EU

DORA: Digital Operational Resilience Testing

Digital Operational Resilience Testing [Art 24-27]

Rule: Financial entities must establish a testing program proportionate to their size and risk profile. Significant entities must conduct advanced threat-led penetration testing (TLPT).

General Testing Requirements [Art 24]

All financial entities must:

RequirementDetail
Establish testing programSound and comprehensive program
Risk-based approachConsider size, business, risk profile
Annual testingAt least annually for critical systems
Address vulnerabilitiesAssess and remediate identified weaknesses
Document resultsRecord findings and remediation
Report to managementSummary of testing activities and findings

Testing Methods [Art 25]

Basic testing program may include:

Test TypePurpose
Vulnerability assessmentsIdentify technical weaknesses
Gap analysesCompare against standards/policies
Physical security reviewsPremises and access controls
Questionnaire-based assessmentsSelf-assessment against frameworks
Source code reviewsWhere feasible
Scenario-based testingSimulate business disruption scenarios
Compatibility testingIntegration and interoperability
Performance testingLoad, stress, scalability
End-to-end testingFull process validation
Penetration testingWhere appropriate (see below)

Penetration Testing [Art 25(2)]

For critical systems and services:

  • Test at least every 3 years (unless TLPT required)
  • Conducted by qualified testers
  • Proper scoping and risk management
  • Findings remediated appropriately

Threat-Led Penetration Testing (TLPT) [Art 26]

Who must conduct TLPT:

  • Significant financial entities identified by competent authorities
  • Based on systemic importance and risk profile
  • At least every 3 years

What is TLPT:

  • Real-world threat intelligence-led testing
  • Simulates tactics, techniques, procedures of actual threat actors
  • Tests live production systems (where feasible)
  • Based on TIBER-EU framework

TLPT Requirements [Art 26(3)-(8)]

RequirementDetail
ScopeAll critical/important functions and supporting ICT services
Live systemsPerformed on live production systems
Threat intelligenceRealistic scenarios from threat intelligence
Testing phasesPreparation, testing, closure, and remediation
Qualified testersExternal or internal with specific requirements
Remediation planAddress all identified vulnerabilities
ReportingSummarized report to competent authority

TLPT Tester Requirements [Art 26(9)]

Testers must:

  • Have highest professional suitability and reputation
  • Possess technical and organizational capabilities
  • Be certified by accreditation body OR adhere to formal codes of conduct
  • Provide independent assurance on proper risk management
  • Hold professional indemnity insurance

Internal testers allowed if:

  • Approved by competent authority
  • Resources are dedicated (no conflict of interest)
  • Threat intelligence is external

Pooled Testing [Art 26(4)]

For ICT services supporting multiple financial entities:

  • Testing can be pooled
  • Results shared among participating entities
  • Coordinated by designated financial entity

Use of ICT Third-Party Providers in TLPT [Art 26(5)]

Where TLPT covers third-party services:

  • Financial entity and ICT provider coordinate
  • Provider must allow testing or provide equivalent assurance
  • Contractual arrangements must facilitate

Testing Results Management

StageActions
Pre-testScope definition, risk management, stakeholder approval
During testControl measures, monitoring, escalation paths
Post-testFindings documentation, risk assessment
RemediationAction plan, implementation, validation
ReportingManagement and competent authority reporting

Exemptions from TLPT

Entity TypeTLPT Status
Significant (designated by authority)Mandatory every 3 years
Non-significantNot required (unless voluntarily adopted)
Simplified framework entitiesNot required

Comparison: Basic Testing vs TLPT

AspectBasic TestingTLPT
FrequencyAnnualEvery 3 years
ScopeRisk-basedAll critical functions
MethodVarious test typesThreat intelligence-led
SystemsMay be non-productionLive production
TestersInternal/externalQualified specialists
ReportingInternalTo competent authority

Citation

Art 24-27, Regulation (EU) 2022/2554

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt