SkarpSkarp

Chapter 10 of 15

DORA Regulation (EU) 2022/2554 — Resilience Testing and Threat-Led Penetration Testing

Controls that exist only on paper do not establish resilience. Chapter IV sets a graduated testing programme and then imposes tightly governed threat-led penetration testing on selected entities.

19 min readen

1. From paper controls to tested resilience

Why Chapter IV matters

DORA Chapter IV requires testing, not merely written controls. It addresses ordinary resilience testing first, then advanced TLPT, and finally the people allowed to conduct TLPT.

Current legal context

Article 26(11)'s technical standards were finalised in Delegated Regulation (EU) 2025/1190, in force since July 8, 2025. Chapter IV itself remains the framework taught here.

2. Article 24(1)-(3): Build the testing programme

A programme, not a one-off test

Article 24(1) requires relevant financial entities to establish, maintain and review a sound and comprehensive digital operational resilience testing programme within the Article 6 ICT risk-management framework.

Risk-based means context-sensitive

Under Article 24(3), testing must reflect evolving ICT risk, the entity's actual or possible exposures, and the criticality of its information assets and services.

Do not lose the exception

The Article 24(1) and (3) duties apply to financial entities other than microenterprises. This is not an unconditional rule for every financial entity.

3. Article 24(4)-(6): Independence, remediation, and annual coverage

Independence is required

Article 24(4) requires independent testing parties. Internal testing is permitted, but sufficient resources and avoidance of conflicts of interest are required throughout test design and execution.

A finding needs closure

Article 24(5) requires policies to prioritise, classify, and remedy all issues, plus validation methods to ascertain that identified weaknesses, deficiencies, or gaps are fully addressed.

Annual baseline

At least yearly, appropriate tests must cover all ICT systems and applications supporting critical or important functions. Article 24(6) applies to entities other than microenterprises.

4. Thought exercise: Design a defensible test cycle

Scenario

A payment firm has a customer mobile app, an identity-verification service, a cloud-hosted transaction-processing platform, and an internal HR portal. Its team tests only the mobile app once a year. Findings are recorded in a spreadsheet, but no one verifies fixes.

Your task

Identify three Article 24 problems before revealing the answer.

Suggested answer

  1. The firm must ensure at least yearly appropriate tests on all ICT systems and applications supporting critical or important functions. Testing only the mobile app may omit the identity-verification and transaction-processing components if they support those functions.
  2. It must have procedures and policies to prioritise, classify and remedy all issues revealed by tests.
  3. It must establish internal validation methodologies to ascertain that identified weaknesses, deficiencies and gaps are fully addressed.

Also ask: was testing undertaken by an independent internal or external party, and, if internal, were resources sufficient and conflicts of interest avoided?

5. Article 25: Use a range of tests

A toolkit rather than a single technique

Article 25(1) lists methods including vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, scenario-based testing, and penetration testing.

Example

A firm may combine a vulnerability scan for exposed systems, an end-to-end test of a payment flow, and a scenario-based exercise for an outage. Article 25(1) says "such as" when listing methods.

Pre-deployment condition

Article 25(2) requires central securities depositories and central counterparties to perform vulnerability assessments before any deployment or redeployment of the specified applications, infrastructure, and ICT services.

Microenterprise rule

Article 25(3) gives microenterprises a risk-based and strategically planned testing approach that balances resources and time with urgency, risk, criticality, and capacity for calculated risk.

6. Article 26(1)-(2): When TLPT applies and what it must cover

TLPT is selected, not automatic

Article 26(1) applies only to identified financial entities, other than microenterprises and entities referred to in Article 16(1), first subparagraph. The excerpt does not list the latter entities.

The frequency rule

Selected entities shall carry out at least every 3 years advanced testing by means of TLPT. A competent authority may request a reduced or increased frequency where necessary.

Production systems are in scope

Each threat-led penetration test shall cover several or all critical or important functions and shall be performed on the live production systems supporting those functions.

Scope requires validation

The entity identifies relevant ICT systems, processes, technologies, and services, including outsourced support. Its assessment determines the precise TLPT scope and competent authorities validate it.

7. Article 26(3)-(7): Third parties, pooled testing, and closure

Outsourcing does not shift responsibility

If an ICT third-party provider is in scope, Article 26(3) requires safeguards for its participation. The financial entity retains full responsibility at all times for compliance with DORA.

Pooled TLPT is conditional

Article 26(4) permits written pooled-testing arrangements only where direct provider participation is reasonably expected to harm specified service quality, security, or data confidentiality interests.

Manage live-test risk

Article 26(5) requires effective risk-management controls to mitigate possible impact on data, assets, and critical or important functions, services, or operations.

