Expert solutions for regulatory testing requirements in the financial sector

DORA Operational Resilience Testing: Art. 24-26 Programme

DORA Articles 24-26 prescribe a structured digital resilience testing programme for financial institutions.

  • 01Fully DORA-compliant testing strategies and frameworks
  • 02Threat-Led Penetration Testing (TLPT) in accordance with regulatory standards
  • 03Integrated ICT risk assessment and vulnerability management
  • 04Automated testing processes and continuous monitoring
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

DORA Operational Resilience Testing under Art. 24-26

The DORA testing programme operates on multiple levels: basic connectivity tests, vulnerability scans, penetration tests, and for significant financial institutions the advanced TLPT under Art. 26. We develop tailored testing strategies that ensure regulatory compliance and sustainably strengthen your cyber resilience.

We offer a comprehensive range of services for DORA Operational Resilience Testing, spanning from strategic planning to technical implementation and continuous optimization. Our approach combines regulatory expertise with modern testing technologies.

6 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

DORA Testing Strategy & Governance Framework

Development of comprehensive testing strategies and governance frameworks to fulfill the requirements of DORA Article 25.

  • Risk-based testing strategy development in accordance with DORA standards
  • Governance framework design for operational resilience testing
  • Integration into existing risk management frameworks
  • Compliance mapping and regulatory documentation
02

Threat-Led Penetration Testing (TLPT)

Implementation and execution of TLPT programs in accordance with DORA requirements and ECB guidelines.

  • TLPT program design and implementation
  • Red team exercises and Advanced Persistent Threat simulation
  • Threat intelligence integration and scenario development
  • TLPT reporting and remediation planning
03

ICT Risk Assessment & Vulnerability Management

Comprehensive ICT risk assessment and vulnerability management for the identification and remediation of security gaps.

  • Continuous ICT risk assessment and asset discovery
  • Vulnerability scanning and penetration testing
  • Risk scoring and prioritization frameworks
  • Remediation tracking and compliance monitoring
04

Automated Testing Solutions

Implementation of automated testing solutions for continuous monitoring and validation of operational resilience.

  • Automated security testing and continuous assessment
  • DevSecOps integration and pipeline security testing
  • Real-time monitoring and alerting systems
  • Automated reporting and compliance dashboards
05

Incident Response & Recovery Testing

Development and validation of incident response capabilities and recovery testing frameworks.

  • Incident response plan development and testing
  • Crisis simulation and tabletop exercises
  • Recovery Time and Recovery Point Objective validation
  • Business continuity testing and resilience validation
06

Third-Party Risk Testing & Validation

Assessment and testing of the operational resilience of critical third-party providers and ICT service providers.

  • Third-party risk assessment and due diligence
  • Supplier resilience testing and validation
  • Contractual security requirements and SLA monitoring
  • Supply chain risk management and contingency planning

5 phases

Our Approach

Together with you, we develop a tailored DORA testing strategy that meets regulatory requirements while sustainably strengthening your operational resilience.

  1. Comprehensive analysis of your ICT landscape and identification of critical systems

  2. Development of a risk-based DORA testing strategy and roadmap

  3. Implementation of TLPT programs and automated testing processes

  4. Integration of testing frameworks into existing governance structures

  5. Continuous optimization and adaptation to evolving threat landscapes

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

DORA Operational Resilience Testing is more than just regulatory compliance, it is a strategic building block for sustainable cyber resilience. Our integrated testing frameworks enable financial institutions not only to fulfill DORA requirements, but also to continuously strengthen their operational resilience against evolving cyber threats.

Our Expertise

  • 01In-depth expertise in DORA requirements and regulatory testing standards
  • 02Many years of experience in cyber resilience testing and penetration testing
  • 03End-to-end approach from strategy through to technical implementation
  • 04Effective automation solutions for continuous testing processes

Regulatory Notice

DORA Article 25 requires financial institutions to implement comprehensive operational resilience testing programs by January 2025. Early strategic preparation is critical for successful compliance implementation.

6 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about DORA Operational Resilience Testing

What types of testing does DORA require for resilience testing?

DORA distinguishes a baseline testing program that every entity must run, such as vulnerability scans and scenario analyses, from the more advanced Threat-Led Penetration Testing (TLPT), which is mandatory only for certain, typically larger and systemically important financial entities. Scope depends on the size and risk profile of the entity.

What is TLPT, and who does it apply to?

Threat-Led Penetration Testing simulates a real, targeted attack on critical systems carried out by an accredited external tester, based on the European TIBER-EU framework. It's mandatory for financial entities designated as systemically significant by the relevant supervisor; that designation is made individually, not simply based on company size alone.

How does resilience testing differ from classic IT security testing?

Classic IT security tests usually check isolated technical vulnerabilities. DORA resilience testing additionally assesses whether the organization as a whole can respond to a successful attack: detection, containment, recovery, and communication are tested as an integrated process, not just the technical defense alone.

How often must the various test types be repeated?

The baseline testing program should run at least annually, while TLPT tests for entities in scope are typically required every three years. Additional, event-driven testing is advisable after material changes to the IT landscape or a major ICT incident, independent of the regular test cycle.

How are test results documented and submitted to supervisors?

Test results should be documented in a structured format, including identified vulnerabilities, their assessment, and the remediation measures taken with deadlines. For TLPT tests, confirmation from the relevant authority is additionally provided, verifying the test was conducted properly under the TIBER-EU standard.

What happens if a test uncovers vulnerabilities?

Identified vulnerabilities need to be prioritized and tracked with concrete, time-bound actions; a test without a follow-on remediation process only meets DORA's requirement formally, not substantively. For TLPT tests, remediation of critical findings is also expected to be demonstrably complete before the next test cycle.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance