European Union · Regulation (EU) 2022/2554 (Digital Operational Resilience Act)
Does DORA require a penetration test?
DORA is the European Union's operational resilience regulation for the financial sector. It is the only framework here that mandates threat-led penetration testing by name, for the entities designated to perform it.
The short answer
Yes, for designated entities. DORA requires a digital operational resilience testing programme under Article 24, with a range of tests including vulnerability assessments under Article 25, and advanced threat-led penetration testing at least every three years under Article 26 for financial entities identified by the competent authority.
Who it applies to
Financial entities in the EU and, critically, the ICT third party service providers they rely on. A software vendor selling to EU financial institutions can be pulled into DORA obligations contractually.
In detail
DORA replaced a patchwork of national financial regulator expectations with one regulation applying across the EU from January 2025. Chapter IV covers testing: Article 24 requires a testing programme, Article 25 lists the test types including vulnerability assessments and scans, and Article 26 sets the threat-led penetration testing requirement.
Threat-led penetration testing under Article 26 is modelled on the TIBER-EU framework and is a different exercise from a standard application penetration test. It uses threat intelligence to build scenarios against live production systems, runs over months rather than days, and involves the competent authority in validating the process.
Not every financial entity performs TLPT. The competent authority identifies which entities must, based on impact, risk profile and ICT maturity. Everything else in Chapter IV, including the general testing programme, applies more broadly.
For a software vendor the relevant question is usually contractual rather than direct. Article 30 sets out what must be in contracts with ICT third party providers, and financial customers push testing, audit and incident obligations down to their vendors through those terms.
What to have in scope
- ICT systems supporting critical or important functions
- For TLPT, live production systems under a threat intelligence led scenario
- For vendors, whatever the Article 30 contractual terms with financial customers commit to
Questions people ask
Does DORA require penetration testing?
Yes for entities designated by their competent authority, which must perform advanced threat-led penetration testing at least every three years under Article 26. All in-scope financial entities must run a digital operational resilience testing programme under Article 24, which includes vulnerability assessments and other test types.
Does DORA apply to software vendors?
Directly, only to designated critical ICT third party service providers. Indirectly, to many more: Article 30 prescribes terms that financial entities must include in contracts with ICT providers, so testing, audit and incident obligations reach vendors through those contracts.
What is threat-led penetration testing?
A test built from threat intelligence about the specific entity, run against live production systems over an extended period, modelled on the TIBER-EU framework. It is substantially broader and longer than a scoped application penetration test.
Related frameworks
This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.