Evidence, attestation, notification

After agreed reports and remediation plans, findings and evidence go to the designated authority. Authorities issue an attestation, and the financial entity notifies its competent authority.

8. Article 26(8)-(11): Selection, tester rotation, and authorities

Rotation protects independence

Where internal testers are used for TLPT, Article 26(8) requires external testers every three tests. Significant credit institutions shall use only external testers meeting Article 27(1)(a)-(e).

Selection factors

Competent authorities identify required TLPT entities using impact on the financial sector, financial-stability concerns and systemic character, plus ICT risk profile, maturity, and technology features.

National arrangements

Member States may designate one authority for national TLPT matters. If they do not, a competent authority may delegate some or all relevant tasks to another national financial-sector authority.

RTS status

The Article 26(11) draft-RTS deadline was July 17, 2024. Delegated Regulation (EU) 2025/1190 now supplements these TLPT matters and has been in force since July 8, 2025.

9. Article 27: Who may perform TLPT?

Baseline tester requirements

Article 27(1) permits only testers with suitability, reputation, technical and organisational capability, relevant expertise, certification or ethical-framework adherence, assurance, and indemnity insurance.

Internal testers face extra conditions

Article 27(2) requires authority approval, verified dedicated resources and conflict avoidance, plus a threat-intelligence provider external to the financial entity.

Data handling is part of the contract

External-tester contracts must require sound management of results. Processing activities from generation through destruction must not create risks to the financial entity.

10. Flashcards: Recall the operative rules

Flip each card, then explain the rule aloud in your own words without removing its conditions.

Article 24(1): What must relevant entities establish?
They shall, other than microenterprises and taking Article 4(2) criteria into account, establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the Article 6 ICT risk-management framework.
Article 24(6): What is the annual minimum?
At least yearly, appropriate tests must be conducted on all ICT systems and applications supporting critical or important functions. The rule applies to financial entities other than microenterprises.
Article 26(1): How often is TLPT required?
Identified financial entities within the provision's scope shall carry out at least every 3 years advanced testing by means of TLPT. The competent authority may request a reduced or increased frequency where necessary.
Article 26(2): Where is TLPT performed?
On live production systems supporting the several or all critical or important functions covered by the threat-led penetration test.
Article 26(8): What is the internal-tester rotation rule?
When financial entities use internal testers for TLPT, they shall contract external testers every three tests.
Article 27(2)(c): What is required for internal-tester use?
The threat-intelligence provider is external to the financial entity, in addition to the Article 27(1) requirements and the other Article 27(2) conditions.

11. Knowledge check: TLPT scope

Select the statement that most accurately reflects Article 26(2).

Which statement is correct?

  1. Every TLPT must cover every ICT system owned by the financial entity, and it must be conducted only in a test environment.
  2. Each TLPT shall cover several or all critical or important functions and shall be performed on live production systems supporting those functions.
  3. A financial entity may set its TLPT scope without authority validation if an ICT third-party service provider is involved.
  4. TLPT must be performed annually by every financial entity, including every microenterprise.
Show Answer

Answer: B) Each TLPT shall cover several or all critical or important functions and shall be performed on live production systems supporting those functions.

Article 26(2) requires coverage of several or all critical or important functions and performance on live production systems supporting them. The entity assesses which functions need coverage, but competent authorities validate the precise scope. Article 26(1) does not impose annual TLPT on every entity or microenterprise.

Key Terms

TLPT
Threat-led penetration testing: the advanced testing referred to in Article 26. For selected entities within Article 26(1), it shall occur at least every 3 years.
Pooled testing
A written, conditional arrangement under Article 26(4) in which an ICT third-party service provider contracts directly with an external tester for a TLPT involving several financial entities.
External tester
A tester outside the financial entity who must meet Article 27(1) requirements. External testers are required every three tests when internal testers are used for TLPT.
Internal tester
A tester within the financial entity. Its use is subject to independence safeguards in Article 24(4), rotation in Article 26(8), and the additional conditions in Article 27(2).
Competent authority
The authority that, among other roles in this Chapter IV excerpt, identifies financial entities required to perform TLPT and validates the precise TLPT scope.
Live production systems
The systems supporting the critical or important functions covered by a TLPT; Article 26(2) requires the test to be performed on them.
Critical or important functions
Functions used in Articles 24 and 26 to define annual-test coverage and TLPT scope. This Chapter IV excerpt does not provide a separate definition.
Digital operational resilience testing programme
The Article 24(1) programme that relevant financial entities shall establish, maintain and review as an integral part of the Article 6 ICT risk-management framework.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself