DORA has applied since 17 January 2025 to banks, insurers, investment firms and payment institutions — and, for the first time, to their critical ICT suppliers. As a regulation (directly applicable, not transposed), it leaves no room for national interpretation. The part firms underestimate most is not the testing, but the ICT third-party register: the complete mapping of suppliers, services and the contractual clauses required — an exercise that surfaces dependencies nobody had documented.
The five pillars
- ICT risk management
- ICT incident management and reporting
- Digital operational resilience testing
- ICT third-party risk management
- Information sharing
Testing (Art. 24–27)
All firms in scope have a baseline testing programme (vulnerability assessments, scans, scenario-based tests). The largest and most systemically important must conduct threat-led penetration testing (TLPT) — on the TIBER-EU model, at least once every three years, against live production systems, on critical functions, with strict requirements for testers (reputation, independence, professional liability insurance). We run the test and measure not just whether we got in, but whether your defenders saw us.
How we work and what you get
Gap analysis across the five pillars → third-party register and contractual clause review → testing programme design → for TLPT, a red team report plus detection assessment (blue team) and roadmap. You receive the DORA gap analysis, ICT third-party register review, testing programme and, where applicable, the TLPT report with the blue team assessment.