Skip to main content
    EU Digital Operational Resilience Act

    DORA Penetration Testing Requirements: Stay Compliant, Stay Audit-Ready.

    DORA (EU Regulation 2022/2554) requires all financial entities operating in the EU to conduct ICT penetration testing of critical systems at least once per year under Article 25. StealthNet AI delivers AI-assisted pentests from $1,500 and hybrid AI plus human engagements from $5,000, with human-validated findings and audit-ready reports in 48 hours.

    48-Hour Reports Article 25 Aligned OSCP-Certified Testers AI + Human Hybrid
    DORA Article 25DORA Article 26 (TLPT Prep)ICT Risk TestingEU Financial Entities

    Get a DORA Pentest Quote

    Tell us about your entity type and ICT scope. We'll respond with a scoped quote within one business day.

    Fixed-fee quote in 24 hours. No credit card. No sales pitch.

    Your details stay private. NDA available on request.

    No commitment. We'll follow up within 1 business day.

    Trusted by Companies Where Security Isn't Optional

    Phish Firewall logo
    Newo AI logo
    TopLeft logo
    Derma Monitor logo
    Avara Software logo
    High Point Networks logo
    Phish Firewall logo
    Newo AI logo
    TopLeft logo
    Derma Monitor logo
    Avara Software logo
    High Point Networks logo

    What customers say

    Highly recommend StealthNet AI

    "StealthNet AI performed a thorough and comprehensive pen test, fast turnaround on conducting the test, they were very responsive, and it was great value."
    RB

    Richard B.

    Founder · Avara Software · Health, Wellness & Fitness

    The best choice for penetration testing

    "The testing was thorough and the reports were structured precisely for the regulatory requirements. Explanation of issues along with steps to reproduce and remediation advice were detailed and clear, making corrections a breeze."
    JM

    Jeremy M.

    Director · IKO Corp · Medical Devices

    Regulatory Context

    What DORA Actually Requires for Penetration Testing

    The Digital Operational Resilience Act entered into force on 17 January 2025 and applies to approximately 22,000 financial entities across the EU, including banks, insurance companies, investment firms, payment service providers, crypto-asset service providers, and fintech platforms. All covered entities must meet two tiers of penetration testing obligations.

    All Financial Entities

    Article 25: Annual ICT Penetration Testing

    Every financial entity covered by DORA must test ICT systems and applications supporting critical or important functions at least once per year. Testing methods must be appropriate to the system's risk profile and must be independently conducted. This is the baseline requirement that applies to every covered entity regardless of size or systemic importance. StealthNet AI's AI-assisted and hybrid pentest bundles are purpose-built to satisfy this requirement at a cost and speed that works for fintechs and growth-stage financial platforms.

    Annual MinimumAll 22,000 Covered Entities
    Selected Entities

    Article 26: Threat-Led Penetration Testing (TLPT)

    Systemically important financial entities identified by their national competent authority must conduct Threat-Led Penetration Testing (TLPT) at least every three years. TLPT covers the entire organization, must be performed on live production systems, includes third-party ICT providers in scope, and involves an active red team phase of at least 12 weeks. The full engagement typically runs 6 to 12 months. StealthNet AI helps organizations prepare for TLPT by hardening their posture and resolving critical findings before the formal TLPT cycle begins.

    Every 3 YearsLive Production Systems
    The Compliance Gap

    Most Financial Entities Are Not Ready for DORA Testing Requirements

    Traditional Pentests Are Too Slow

    Legacy penetration testing firms take 4 to 8 weeks to scope, begin, and deliver results. DORA requires annual testing of ICT systems. A process that takes 2 months to kick off cannot realistically support a continuous compliance posture across all critical functions.

    Enterprise Pricing Doesn't Fit Fintechs

    Traditional pentest engagements start at $15,000 to $25,000 per test. For a Series A fintech or crypto-asset service provider that needs to test multiple systems annually, this cost model is unsustainable. DORA compliance should not require an enterprise security budget.

    Reports Aren't Built for Regulators

    Most pentest reports are written for developers, not compliance teams or national competent authorities. DORA requires testing to be documented in a way that demonstrates risk coverage and methodology alignment. StealthNet reports are structured for audit-readiness from the first page.

    How It Works

    From Scoping to DORA-Ready Report in 48 Hours

    01

    Scope Your ICT Systems

    Tell us which systems, applications, and functions are in scope for your DORA Article 25 obligation. We align the engagement to your risk profile and document the scope for your compliance record.

    02

    AI Agents Execute Testing

    Our AI agents perform autonomous exploitation across your web applications, APIs, external network perimeter, and cloud infrastructure. Coverage is aligned to DORA's ICT testing requirements.

    03

    Human Tester Validates Findings

    Every finding is reviewed and validated by a senior OSCP-certified penetration tester before it enters the report. You get AI speed with human-grade accuracy, not a glorified vulnerability scan.

    04

    Audit-Ready Report Delivered

    You receive a structured pentest report with executive summary, CVSS-scored findings, reproduction steps, remediation guidance, and a methodology section demonstrating DORA Article 25 alignment for your compliance team and auditors.

    Coverage

    ICT Systems and Functions Covered Under DORA Article 25

    Web Applications and APIs

    Testing of customer-facing and internal web applications, REST and GraphQL APIs, authentication systems, and business logic flows. Covers OWASP Top 10 and API Security Top 10.

    External Network Perimeter

    Enumeration and exploitation of internet-facing infrastructure, including exposed services, open ports, misconfigured firewalls, and CVE-matched vulnerabilities across your external attack surface.

    Cloud Infrastructure

    Assessment of AWS, Azure, and GCP environments for IAM misconfigurations, excessive permissions, exposed storage, insecure credentials, and privilege escalation paths.

    Internal Network and Active Directory

    Simulation of lateral movement, insider threat scenarios, and privilege escalation including Active Directory misconfigurations, Kerberoasting, and path-to-domain-admin analysis.

    Source Code and SDLC

    Security review of application source code for injection vulnerabilities, authentication bypasses, hardcoded secrets, and dependency risks. Aligned to DORA's requirements for SDLC security testing.

    Third-Party ICT Provider Interfaces

    Testing of integration points with third-party ICT providers, SaaS platforms, and data processors that fall within your DORA Article 25 scope, including API authentication and data handling controls.

    Pricing

    DORA Pentest Pricing Built for Financial Entities, Not Just Enterprises

    One-off tests for your annual Article 25 obligation. Quarterly bundles for continuous compliance posture.

    AI-Assisted Pentest

    $1,500

    • DORA Article 25 aligned methodology
    • Web app, API, and external perimeter coverage
    • Human-validated findings, not a vuln scan
    • Audit-ready compliance report
    • 48-hour delivery

    Best for: Smaller financial entities and fintechs satisfying the DORA Article 25 annual testing requirement

    Most Popular

    Hybrid (AI + Human) Pentest

    Starting at $5,000

    Typical engagements range from $5,000 to $10,000 depending on scope

    • Everything in AI-Assisted
    • Senior OSCP-certified tester engagement
    • Business logic and chained vulnerability testing
    • Third-party ICT interface coverage
    • Free remediation retest included
    • Compliance-mapped findings for your auditor

    Best for: Financial entities with complex ICT environments, multiple critical functions in scope, or third-party ICT provider dependencies

    Quarterly Compliance Bundle

    Custom

    Scheduled quarterly across the year

    • Quarterly test cadence for continuous compliance
    • Priority scheduling and account management
    • TLPT readiness prep included
    • Cumulative findings tracking across tests

    Best for: Financial entities managing multiple critical functions or preparing for TLPT readiness under Article 26

    Why StealthNet

    Enterprise Security. Fintech-Friendly Speed and Pricing.

    48hrs

    From scope confirmation to report delivery

    22,000

    Financial entities covered by DORA in the EU

    100%

    Findings validated by senior human testers

    OSCP

    Certified testers on every engagement

    Cost per test
    Traditional
    $15,000 to $25,000
    StealthNet
    AI: $1,500 / Hybrid: from $5,000
    Delivery
    Traditional
    4 to 8 weeks
    StealthNet
    48 hours
    DORA Article 25 alignment
    Traditional
    Manual mapping
    StealthNet
    Built into methodology
    Human validation
    Traditional
    Variable
    StealthNet
    Every finding, OSCP-certified
    Retest
    Traditional
    Extra charge
    StealthNet
    Free with hybrid
    Article Mapping

    How the Test Maps to DORA Articles 24 to 28

    DORA does not describe a penetration test in one place. These are the articles the engagement produces evidence for, and what your competent authority actually receives.

    Art. 24 General testing requirements
    What we test
    ICT tools and systems supporting in-scope functions, on a risk-based scope
    Evidence in your report
    Documented scope, methodology, and risk-based rationale
    Art. 25 Testing of ICT tools and systems
    What we test
    Annual vulnerability assessment and penetration testing of critical ICT systems
    Evidence in your report
    Dated report with severity-rated findings, the core Article 25 artifact
    Art. 26 Threat-led penetration testing
    What we test
    TLPT readiness: whether your detection and response would survive a TIBER-EU style exercise
    Evidence in your report
    Readiness assessment and gap list ahead of a formal TLPT
    Art. 5 to 15 ICT risk management
    What we test
    Exploitable paths that your ICT risk register treats as theoretical
    Evidence in your report
    Validated risks in register format for your risk-management framework
    Art. 28 and 30 ICT third-party risk
    What we test
    Provider-hosted components inside critical functions, where contracts allow
    Evidence in your report
    Coverage statement naming what was tested and what contracts excluded
    Art. 11 Response and recovery
    What we test
    Whether attacker actions produced usable detection and logging
    Evidence in your report
    Detection-gap list showing which actions went unlogged

    Also working to another framework? The same engagement can carry ISO 27001 penetration testing and PCI DSS penetration testing mappings. See compliance penetration testing for how the overlap works.

    Compare

    Article 25 Penetration Testing vs. Article 26 TLPT

    Two different obligations that get conflated constantly. Most entities owe the first every year and the second only if designated.

    Who owes it
    Art. 25 Penetration Test
    All in-scope financial entities, for critical ICT systems
    Art. 26 TLPT
    Only entities designated by their competent authority
    Vulnerability Scan
    All entities, as part of the wider testing programme
    Frequency
    Art. 25 Penetration Test
    At least annually
    Art. 26 TLPT
    At least every three years
    Vulnerability Scan
    Continuous or periodic
    What it proves
    Art. 25 Penetration Test
    Exploitable weaknesses in critical systems, with severity and remediation
    Art. 26 TLPT
    Whether live detection and response withstand a threat-intel-led attack
    Vulnerability Scan
    Presence of known CVEs and misconfigurations
    Typical duration
    Art. 25 Penetration Test
    48 hours to 10 business days
    Art. 26 TLPT
    Three to twelve months, with a red team and control team
    Vulnerability Scan
    Hours
    StealthNet role
    Art. 25 Penetration Test
    Delivers the engagement end to end
    Art. 26 TLPT
    Prepares you: readiness assessment and remediation before the formal exercise
    Vulnerability Scan
    Included as continuous coverage between tests

    Already in force

    DORA has applied since 17 January 2025

    Regulation (EU) 2022/2554 entered into force in January 2023 and became applicable on 17 January 2025. National competent authorities now expect a running digital operational resilience testing programme, which means a current report rather than a plan to commission one.

    • Annual testing of every ICT system supporting a critical or important function.
    • A documented programme: scope, methodology, results, remediation, verification.
    • Third-party ICT components inside critical functions covered or explicitly excluded.
    • TLPT readiness if your authority designates you under Article 26.
    Related Services

    Pentest Services Included in Every Compliance Engagement

    Every compliance pentest pulls from these test-type services as needed. Scope is sized to your environment, not padded with hours.

    FAQ

    DORA Penetration Testing: Common Questions

    DORA Article 25 requires all covered financial entities to test ICT systems and applications supporting critical or important functions at least once per year. Testing must use methods appropriate to the system's risk profile and must be conducted independently. A separate obligation under DORA Article 26 requires selected systemically important entities to conduct Threat-Led Penetration Testing (TLPT) at least every three years on live production systems. StealthNet AI is designed to satisfy the Article 25 annual testing requirement for EU and UK financial entities.

    DORA applies to approximately 22,000 financial entities operating in the EU, including banks, investment firms, insurance companies, payment service providers, electronic money institutions, crypto-asset service providers (CASPs), crowdfunding platforms, account information service providers, and fintech platforms. ICT third-party service providers that serve these entities are also subject to DORA's oversight framework. If your company provides financial services in the EU or processes data for EU financial entities, you are likely in scope.

    Article 25 applies to all covered entities and requires annual ICT penetration testing of critical and important functions. It is a broad baseline obligation. Article 26 applies only to selected entities identified by their national competent authority based on systemic importance, and requires Threat-Led Penetration Testing (TLPT) at least every three years. TLPT is materially more complex: it covers the entire organization including third parties, must be performed on live production systems, and involves an active red team phase of at least 12 weeks. StealthNet AI addresses Article 25 directly and helps organizations build the security posture needed before entering a TLPT cycle.

