DORA · Digital Operational Resilience Act · Financial Sector

DORA pentest: Resilience evidence for the financial sector

DORA has been in force since 17 January 2025. The transition period has ended and regulators are actively checking compliance.

DORA has applied directly since 17 January 2025, and since 2026 the grace period is over: national regulators such as BaFin cross-check the Register of Information automatically and run active compliance reviews. Banks, insurers, payment service providers, and their critical IT suppliers must regularly demonstrate digital operational resilience through technical testing. Our penetration test delivers exactly this evidence, per Art. 24 and 25 DORA, auditable and ready for direct use.

  • Art. 25 DORA covered
  • Report delivered within 5 working days
  • Free initial consultation
What DORA requires of you

Art. 24 / 25 DORA

  • Regular security testing

    Art. 25 DORA mandates annual testing of digital operational resilience, and penetration tests are the recognised evidence instrument.

  • Documented test evidence

    Your report must contain findings, risk assessments, and remediation measures, ready for use in regulatory audits and internal compliance.

  • Supply chain in scope

    DORA extends to critical IT service providers. Even as an IT supplier to a bank, you may be subject to DORA obligations.

Art. 26 / 27 DORA · TLPT

  • TLPT applies to few institutions

    TLPT is mandatory only for institutions designated as "significant" by their supervisor: e.g. G-SIIs/O-SIIs, payment institutions processing over €150bn per year (in each of the two preceding calendar years), or insurers with over €1.5bn in gross written premiums and at the same time over €10bn in technical provisions. Everyone else is covered by a structured pentest under Art. 25.

Our DORA pentest report is designed for direct use in regulatory audits, internal compliance evidence, and board-level reporting.

DORA explained

What is DORA and who does it affect?

The Digital Operational Resilience Act (DORA) is an EU regulation that has applied directly in all EU member states since 17 January 2025. It requires financial companies and their critical IT service providers to systematically test and demonstrate digital operational resilience. DORA replaces and harmonises previously fragmented national requirements, directly affecting more than 22,000 organisations across the EU.

  1. 01

    DORA has been in force since 17 January 2025. The transition period has ended and regulators are actively checking compliance.

  2. 02

    The regulation applies directly without national implementing legislation. The BaFin and ECB are monitoring compliance.

  3. 03

    IT service providers, cloud providers, and data centres may also be DORA-obligated if they provide critical functions for financial entities.

DORA timeline

From regulation to active enforcement

DORA is no longer a future concern: it has followed a clear roadmap since 2023, from entry into force to today's active supervisory practice.

  1. 16 Jan 2023

    DORA enters into force

    Regulation (EU) 2022/2554 is published in the Official Journal and formally enters into force, with a two-year transition period before the application date.

  2. 17 Jan 2025

    Application date

    DORA applies directly, without national implementing legislation, across all EU member states. From this date, financial entities must be able to demonstrate technical compliance.

  3. 2025

    Transition year & RTS finalisation

    The ESAs (EBA, ESMA, EIOPA) finalise the Regulatory Technical Standards (RTS), including on the Register of Information and TLPT methodology. Supervisors initially focus on assessing implementation readiness.

  4. Since 2026

    Active enforcement

    The grace period is over: national competent authorities now run active compliance reviews, cross-check the Register of Information automatically, and issue the first fines and periodic penalty payments.

Art. 25 vs. Art. 26 DORA

Which DORA requirement applies to you?

Art. 24 / 25 DORA

Criterion

Art. 26 / 27 DORA · TLPT

All DORA-obligated entities

Target group

Institutions designated as "significant" by their supervisor

Penetration test / VA

Test type

TLPT (TIBER-EU framework)

Annual

Frequency

Every 3 years

Fully covered

Our service

Outside our scope

Manageable, plannable

Effort

Very high, accredited team required

The vast majority of the market (banks, insurers, payment providers, fintechs, and IT service providers) falls under Art. 25 DORA. TLPT is also explicitly aligned with the TIBER-EU framework: a test correctly run under TIBER-EU also satisfies the DORA obligation. That is exactly what our pentest covers, under Art. 25.

