DORA · Digital Operational Resilience Act · Financial Sector
DORA has been in force since 17 January 2025. The transition period has ended and regulators are actively checking compliance.
DORA has applied directly since 17 January 2025, and since 2026 the grace period is over: national regulators such as BaFin cross-check the Register of Information automatically and run active compliance reviews. Banks, insurers, payment service providers, and their critical IT suppliers must regularly demonstrate digital operational resilience through technical testing. Our penetration test delivers exactly this evidence, per Art. 24 and 25 DORA, auditable and ready for direct use.
Art. 24 / 25 DORA
Regular security testing
Art. 25 DORA mandates annual testing of digital operational resilience, and penetration tests are the recognised evidence instrument.
Documented test evidence
Your report must contain findings, risk assessments, and remediation measures, ready for use in regulatory audits and internal compliance.
Supply chain in scope
DORA extends to critical IT service providers. Even as an IT supplier to a bank, you may be subject to DORA obligations.
Art. 26 / 27 DORA · TLPT
TLPT applies to few institutions
TLPT is mandatory only for institutions designated as "significant" by their supervisor: e.g. G-SIIs/O-SIIs, payment institutions processing over €150bn per year (in each of the two preceding calendar years), or insurers with over €1.5bn in gross written premiums and at the same time over €10bn in technical provisions. Everyone else is covered by a structured pentest under Art. 25.
Our DORA pentest report is designed for direct use in regulatory audits, internal compliance evidence, and board-level reporting.
DORA explained
The Digital Operational Resilience Act (DORA) is an EU regulation that has applied directly in all EU member states since 17 January 2025. It requires financial companies and their critical IT service providers to systematically test and demonstrate digital operational resilience. DORA replaces and harmonises previously fragmented national requirements, directly affecting more than 22,000 organisations across the EU.
DORA has been in force since 17 January 2025. The transition period has ended and regulators are actively checking compliance.
The regulation applies directly without national implementing legislation. The BaFin and ECB are monitoring compliance.
IT service providers, cloud providers, and data centres may also be DORA-obligated if they provide critical functions for financial entities.
DORA timeline
DORA is no longer a future concern: it has followed a clear roadmap since 2023, from entry into force to today's active supervisory practice.
Regulation (EU) 2022/2554 is published in the Official Journal and formally enters into force, with a two-year transition period before the application date.
DORA applies directly, without national implementing legislation, across all EU member states. From this date, financial entities must be able to demonstrate technical compliance.
The ESAs (EBA, ESMA, EIOPA) finalise the Regulatory Technical Standards (RTS), including on the Register of Information and TLPT methodology. Supervisors initially focus on assessing implementation readiness.
The grace period is over: national competent authorities now run active compliance reviews, cross-check the Register of Information automatically, and issue the first fines and periodic penalty payments.
Art. 25 vs. Art. 26 DORA
Art. 24 / 25 DORA
Criterion
Art. 26 / 27 DORA · TLPT
All DORA-obligated entities
Target group
Institutions designated as "significant" by their supervisor
Penetration test / VA
Test type
TLPT (TIBER-EU framework)
Annual
Frequency
Every 3 years
Fully covered
Our service
Outside our scope
Manageable, plannable
Effort
Very high, accredited team required
The vast majority of the market (banks, insurers, payment providers, fintechs, and IT service providers) falls under Art. 25 DORA. TLPT is also explicitly aligned with the TIBER-EU framework: a test correctly run under TIBER-EU also satisfies the DORA obligation. That is exactly what our pentest covers, under Art. 25.
Who is affected?
DORA covers virtually the entire financial industry and its IT service providers. If your organisation operates in one of the areas below, you are very likely subject to DORA obligations.
Regulatory action: supervisory authorities can impose requirements, restrict operations, or issue fines where evidence of compliance is missing.
Fines under the German Banking Act: DORA itself states no amounts and leaves them to the member states. In Germany, failing to report a major incident or to carry out a TLPT carries up to €5 million, all other breaches up to €500,000 (section 56(5e) in conjunction with (6) KWG). There is no turnover-based percentage.
Management body responsibility: Article 5(2) DORA assigns ultimate responsibility for the ICT risk management framework to the management body. The offence in section 56(5e) KWG applies to whoever commits the breach, so it reaches directors personally. DORA sets no separate ceiling for them.
Reputational damage: security incidents without proven protective measures put banking licences, customer trust, and business partnerships at risk.
Register violations: failing to submit the Register of Information on time or in full is a standalone compliance violation.
Assessment areas
Art. 25 DORA defines a whole spectrum of "appropriate tests": from vulnerability assessments and scenario-based testing to source code reviews of safety-critical applications, physical security reviews, and penetration testing. Our pentest covers the practically relevant core areas and maps every finding directly to the corresponding DORA articles.
Segmentation, firewall configurations, exposed services, and privileged access: we test whether your network meets the requirements for digital operational resilience.
Art. 25 DORA · Infrastructure pentest
Active Directory, privileged accounts, MFA enforcement, and lateral movement opportunities: central attack vectors in the financial sector.
Art. 25 DORA · AD pentest
Web applications, banking portals, APIs, and internal tools: we test against OWASP Top 10 and financial-sector-specific vulnerabilities, and where needed add source code reviews for particularly critical applications, as Art. 25 DORA envisages for safety-critical systems.
Art. 25 DORA · Web app pentest
Access control for server rooms, data centres, and sensitive areas: physical attack vectors are also relevant under DORA.
Art. 25 DORA · Physical pentest
Phishing, vishing, and pretexting targeting your employees: human vulnerabilities are the most common entry point for attackers in the financial sector.
Art. 25 DORA · Social engineering
Art. 28 DORA requires you to maintain a continuously updated register of all ICT third-party contracts (reported annually) and to review critical IT service providers, which can themselves fall under direct ESA oversight as a "critical ICT third-party provider". We test remote access points, API interfaces, and third-party integrations.
Art. 25 DORA · Supply chain
around 22,000
affected organisations across the EU
Since Jan. 2025
DORA in force, active supervisory enforcement since 2026
€5 million
German fine ceiling, section 56 KWG
Source: European Commission / European Supervisory Authorities (ESAs), DORA impact assessment
Our approach
We guide you from scope definition to an audit-ready report: structured, on time, and fully mapped to the relevant DORA articles.
Joint definition of the systems, applications, and processes to be tested. We identify upfront which DORA articles apply to your scope.
OSINT on your organisation, network footprinting, and planning of realistic attack paths, the way real attackers in the financial sector operate.
Manual testing within the agreed scope: infrastructure, Active Directory, web applications, physical security, and social engineering.
All findings are mapped directly to the corresponding DORA articles, for maximum auditability with regulators and internal reviewers.
Detailed pentest report with CVSS ratings, DORA mapping, prioritised remediation recommendations, and an executive summary for the board and senior management.
Illustrative example – no real customer data.
Our services
We combine all relevant attack vectors into a comprehensive DORA assessment, from infrastructure to the human factor, everything mapped to Art. 25.
Network segmentation, firewall configurations, Active Directory security, and remote access: technically verified and directly mapped to DORA Art. 25.
Learn moreBanking portals, customer applications, and internal APIs: we test against OWASP Top 10 and financial-sector-specific vulnerabilities including session hijacking and insecure direct object references.
Learn morePhishing simulations, vishing, and physical access tests: we verify whether your staff and access control systems withstand real-world attacks.
Learn moreFrequently asked questions
In 30 minutes we discuss your DORA scope, clarify which systems need to be tested, and you receive a no-obligation fixed-price quote, free of charge.