5 October 2026 · 10 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)
DORA Penetration Testing and Threat-Led Penetration Testing (TLPT): What Articles 24 to 27 Require
The Digital Operational Resilience Act has applied to EU financial entities since 17 January 2025. It is the first EU law that names penetration testing and threat-led testing as explicit obligations. Here is what that means for your testing programme.
What DORA is and who it covers
DORA is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. As a regulation it applies directly in every member state, without national transposition, and it has applied since 17 January 2025. It covers banks, payment and e-money institutions, investment firms, crypto-asset service providers, insurers and reinsurers, pension funds, trading venues, central counterparties, fund managers and the critical ICT third-party providers that serve them. In the Netherlands, supervision sits with De Nederlandsche Bank (DNB) and the Autoriteit Financiële Markten (AFM).
DORA is built on five pillars: ICT risk management, ICT incident reporting, digital operational resilience testing, ICT third-party risk, and information sharing. Chapter IV, Articles 24 to 27, is the testing pillar, and it is where penetration testing becomes a legal obligation rather than an audit expectation.
Articles 24 to 27: the testing obligations
Four articles set the programme, the basic tests, the advanced tests and who may perform them.
Article 24: a digital operational resilience testing programme
Every financial entity (except microenterprises, which get a lighter regime) must establish, maintain and review a testing programme as part of its ICT risk-management framework. The programme follows a risk-based approach, uses independent internal or external testers, and tests all ICT systems and applications supporting critical or important functions at least once a year.
Article 25: testing of ICT tools and systems
Article 25 lists the tests the programme should include: vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing. This is the article that puts penetration testing in EU law.
Article 26: advanced testing via threat-led penetration testing (TLPT)
Financial entities identified by their competent authority must carry out TLPT at least every three years. TLPT covers several or all critical or important functions, is performed on live production systems, and includes the ICT third-party providers that support those functions. The regulatory technical standards on TLPT align the method with the TIBER-EU framework; in the Netherlands that is run as TIBER-NL under DNB.
Article 27: requirements for testers
TLPT testers must be of the highest suitability and reputability, possess technical and organisational capabilities and expertise in threat intelligence, penetration testing and red-team testing, be certified by an accreditation body or adhere to formal codes of conduct, provide independent assurance or audit reports on their risk management, and be covered by professional indemnity insurance. Internal testers are allowed under conditions, but the threat-intelligence provider must always be external.
Annual penetration testing versus TLPT
DORA asks for both, from different populations and on different cycles. They are not interchangeable.
| Aspect | Penetration testing (Art. 24-25) | TLPT (Art. 26-27) |
|---|---|---|
| Who must do it | All financial entities in scope, except microenterprises | Entities designated by their competent authority (significant, systemic) |
| Cadence | At least annually for systems supporting critical or important functions | At least every three years, authority may adjust |
| Environment | Production or representative test environment, per risk | Live production systems |
| Method | Scoped, control-focused, vulnerability and exploit driven | Intelligence-led red team against critical functions, TIBER-EU aligned |
| Testers | Independent internal or external testers | Article 27 requirements; threat intelligence always external |
| Output | Findings, remediation, retest | Attestation from the authority plus remediation plan |
What supervisors and auditors expect to see
DNB and AFM review the testing pillar through your ICT risk-management framework. Have these ready.
- A written testing programme (Art. 24) that maps every critical or important function to the ICT systems that support it and to a test type and frequency
- Evidence that each such system was tested in the last 12 months, with penetration testing for internet-facing and high-impact systems
- Tester independence: who tested, their qualifications, and their separation from the teams that run the systems
- A prioritisation and remediation process for findings, with ownership, deadlines and retest evidence
- Coverage of ICT third-party providers that support critical functions, through your own tests, their test reports, or contractual testing rights
- For designated entities: TLPT scoping, authority engagement, and the three-year schedule
How DORA testing fits with NIS2, ISO 27001 and your existing cycle
Most financial entities already run an annual penetration test for ISO 27001 or an internal audit cycle. DORA does not require a separate test; it requires that the programme is risk-based, covers every system behind a critical or important function, and is documented in the ICT risk-management framework. Banks and insurers that are also NIS2 entities can use one testing programme for both, provided the scope statement names the DORA functions explicitly.
Where DORA changes the picture is TLPT. A standard penetration test does not satisfy Article 26. Designated entities need a TIBER-aligned engagement with a separate threat-intelligence phase, a red-team phase on production, and a closure phase with the supervisor. Plan it 9 to 12 months ahead; the scoping and authority coordination take longer than the testing itself.
How we support DORA testing
For the annual programme we scope penetration tests to your critical or important functions, test the supporting systems internally and externally, include the relevant third-party interfaces, and deliver a report that cites Articles 24 and 25 per finding so your compliance team can file it without rework. For designated entities we provide the red-team component of TLPT alongside an external threat-intelligence provider, under the TIBER-EU process.
Our testers are OSCP-certified and named in every report, with professional indemnity cover and documented methodology, which addresses the Article 27 tester requirements your supervisor will ask about.
Frequently asked questions
Building your DORA testing programme?
From the annual penetration tests behind Articles 24 and 25 to the red-team component of TLPT, we test to the article and report to the supervisor's expectations. Talk to an expert.