    StealthNet AI's penetration testing engagements are designed to align with the ICT testing requirements under DORA Article 25. Our methodology covers critical and important functions as defined by your organization, uses independent testing methodology, and delivers audit-ready reports that document scope, findings, CVSS severity ratings, reproduction steps, and remediation guidance. We recommend confirming specific documentation requirements with your legal or compliance team and national competent authority, as DORA enforcement varies by jurisdiction.

    DORA sets a minimum of once per year for Article 25 ICT testing. However, many financial entities are moving toward quarterly or continuous testing for their most critical systems to maintain an accurate picture of their risk posture throughout the year, not just at the point of annual assessment. StealthNet AI's quarterly compliance bundles are designed for entities that want to stay ahead of the minimum requirement and build a demonstrable record of ongoing security diligence for their regulators.

    TLPT (Threat-Led Penetration Testing) is the advanced testing obligation under DORA Article 26 that applies to selected systemically important financial entities. A TLPT engagement covers the entire organization on live production systems, includes third-party ICT providers, and involves an active red team phase of at least 12 weeks over a 6 to 12 month total timeline. StealthNet AI does not replace a formal TLPT engagement, but we help organizations prepare for TLPT by identifying and remediating critical findings before the formal cycle begins, reducing risk and improving outcomes.

    Our AI agents perform autonomous exploitation across web applications, APIs, external network infrastructure, and cloud environments in a compressed timeframe that would take traditional firms several weeks. A senior OSCP-certified penetration tester then validates every finding before the report is generated. This means you receive speed without sacrificing the depth or human judgment that a compliance-grade report requires.

    Traditional DORA-aligned penetration tests run between $20,000 and $60,000. StealthNet AI pentests start at $1,500 and hybrid AI plus human engagements start at $5,000, with most Article 25 scopes covering critical ICT systems landing between $5,000 and $10,000 depending on the number of in-scope applications, APIs, and network ranges.

    Reports are structured as independent testing evidence: scope rationale, methodology, CVSS-rated findings with exploitation proof, mapping to the DORA Article 25 testing obligation, remediation guidance, and retest validation. Supervisors and internal audit functions consistently accept this format as evidence that testing was performed by independent, competent testers.

    Yes. The same engagement model covers UK entities working to FCA and PRA operational resilience expectations, and EU entities under DORA. If you operate across both, we scope one engagement and map findings to both sets of expectations rather than running two tests.

    Article 24 sets the general requirement to test ICT tools and systems. Article 25 names vulnerability assessments and penetration testing as part of the digital operational resilience testing programme, on at least an annual basis for critical ICT systems. Article 26 covers threat-led penetration testing (TLPT) for entities designated by their competent authority, at least every three years. Articles 5 to 15 on ICT risk management, and Article 28 on third-party risk, both consume the test output as supporting evidence.

    Article 25 requires annual testing of ICT systems and applications supporting critical or important functions. In practice that means anything whose failure would materially impair the continued provision of services: core banking and ledger systems, payment initiation and settlement, trading and order management, customer-facing platforms and mobile apps, the APIs behind them, identity providers, and the cloud tenancies hosting them. Your own critical-function mapping under Article 8 sets the boundary.

    Yes, indirectly. Article 28 makes you responsible for the ICT risk your providers introduce, and Article 30 requires contractual rights around testing and audit. Competent authorities expect you to evidence that provider-hosted components inside your critical functions are covered, either by your own testing where contracts allow, or by reviewing the provider's testing evidence. We scope provider-hosted components explicitly so the report shows what was covered and what was excluded by contract.

    Article 25 expects a documented testing programme, not just individual reports. That means a defined scope and methodology, the risk-based rationale for what was tested and what was not, results with severity ratings, a remediation plan with owners and target dates, and evidence that findings were closed and verified. Every StealthNet engagement delivers all six, including a retest section that closes the loop.

    DORA (Regulation (EU) 2022/2554) entered into force in January 2023 and has applied since 17 January 2025. Financial entities in scope are expected to have a running digital operational resilience testing programme now, with annual testing of critical ICT systems, so a current penetration test report is a live supervisory expectation rather than a future one.
    Get Started

    Get Your DORA Pentest Scoped This Week.

    Share your entity type, ICT scope, and timeline. We'll respond with a scoped quote within one business day. No commitment required.

    See a Sample Report

    No commitment required. Every engagement is scoped before a proposal is sent.