Quote in 48 hours
Scope your DORA pentest
TLPT scoped to TIBER-EU. Quote in 24 hours.
The EU Digital Operational Resilience Act (DORA) entered into force on 17 January 2025, bringing mandatory penetration testing requirements to approximately 22,000 financial entities across the European Union. If your company is a bank, fintech, payment service provider, crypto-asset service provider (CASP), insurance firm, or investment platform operating in the EU, you are now legally required to test your ICT systems at least once per year.
This post explains exactly what DORA requires, who it applies to, how the two tiers of testing obligations differ, and what a practical compliance approach looks like for financial entities that are not sitting on enterprise security budgets.
What is DORA and why does it require penetration testing?
DORA (EU Regulation 2022/2554) is a harmonized EU regulatory framework designed to ensure that financial entities can withstand, respond to, and recover from ICT-related disruptions, including cyberattacks. It applies across 20-plus categories of financial entities and represents the first time the EU has mandated a unified set of digital resilience requirements across the entire financial sector.
DORA penetration testing requirements sit inside the regulation's broader ICT risk management and testing framework. The regulation's core premise is that financial entities cannot simply assume their systems are secure. They have to actively prove it, on a recurring basis, and document the results in a way that satisfies their national competent authority.
The two core testing obligations are set out in Articles 25 and 26.
DORA Article 25: annual penetration testing requirements for all entities
Article 25 is the baseline. It applies to every covered financial entity regardless of size or systemic importance.
The requirement: financial entities must test ICT systems and applications supporting critical or important functions at least once per year. Testing methods must be appropriate to the risk profile of the system being tested. The testing must be conducted independently, either by internal teams with sufficient separation of duties or by qualified external providers.
This is not a checkbox exercise. The regulation explicitly expects testing to be followed by remediation, with documentation that demonstrates findings were addressed. The idea behind Article 25 is that security testing should inform your risk posture on an ongoing basis, not just produce a report that sits in a folder until the next audit.
For most fintechs and growth-stage financial platforms, the Article 25 DORA penetration testing obligation is the relevant baseline. It is achievable with the right provider and a realistic budget, but it requires planning to execute well.
What ICT systems fall under DORA Article 25 penetration testing?
Any ICT system or application supporting a "critical or important function" is in scope. DORA defines critical or important functions as those where a disruption would materially impair financial performance, the soundness of governance, or the continuity of financial services. In practice, this covers most core-platform systems: customer-facing applications, payment processing infrastructure, data handling systems, cloud environments, and key third-party integrations.
DORA Article 26: threat-led penetration testing (TLPT) for systemically important entities
Article 26 introduces a materially more demanding obligation that applies only to financial entities identified by their national competent authority as systemically important. Not every DORA-covered entity will be subject to TLPT, but if you are a larger bank, major payment infrastructure provider, or a platform with significant systemic exposure, you need to understand what is coming.
TLPT requirements at a glance
The TLPT requirement in plain terms:
- Frequency: At least once every three years. Regulators may increase or decrease this based on the entity's risk profile.
- Scope: TLPT covers the entire organization, not a scoped subset of systems. All critical and important functions are included, along with third-party ICT providers that contribute to those functions.
- Testing environment: TLPT must be performed on live production systems. This is a significant departure from standard pentesting norms where test environments are often used to limit blast radius.
- Duration: The full TLPT engagement typically runs 6 to 12 months from initiation to completion. The active red team phase must be at least 12 weeks.
- External testers: Every third TLPT engagement must involve an external red team provider. This means roughly once every nine years in practice, but many institutions will use external testers more frequently.
- Framework alignment: TLPT under DORA is modeled on the TIBER-EU framework developed by the European Central Bank. Entities already familiar with TIBER-EU will recognize the structure.
TLPT is not something most fintechs will need to worry about immediately. The entities selected for TLPT tend to be large, systemically important institutions. But the first TLPT notifications for relevant entities are expected in 2026, with active tests running through 2026 and 2027. If you think you may be in scope, now is the time to start building the security posture that TLPT will expose.
Beyond the DORA minimum: continuous penetration testing for compliance
DORA sets floors, not ceilings. The annual Article 25 minimum is a regulatory baseline, not a security strategy.
The regulation's underlying philosophy is continuous improvement. It expects entities to understand where they are exposed, fix what they find, and prove the fixes have taken effect. A single annual pentest satisfies the letter of Article 25, but a financial entity with significant ICT risk that only tests once per year is not demonstrating the kind of ongoing diligence that regulators will find credible when incidents occur.
Many EU financial entities are already moving toward quarterly testing cadences for their most critical systems. This means running a lighter, faster test after each major release cycle or infrastructure change, and reserving the deeper annual engagement for full-scope coverage and compliance documentation.
