DORA Penetration Testing Requirements: A Practical Checklist for Financial Firms

by Rebecca Sutton

DORA’s penetration testing requirements are not one rule but two, and mixing them up is the fastest way to over-spend or under-prepare. Every financial entity DORA covers must run a general resilience testing programme every year. A much smaller group, those a regulator formally designates as significant, must also run threat-led penetration testing (TLPT) every three years. This guide sets out what each tier actually involves and how to prepare, whether or not you expect to be designated.

Analyst reviewing financial testing data on a laptop while checking DORA penetration testing requirements

DORA penetration testing requirements: which tier applies to you?

DORA, Regulation (EU) 2022/2554, has applied across the EU since 17 January 2025. It covers a long list of financial entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, pension funds, credit rating agencies and more. It also reaches the ICT third parties that keep them running. PwC estimates it reaches over 22,000 financial entities and technology suppliers.

Nearly all of them need the baseline programme. Only a subset need TLPT. Work out which group you’re in before you plan anything else.

Tier one: the annual baseline programme (Articles 24-25)

Every DORA-covered entity runs this, scaled to its own size and risk. It is a mix of methods, not a single test:

  • Vulnerability assessments and scans
  • Network security assessments
  • Gap analyses against DORA’s ICT risk requirements
  • Source code reviews, where practical
  • Scenario-based testing
  • Penetration testing

This runs at least once a year. For most small and mid-sized DORA-covered firms, this is the whole obligation. It should look similar in shape to a well-run existing security testing calendar, just mapped explicitly against DORA’s requirements so you can show a regulator what was tested and when.

Tier two: threat-led penetration testing (Articles 26-27)

TLPT is a different animal. It is an intelligence-led red team exercise, run on live production systems. Testers build it around real threat intelligence about the specific tactics a sophisticated attacker, a nation-state group, an organised financial cybercrime outfit, or a serious insider threat, would use against your firm. That is deliberately more realistic, and more disruptive, than a standard scoped penetration test.

It is also not universal. Article 26(8) leaves it to competent authorities to designate which entities must run TLPT. They weigh up the firm’s impact on financial stability, any systemic risk it poses, and its ICT risk profile and maturity. A joint technical standard from the EBA, ESMA and EIOPA, finalised in 2024, spells out how that designation process works. In practice this targets larger, systemically significant players rather than every firm DORA touches.

Where TLPT does apply, here is the checklist that matters:

  1. Frequency: at least once every three years, adjustable by the regulator based on risk.
  2. Scope: several or all “critical or important functions,” including systems run by outsourced ICT and cloud providers.
  3. Testers: independent of the firm being tested; external testers required at least every third test (every test, for significant credit institutions).
  4. Methodology: aligned with TIBER-EU, so existing TIBER experience carries across.
  5. Reporting: a summary of findings and a remediation plan goes to your supervising authority once testing wraps up.
  6. Recognition: authorities can attest compliance so firms operating in multiple EU states are not forced to repeat the exercise for each regulator.

Does this apply if you’re a UK business?

Only if you have EU exposure. DORA is EU law, and a UK firm regulated solely by the FCA or PRA, with no EU footprint, is not automatically caught. What brings a UK firm in is EU activity: an EU-authorised subsidiary or branch, or providing ICT services, including cloud and software, to EU-regulated financial entities. Scope follows the specific entity carrying out that activity, not the parent group as a whole, so part of a UK business can be in scope while the rest is not.

If none of that applies to you, you are not exempt from operational resilience obligations altogether. You sit under the FCA and PRA’s own regime instead, principally PS21/3, in force since 31 March 2022. It required firms to finish mapping and scenario testing by 31 March 2025, so they could stay within agreed impact tolerances for each important business service. It covers banks, building societies, insurers, PRA-designated investment firms, recognised investment exchanges, enhanced-scope SM&CR firms, and payment and e-money institutions.

Don’t assume the two are interchangeable. PwC’s view is that DORA is notably more prescriptive on ICT and cyber testing specifically than the UK’s existing framework. The UK regime is built around mapping business services and impact tolerances, not mandating threat-led red team exercises. Being PS21/3-compliant does not automatically mean you satisfy DORA if EU activity brings you into scope.

A practical preparation checklist

  • Map your critical and important business functions, and the ICT systems, including cloud and outsourced providers, that support them.
  • Check whether your current testing programme already covers what Articles 24-25 expect, and document it that way.
  • If TLPT designation is even a possibility, start scoping conversations with an accredited, independent external tester well before any deadline. A genuine threat-led exercise on live systems takes months to plan properly, and third-party providers usually need to be brought into scope too.
  • Keep records of remediation from every test. Authorities expect to see findings closed out, not just tests completed.
  • Review this annually. Designation criteria and your own risk profile can both change year to year.

Meeting DORA penetration testing requirements starts with a current, well-run testing programme that both tiers can build on. It is a far shorter step from regular testing to full DORA compliance than from a standing start. If you already know your critical functions but aren’t sure your current testing maps cleanly onto DORA’s two tiers, a scoped penetration test can usually clarify that in a single engagement. Get in touch if you’d like to talk through where your firm sits before a regulator asks.

Frequently asked questions

Do we need a penetration test every year under DORA?

Some form of testing under the general programme (Articles 24-25) is expected annually for essentially all DORA-covered entities. A full threat-led penetration test (TLPT) is only required every three years, and only for firms designated by their regulator.

Who decides if we need TLPT?

Your competent authority, based on your firm’s impact on financial stability, systemic risk, and ICT risk profile and maturity, following the joint technical standard published by the EBA, ESMA and EIOPA.

Can our internal security team run the TLPT?

Not alone. Designated firms must bring in independent external testers at least every third test, and significant credit institutions must use external testers every time.

We’re a UK-only firm. Does DORA still apply?

Only if you have an EU-regulated subsidiary or branch, or supply ICT services to EU financial entities. Otherwise you fall under the FCA/PRA’s own operational resilience rules (PS21/3), which is a related but distinct regime.

What’s the single most useful thing to do first?

Map your critical business functions against the ICT systems, including third parties, behind them. That map is the starting point for both tiers of testing and for any conversation with a regulator.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like