Who is affected?

Which organisations in the financial sector does DORA apply to?

DORA covers virtually the entire financial industry and its IT service providers. If your organisation operates in one of the areas below, you are very likely subject to DORA obligations.

  1. 01Banks & credit institutions
  2. 02Insurers & reinsurers
  3. 03Payment service providers
  4. 04Investment firms
  5. 05Investment funds & asset managers
  6. 06Crypto-asset service providers (MiCA)
  7. 07Fintechs & neobanks
  8. 08Critical ICT third-party providers
  9. 09Exchanges & trading venues

What are the consequences of missing DORA evidence?

  1. Regulatory action: supervisory authorities can impose requirements, restrict operations, or issue fines where evidence of compliance is missing.

  2. Fines under the German Banking Act: DORA itself states no amounts and leaves them to the member states. In Germany, failing to report a major incident or to carry out a TLPT carries up to €5 million, all other breaches up to €500,000 (section 56(5e) in conjunction with (6) KWG). There is no turnover-based percentage.

  3. Management body responsibility: Article 5(2) DORA assigns ultimate responsibility for the ICT risk management framework to the management body. The offence in section 56(5e) KWG applies to whoever commits the breach, so it reaches directors personally. DORA sets no separate ceiling for them.

  4. Reputational damage: security incidents without proven protective measures put banking licences, customer trust, and business partnerships at risk.

  5. Register violations: failing to submit the Register of Information on time or in full is a standalone compliance violation.

Assessment areas

Which DORA requirements do we test technically?

Art. 25 DORA defines a whole spectrum of "appropriate tests": from vulnerability assessments and scenario-based testing to source code reviews of safety-critical applications, physical security reviews, and penetration testing. Our pentest covers the practically relevant core areas and maps every finding directly to the corresponding DORA articles.

  1. Network & system security

    Segmentation, firewall configurations, exposed services, and privileged access: we test whether your network meets the requirements for digital operational resilience.

    Art. 25 DORA · Infrastructure pentest

  2. Access management & identities

    Active Directory, privileged accounts, MFA enforcement, and lateral movement opportunities: central attack vectors in the financial sector.

    Art. 25 DORA · AD pentest

  3. Application security

    Web applications, banking portals, APIs, and internal tools: we test against OWASP Top 10 and financial-sector-specific vulnerabilities, and where needed add source code reviews for particularly critical applications, as Art. 25 DORA envisages for safety-critical systems.

    Art. 25 DORA · Web app pentest

  4. Physical security

    Access control for server rooms, data centres, and sensitive areas: physical attack vectors are also relevant under DORA.

    Art. 25 DORA · Physical pentest

  5. Social engineering & awareness

    Phishing, vishing, and pretexting targeting your employees: human vulnerabilities are the most common entry point for attackers in the financial sector.

    Art. 25 DORA · Social engineering

  6. Third parties & ICT supply chain

    Art. 28 DORA requires you to maintain a continuously updated register of all ICT third-party contracts (reported annually) and to review critical IT service providers, which can themselves fall under direct ESA oversight as a "critical ICT third-party provider". We test remote access points, API interfaces, and third-party integrations.

    Art. 25 DORA · Supply chain

testing obligation under Art. 24(6) Art. 28 DORA requires a continuously updated register of all ICT third-party contracts, reported to the supervisor at least once a year. BaFin announces the submission window annually.

around 22,000

affected organisations across the EU

Since Jan. 2025

DORA in force, active supervisory enforcement since 2026

€5 million

German fine ceiling, section 56 KWG

Source: European Commission / European Supervisory Authorities (ESAs), DORA impact assessment

Our approach

How does your DORA pentest work?

We guide you from scope definition to an audit-ready report: structured, on time, and fully mapped to the relevant DORA articles.

  1. Step 01

    Scope definition & DORA mapping

    Joint definition of the systems, applications, and processes to be tested. We identify upfront which DORA articles apply to your scope.

