Chapter 10 of 15
DORA Regulation (EU) 2022/2554 — Resilience Testing and Threat-Led Penetration Testing
Controls that exist only on paper do not establish resilience. Chapter IV sets a graduated testing programme and then imposes tightly governed threat-led penetration testing on selected entities.
1. From paper controls to tested resilience
Why Chapter IV matters
DORA Chapter IV requires testing, not merely written controls. It addresses ordinary resilience testing first, then advanced TLPT, and finally the people allowed to conduct TLPT.
Current legal context
Article 26(11)'s technical standards were finalised in Delegated Regulation (EU) 2025/1190, in force since July 8, 2025. Chapter IV itself remains the framework taught here.
2. Article 24(1)-(3): Build the testing programme
A programme, not a one-off test
Article 24(1) requires relevant financial entities to establish, maintain and review a sound and comprehensive digital operational resilience testing programme within the Article 6 ICT risk-management framework.
Risk-based means context-sensitive
Under Article 24(3), testing must reflect evolving ICT risk, the entity's actual or possible exposures, and the criticality of its information assets and services.
Do not lose the exception
The Article 24(1) and (3) duties apply to financial entities other than microenterprises. This is not an unconditional rule for every financial entity.
3. Article 24(4)-(6): Independence, remediation, and annual coverage
Independence is required
Article 24(4) requires independent testing parties. Internal testing is permitted, but sufficient resources and avoidance of conflicts of interest are required throughout test design and execution.
A finding needs closure
Article 24(5) requires policies to prioritise, classify, and remedy all issues, plus validation methods to ascertain that identified weaknesses, deficiencies, or gaps are fully addressed.
Annual baseline
At least yearly, appropriate tests must cover all ICT systems and applications supporting critical or important functions. Article 24(6) applies to entities other than microenterprises.
4. Thought exercise: Design a defensible test cycle
Scenario
A payment firm has a customer mobile app, an identity-verification service, a cloud-hosted transaction-processing platform, and an internal HR portal. Its team tests only the mobile app once a year. Findings are recorded in a spreadsheet, but no one verifies fixes.
Your task
Identify three Article 24 problems before revealing the answer.
Suggested answer
- The firm must ensure at least yearly appropriate tests on all ICT systems and applications supporting critical or important functions. Testing only the mobile app may omit the identity-verification and transaction-processing components if they support those functions.
- It must have procedures and policies to prioritise, classify and remedy all issues revealed by tests.
- It must establish internal validation methodologies to ascertain that identified weaknesses, deficiencies and gaps are fully addressed.
Also ask: was testing undertaken by an independent internal or external party, and, if internal, were resources sufficient and conflicts of interest avoided?
5. Article 25: Use a range of tests
A toolkit rather than a single technique
Article 25(1) lists methods including vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, scenario-based testing, and penetration testing.
Example
A firm may combine a vulnerability scan for exposed systems, an end-to-end test of a payment flow, and a scenario-based exercise for an outage. Article 25(1) says "such as" when listing methods.
Pre-deployment condition
Article 25(2) requires central securities depositories and central counterparties to perform vulnerability assessments before any deployment or redeployment of the specified applications, infrastructure, and ICT services.
Microenterprise rule
Article 25(3) gives microenterprises a risk-based and strategically planned testing approach that balances resources and time with urgency, risk, criticality, and capacity for calculated risk.
6. Article 26(1)-(2): When TLPT applies and what it must cover
TLPT is selected, not automatic
Article 26(1) applies only to identified financial entities, other than microenterprises and entities referred to in Article 16(1), first subparagraph. The excerpt does not list the latter entities.
The frequency rule
Selected entities shall carry out at least every 3 years advanced testing by means of TLPT. A competent authority may request a reduced or increased frequency where necessary.
Production systems are in scope
Each threat-led penetration test shall cover several or all critical or important functions and shall be performed on the live production systems supporting those functions.
Scope requires validation
The entity identifies relevant ICT systems, processes, technologies, and services, including outsourced support. Its assessment determines the precise TLPT scope and competent authorities validate it.
7. Article 26(3)-(7): Third parties, pooled testing, and closure
Outsourcing does not shift responsibility
If an ICT third-party provider is in scope, Article 26(3) requires safeguards for its participation. The financial entity retains full responsibility at all times for compliance with DORA.
Pooled TLPT is conditional
Article 26(4) permits written pooled-testing arrangements only where direct provider participation is reasonably expected to harm specified service quality, security, or data confidentiality interests.
Manage live-test risk
Article 26(5) requires effective risk-management controls to mitigate possible impact on data, assets, and critical or important functions, services, or operations.
