORA is
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied across the EU since 17 January 2025. It sets one standard for how financial entities manage information and communication technology (ICT) risk, so that a cyber attack or IT failure does not stop critical financial services.
It covers around twenty types of financial entity, including banks, investment firms, payment and e-money institutions, insurers and reinsurers, crypto-asset service providers and trading venues. Smaller firms get a simplified framework, but are not exempt.
DORA has five pillars: ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk, and information sharing. Testing is where we come in.
What DORA asks you to test
Article 24 requires a risk-based digital operational resilience testing programme, and testing of all ICT systems and applications that support critical or important functions at least once a year. The tests must be carried out by independent parties, internal or external.
Article 25 lists the kinds of test the programme should include. The ones we deliver are below.
| Test type in DORA | Named in Article 25 | How we help |
|---|---|---|
| Vulnerability assessments and scans | Yes | Vulnerability management, attack surface management |
| Network security assessments | Yes | Infrastructure and network testing |
| Physical security reviews | Yes | Physical penetration testing |
| Scenario-based tests | Yes | Tabletop exercises, red teaming |
| Penetration tests | Yes | Penetration testing of applications, cloud and infrastructure |
| Threat-led penetration testing (TLPT) | Article 26, if your authority requires it | Red team readiness exercises before a formal TLPT |
Findings have to be fixed, and you need procedures to prioritise, classify and remediate the issues that testing finds. Keeping that evidence in one place is what the platform is for.
Threat-led penetration testing
Article 26 requires some entities, identified by their national competent authority, to carry out advanced threat-led penetration testing (TLPT) at least every three years. TLPT follows the TIBER-EU approach: a threat intelligence phase, then a red team test against live production systems, under the oversight of the authority.
A formal TLPT has strict requirements for testers and threat intelligence providers, set out in Article 27 and the regulatory technical standards. If you are in scope, a red team readiness exercise beforehand is a sensible way to find the obvious gaps on your own terms, rather than in front of your regulator.
What it means for UK firms
DORA is EU law. It does not apply directly to UK firms, and UK financial firms work under their own regime: the PRA and FCA operational resilience rules, with CBEST for threat-led testing.
It still reaches the UK in two ways. UK groups with EU-regulated subsidiaries must comply for those entities. And UK technology suppliers to EU financial entities are affected through their contracts: Article 30 requires those contracts to include security requirements, audit and access rights, help during ICT incidents, and in some cases participation in the client’s threat-led testing.
If you supply software, cloud or managed services to EU banks, insurers or payment firms, expect to be asked for evidence of regular testing and vulnerability management. Being able to show it is now a commercial requirement.
How APOLLOSEC helps
- A testing programme that meets Article 25, from continuous vulnerability scanning to penetration tests and scenario-based exercises.
- Annual testing of critical systems, scoped to the ICT that supports your critical or important functions.
- Evidence in one place: every test, finding, deadline and retest recorded on the platform for your auditors and regulator.
- Red team readiness before a formal TLPT.
- Supplier assurance for UK ICT providers who need to show EU financial customers their security is tested.
Background reading: our earlier article on preparing for DORA.