  2. Step 02

    Reconnaissance & attack planning

    OSINT on your organisation, network footprinting, and planning of realistic attack paths, the way real attackers in the financial sector operate.

  3. Step 03

    Technical penetration test

    Manual testing within the agreed scope: infrastructure, Active Directory, web applications, physical security, and social engineering.

  4. Step 04

    Analysis & DORA article mapping

    All findings are mapped directly to the corresponding DORA articles, for maximum auditability with regulators and internal reviewers.

  5. Step 05

    Report & handover

    Detailed pentest report with CVSS ratings, DORA mapping, prioritised remediation recommendations, and an executive summary for the board and senior management.

DORA pentest report · sample excerpt Sample
Exposed admin interface without MFAArt. 25 DORA
Active Directory: kerberoastable accountsArt. 25 DORA
Banking portal: SQL injection in search fieldArt. 25 DORA
Phishing simulation: significant share of staff responded (example figure)Art. 25 DORA
VPN: outdated TLS version (1.1)Art. 25 DORA
Server room: tailgating without challengeArt. 25 DORA
DORA Art. 24 & 25 mapped Digital Operational Resilience Act (EU) 2022/2554

Illustrative example – no real customer data.

Frequently asked questions

DORA & penetration testing: your questions answered

Very likely yes. DORA applies to virtually all regulated financial entities in the EU: banks, insurers, payment service providers, investment firms, fintechs, crypto-asset service providers, and critical IT service providers of these entities. The full list is set out in Art. 2 DORA. According to the European Commission, this affects more than 22,000 entities across the EU alone.
No. Threat-Led Penetration Testing (TLPT per TIBER-EU) is only mandatory for systemically important financial institutions designated as significant by the ECB or national regulators. The vast majority of the market falls under Art. 25 DORA, where a structured penetration test is sufficient. TLPT applies specifically to G-SIIs/O-SIIs, payment service providers with an annual payment volume above €150 billion, or insurers with gross premiums above €500 million.
Art. 25 DORA mandates annual testing. We also recommend additional tests after significant changes to your IT infrastructure, after security incidents, or when new systems and applications are introduced. Since 2026 the earlier grace period is over: supervisors such as BaFin cross-check these records actively and automatically.
DORA explicitly provides for a proportionality principle (Art. 4 DORA): the scope and intensity of requirements depend on your size, risk profile, and the nature, scale, and complexity of your services. Small, non-interconnected investment firms and certain small payment institutions benefit from reduced requirements. In principle, though, you are still in scope as soon as you fall under one of the categories listed in Art. 2 DORA; only the concrete testing scope is scaled to risk.
Costs depend on scope, company size, and the test modules required. After a free initial consultation you will receive a transparent fixed-price offer, typically within 24 hours. A single test area, such as infrastructure or a web application, costs noticeably less than a combined DORA assessment covering several modules.
Yes. DORA requires financial entities to review their critical IT service providers. At the same time, IT service providers delivering critical functions to financial entities may themselves be classified as critical ICT third-party providers and be subject to their own requirements. This obligation stems from Art. 28 DORA, which requires a continuously updated register of all ICT third-party contracts.
Art. 25 DORA requires testing of all ICT systems and applications that support critical or important functions. In practice this covers core banking systems, payment infrastructure, customer portals, internal networks, and remote access points. Art. 25 DORA explicitly names several accepted testing methods, including vulnerability assessments, scenario-based tests, and source-code reviews of security-critical applications.
A normal pentest under Art. 25 DORA targets agreed systems within a defined timeframe. TLPT (Art. 26/27, based on the TIBER-EU framework) is a months-long, threat-intelligence-driven simulation of a real attack on production systems, carried out by accredited external testers, including a red-team phase and regulatory oversight. TLPT is mandatory only for institutions designated as significant by their supervisor; the vast majority of organisations fully satisfy their DORA testing obligation under Art. 25.

Ready for your DORA pentest?

In 30 minutes we discuss your DORA scope, clarify which systems need to be tested, and you receive a no-obligation fixed-price quote, free of charge.