Chapter 3 of 15
DORA Regulation (EU) 2022/2554 — Proportionality, Governance, Recovery, and TLPT
A single regime cannot treat every financial entity identically. This chapter examines how DORA combines broad ICT coverage with proportionality, management accountability, recovery duties, streamlined reporting, and advanced threat-led penetration testing.
1. Broad ICT Coverage and the Boundaries of Scope
A deliberately broad starting point
Recital (35) says DORA should address risk from all types of ICT services, supporting sector-wide resilience while keeping pace with technological development.
What counts as an ICT service?
The definition should be understood in a broad manner, covering ongoing digital and data services through ICT systems for one or more internal or external users.
Example and narrow exclusion
So-called over-the-top services are included as an example. Only traditional analogue PSTN, landline, POTS, or fixed-line telephone services are excluded.
Scope is broad, not unlimited
Recitals (37), (39), (40), and (41) identify included entities, exclusions, and Member State choices. Scope depends on each stated category and condition.
Currency check
A June 28, 2023 proposal would add financial information service providers to Article 2(1), but it remains proposed as of July 24, 2026.
2. Proportionality: Scale the Framework Without Losing Resilience
The proportionality variables
Recital (36) says entities should balance ICT needs against size, overall risk profile, and the nature, scale, and complexity of services, activities, and operations.
Supervisory check
Competent authorities should continue to assess and review how resources and capabilities are distributed for the ICT risk management framework.
Microenterprise distinction
Recital (38): "only financial entities that are not microenterprises in the sense of this Regulation should be required to establish more complex governance arrangements".
Simplified framework
Recital (42) identifies specified small, exempt, or lightly regulated entities for a simplified ICT risk management framework, including certain schemes with up to 100 members.
Not simply an exemption
Recital (43) removes many specified arrangements for microenterprises and simplified entities. A microenterprise still should assess its need for redundant ICT capacity from its risk profile.
3. Apply Proportionality: Choose the Most Accurate Reading
Thought exercise: Do not overstate what Recital (43) says
Consider three hypothetical entities. Match each to the most accurate conclusion based only on Recitals (42) and (43) of DORA.
- Entity A is a microenterprise. Its leadership says: "We never need redundant ICT capacity because microenterprises are exempt."
- Entity B is subject to DORA's simplified ICT risk management framework. Its leadership says: "We must perform TLPT every year because every financial entity must carry out advanced testing."
- Entity C is a payment institution that has not been exempted under national law transposing the relevant sectoral Union law. Its leadership says: "We automatically receive the simplified framework because some payment institutions do."
Pause and decide whether each statement is accurate.
Suggested answer
- Entity A is inaccurate. Recital (43) says microenterprises should only be required to assess the need to maintain redundant ICT capacities based on their risk profile. That is not the same as saying redundancy can never be needed.
- Entity B is inaccurate. Microenterprises and financial entities subject to the simplified framework should be exempted from advanced testing based on TLPT. The recital reserves TLPT for entities meeting DORA's criteria.
- Entity C is inaccurate. Recital (42) distinguishes exempted payment institutions from those not exempted under relevant national law. Those not exempted should comply with the general framework.
Visual description: Think of a three-lane road. The general framework is the main lane; the simplified framework is a narrower lane for specified entities; TLPT is an advanced lane reached only by entities that satisfy the relevant criteria. Proportionality changes the route and intensity of controls. It does not mean that risk management disappears.
4. Governance: Management Body Responsibility, Investment, and ICT Functions
A pivotal and active role
Recital (45) says management bodies should be required to steer and adapt the ICT risk management framework and overall digital operational resilience strategy.
Beyond technology
The management-body approach should cover people and processes through cyber-risk awareness at each corporate layer and strict cyber hygiene for all staff.
Ultimate responsibility
"The ultimate responsibility of the management body in managing a financial entity’s ICT risk should be an overarching principle of that comprehensive approach".
Capability, not one diagram
Recital (47) lists identification, protection and prevention, detection, response and recovery, learning and evolving, and communication. Models may differ if they address these functions.
Resources and current systems
Recitals (46) and (48) link responsibility to adequate ICT investment and budget, plus updated, reliable, capable systems able to handle stressed conditions.
5. Recovery and Continuity: Resume Activities Without Compromising Security
Why continuity plans matter
Recital (49) says efficient business continuity and recovery plans are necessary to resolve ICT incidents promptly, limit damage, and prioritise resumption and recovery.
The non-negotiable boundary
Resumption should in no way jeopardise system integrity and security or data availability, authenticity, integrity, or confidentiality.
Flexible objectives
Entities may determine recovery time and recovery point objectives flexibly, considering the nature and criticality of functions and specific business needs.
But assess market impact
Recital (50) says entities should nevertheless be required to assess potential overall impact on market efficiency when determining recovery objectives.
6. Incident Reporting: Direct Reporting, Information Flows, and a Proposed Change
Harmonised direct reporting
Recital (51) says reporting should be improved and streamlined through direct reporting by all financial entities to their relevant competent authorities.
One addressee where needed
If more than one national competent authority supervises an entity, Member States should designate a single competent authority to receive the report.
Why direct reporting?
"The direct reporting should enable financial supervisors to have immediate access to information about major ICT-related incidents."
A two-way information flow
Supervisors should provide feedback or guidance; ESAs should share anonymised cyber-threat and vulnerability data to aid collective defence.
Proposal is not current law
COM(2025) 837 would route Article 19 reporting through a NIS2 single-entry point, but it remains proposed as of July 24, 2026.
7. TLPT: From Basic Testing to Advanced, Threat-Led Testing
Testing is a spectrum
Recital (56) ranges from scans, reviews, and scenario tests to advanced TLPT. Entities should regularly test systems and ICT-responsible staff.
Who faces TLPT?
"Such advanced testing should be required only of financial entities that are mature enough from an ICT perspective to reasonably carry it out."
One test framework for cross-border groups
A qualifying cross-border group should comply with one set of TLPT requirements in its home Member State, including Union-wide group infrastructure.
Scope and pooled testing
An entity may choose which and how many critical or important functions to test. Pooled testing is allowed only under the recital's condition and safeguards.
Internal testers are conditional
Internal testers need supervisory approval and no conflicts. The rule requires "periodical alternation of the use of internal and external testers (every three tests)".
8. Quiz: Recovery Objectives and Safeguards
Choose the most accurate answer
A financial entity sets an extremely short recovery time objective for a critical function. During an incident, its team proposes to restore the function using data whose integrity has not yet been verified. Which answer best reflects Recitals (49) and (50)?
What is the best answer?
- Proceed immediately because Recital (50) gives complete freedom to set recovery objectives.
- Do not treat speed as overriding security: resumption should in no way jeopardise system integrity and security or the listed data qualities; recovery objectives also require assessment of potential overall impact on market efficiency.
- Delay all recovery until every ICT system in the entity has been rebuilt.
- Ignore back-up policies because the criticality of the function is the only consideration.
Show Answer
Answer: B) Do not treat speed as overriding security: resumption should in no way jeopardise system integrity and security or the listed data qualities; recovery objectives also require assessment of potential overall impact on market efficiency.
Recital (49) prioritises resumption and recovery in accordance with back-up policies, but says resumption should in no way jeopardise network and information system integrity and security or data availability, authenticity, integrity, or confidentiality. Recital (50) permits flexible objectives but says entities should nevertheless be required to assess potential overall impact on market efficiency.
9. Flashcards: Precision Recall
Flip each card and test your recall of the recital-level wording and conditions.
- How does Recital (35) describe ICT services?
- "the definition of ICT services in the context of this Regulation should be understood in a broad manner, encompassing digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis"
- Which telephone services does Recital (35) exclude?
- Only the limited category of traditional analogue telephone services qualifying as PSTN, landline services, POTS, or fixed-line telephone services.
- What is the Recital (38) microenterprise rule?
- "only financial entities that are not microenterprises in the sense of this Regulation should be required to establish more complex governance arrangements"
- What is the management body's overarching principle in Recital (45)?
- "The ultimate responsibility of the management body in managing a financial entity’s ICT risk should be an overarching principle of that comprehensive approach"
- What does direct incident reporting enable under Recital (52)?
- "The direct reporting should enable financial supervisors to have immediate access to information about major ICT-related incidents."
- What conditions apply to using internal TLPT testers?
- Supervisory approval, no conflicts of interest, and "periodical alternation of the use of internal and external testers (every three tests)". Threat intelligence must always be external.
10. Final Quiz: Identify the Exact TLPT Position
Choose the statement that follows Recitals (56) to (61) most closely.
Which statement is correct?
- Every financial entity should perform TLPT because all ICT vulnerabilities require advanced testing.
- A single TLPT must cover all critical or important functions of the financial entity.
- TLPT should be required only of entities mature enough from an ICT perspective to reasonably carry it out; an entity may determine which and how many critical or important functions to include in a test.
- An authority's TLPT attestation is a supervisory endorsement that the entity's ICT risk management is adequate.
Show Answer
Answer: C) TLPT should be required only of entities mature enough from an ICT perspective to reasonably carry it out; an entity may determine which and how many critical or important functions to include in a test.
Recital (56) limits advanced testing to financial entities mature enough from an ICT perspective to reasonably carry it out. Recital (59) says financial entities should be free to determine which and how many critical or important functions are included. Recital (61) says attestations are solely for mutual recognition and are not supervisory endorsements.
Key Terms
- PSTN
- Public Switched Telephone Network; one of the traditional analogue telephone service categories excluded in Recital (35).
- TLPT
- Threat-led penetration testing; the advanced form of digital operational resilience testing discussed in Recitals (56) to (61).
- ICT services
- In Recital (35), digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, understood broadly.
- pooled testing
- A TLPT involving several financial entities, permitted by Recital (60) only under stated conditions and safeguards.
- management body
- The governing body that Recital (45) places at the centre of steering and adapting ICT risk management and digital operational resilience strategy.
- microenterprise
- A financial entity that qualifies as a microenterprise in the sense of DORA; Recitals (38) and (43) attach specific proportionality consequences to this category.
- threat intelligence
- Information used in a TLPT; Recital (61) says its provider must always be external to the financial entity.
- recovery time objective
- An objective that a financial entity may determine flexibly under Recital (50), taking account of relevant function criticality and business needs.
- recovery point objective
- An objective that a financial entity may determine flexibly under Recital (50), alongside consideration of function criticality and business needs.
- major ICT-related incident
- The category of incident addressed by the improved and streamlined reporting approach described in Recitals (51) to (53).
- simplified ICT risk management framework
- The proportionate framework Recital (42) says should apply to specified smaller, exempt, or lightly regulated financial entities.