Evidence, attestation, notification
After agreed reports and remediation plans, findings and evidence go to the designated authority. Authorities issue an attestation, and the financial entity notifies its competent authority.
8. Article 26(8)-(11): Selection, tester rotation, and authorities
Rotation protects independence
Where internal testers are used for TLPT, Article 26(8) requires external testers every three tests. Significant credit institutions shall use only external testers meeting Article 27(1)(a)-(e).
Selection factors
Competent authorities identify required TLPT entities using impact on the financial sector, financial-stability concerns and systemic character, plus ICT risk profile, maturity, and technology features.
National arrangements
Member States may designate one authority for national TLPT matters. If they do not, a competent authority may delegate some or all relevant tasks to another national financial-sector authority.
RTS status
The Article 26(11) draft-RTS deadline was July 17, 2024. Delegated Regulation (EU) 2025/1190 now supplements these TLPT matters and has been in force since July 8, 2025.
9. Article 27: Who may perform TLPT?
Baseline tester requirements
Article 27(1) permits only testers with suitability, reputation, technical and organisational capability, relevant expertise, certification or ethical-framework adherence, assurance, and indemnity insurance.
Internal testers face extra conditions
Article 27(2) requires authority approval, verified dedicated resources and conflict avoidance, plus a threat-intelligence provider external to the financial entity.
Data handling is part of the contract
External-tester contracts must require sound management of results. Processing activities from generation through destruction must not create risks to the financial entity.
10. Flashcards: Recall the operative rules
Flip each card, then explain the rule aloud in your own words without removing its conditions.
- Article 24(1): What must relevant entities establish?
- They shall, other than microenterprises and taking Article 4(2) criteria into account, establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the Article 6 ICT risk-management framework.
- Article 24(6): What is the annual minimum?
- At least yearly, appropriate tests must be conducted on all ICT systems and applications supporting critical or important functions. The rule applies to financial entities other than microenterprises.
- Article 26(1): How often is TLPT required?
- Identified financial entities within the provision's scope shall carry out at least every 3 years advanced testing by means of TLPT. The competent authority may request a reduced or increased frequency where necessary.
- Article 26(2): Where is TLPT performed?
- On live production systems supporting the several or all critical or important functions covered by the threat-led penetration test.
- Article 26(8): What is the internal-tester rotation rule?
- When financial entities use internal testers for TLPT, they shall contract external testers every three tests.
- Article 27(2)(c): What is required for internal-tester use?
- The threat-intelligence provider is external to the financial entity, in addition to the Article 27(1) requirements and the other Article 27(2) conditions.
11. Knowledge check: TLPT scope
Select the statement that most accurately reflects Article 26(2).
Which statement is correct?
- Every TLPT must cover every ICT system owned by the financial entity, and it must be conducted only in a test environment.
- Each TLPT shall cover several or all critical or important functions and shall be performed on live production systems supporting those functions.
- A financial entity may set its TLPT scope without authority validation if an ICT third-party service provider is involved.
- TLPT must be performed annually by every financial entity, including every microenterprise.
Show Answer
Answer: B) Each TLPT shall cover several or all critical or important functions and shall be performed on live production systems supporting those functions.
Article 26(2) requires coverage of several or all critical or important functions and performance on live production systems supporting them. The entity assesses which functions need coverage, but competent authorities validate the precise scope. Article 26(1) does not impose annual TLPT on every entity or microenterprise.
Key Terms
- TLPT
- Threat-led penetration testing: the advanced testing referred to in Article 26. For selected entities within Article 26(1), it shall occur at least every 3 years.
- Pooled testing
- A written, conditional arrangement under Article 26(4) in which an ICT third-party service provider contracts directly with an external tester for a TLPT involving several financial entities.
- External tester
- A tester outside the financial entity who must meet Article 27(1) requirements. External testers are required every three tests when internal testers are used for TLPT.
- Internal tester
- A tester within the financial entity. Its use is subject to independence safeguards in Article 24(4), rotation in Article 26(8), and the additional conditions in Article 27(2).
- Competent authority
- The authority that, among other roles in this Chapter IV excerpt, identifies financial entities required to perform TLPT and validates the precise TLPT scope.
- Live production systems
- The systems supporting the critical or important functions covered by a TLPT; Article 26(2) requires the test to be performed on them.
- Critical or important functions
- Functions used in Articles 24 and 26 to define annual-test coverage and TLPT scope. This Chapter IV excerpt does not provide a separate definition.
- Digital operational resilience testing programme
- The Article 24(1) programme that relevant financial entities shall establish, maintain and review as an integral part of the Article 6 ICT risk-management framework.