This is where AI-assisted penetration testing starts to make practical sense. A traditional pentest costs $15,000 to $25,000 and takes weeks to initiate. At that price and speed, quarterly testing is not realistic for most fintechs. AI-assisted pentests that deliver results in 48 hours at a fraction of the cost make it feasible to maintain a genuinely continuous testing posture without an enterprise security budget.
What continuous DORA penetration testing looks like in practice
Continuous penetration testing does not mean a human tester is running 24 hours a day. It means structuring your testing program so that your security posture is assessed regularly, findings are remediated, and your compliance documentation reflects current risk rather than risk from 11 months ago.
A layered model for continuous DORA Article 25 compliance
A practical model for DORA Article 25 compliance:
- Always-on surface monitoring: Automated scanning of your external attack surface to catch new exposures as they emerge, not weeks after they are introduced.
- On-demand targeted tests: Lightweight AI-assisted penetration tests triggered by meaningful changes, including major feature releases, infrastructure migrations, cloud configuration changes, or new third-party integrations.
- Annual full-scope engagement: A deeper hybrid or manual pentest covering all critical and important functions in scope for your Article 25 obligation, with full audit-ready documentation for your compliance team and national competent authority.
- Remediation tracking: Documented evidence that findings from each engagement were triaged, assigned, and resolved within a defined timeframe.
The combination of Article 25's annual requirement and the spirit of ongoing diligence that DORA expects pushes naturally toward this kind of layered program. The AI layer handles the speed and frequency; the human layer handles the depth and regulatory credibility of the documentation.
Who does DORA penetration testing apply to?
EU financial entities in scope for DORA penetration testing
The breadth of DORA's coverage is wider than many organizations realize. The regulation applies to all of the following operating within the EU:
- Credit institutions (banks)
- Payment institutions and electronic money institutions
- Investment firms
- Insurance and reinsurance undertakings
- Crypto-asset service providers (CASPs) operating under MiCA
- Crowdfunding service providers
- Account information service providers
- Central counterparties and trading venues
- Credit rating agencies
- Data reporting services
- ICT third-party service providers serving any of the above
US-based companies with EU operations, EU customers, or EU-regulated subsidiary entities are also in scope if they provide financial services in the EU. The regulation does not offer a geographic safe harbor based on where a company is incorporated.
Fintechs that secured MiCA authorization as CASPs came into full DORA scope when MiCA went live. If you are operating a crypto exchange, custody platform, or token issuance service serving EU customers, you are a DORA-covered entity.
What a DORA-compliant penetration test report needs to include
The regulation does not prescribe a specific report template, but it does require documentation that demonstrates the testing was meaningful, the findings were addressed, and the entity has a clear view of its ICT risk. A DORA-aligned pentest report should include:
- Scope documentation: A clear description of the ICT systems and functions tested, aligned to your critical and important function inventory.
- Methodology description: Documentation of the testing approach that demonstrates independence and risk-appropriateness.
- Findings with CVSS scoring: Each finding should include severity rating, reproduction steps, and business impact context.
- Remediation guidance: Specific, actionable recommendations for each finding, not generic advice.
- Evidence of retesting: For any findings remediated during the engagement, documentation that fixes were verified.
- Executive summary: A board-ready summary that maps findings to operational risk, not just technical severity.
This documentation serves two audiences: your technical team who needs to fix things, and your national competent authority who needs to see that you are managing ICT risk actively and not just filing paperwork.
How AI-assisted penetration testing supports DORA compliance
A common misconception is that AI-assisted penetration testing is just an automated vulnerability scan with a more expensive name. It is not.
At StealthNet AI, AI agents perform autonomous exploitation across web applications, APIs, external network perimeters, and cloud infrastructure. But every finding is then reviewed and validated by a senior OSCP-certified penetration tester before it enters the report. You get the speed of AI (48-hour delivery versus weeks) with the accuracy and judgment of a human tester who knows the difference between a theoretical vulnerability and an exploitable finding.
For DORA Article 25, the key requirements are independence, risk-appropriateness, and audit-ready documentation. An AI-assisted pentest delivered by StealthNet satisfies all three. The AI handles coverage breadth and speed. The human tester handles depth, accuracy, and the kind of business logic testing that automated tools miss. The report is structured for compliance teams, not just developers.
For entities preparing for TLPT under Article 26, a well-structured AI-assisted program in the lead-up to the formal TLPT cycle helps identify and remediate critical findings before a red team is running against live production systems. That prep work materially reduces risk during the engagement and improves outcomes.
DORA penetration testing timeline: where EU financial entities stand in 2026
- January 2025: DORA entered into full force. All covered entities became subject to its requirements, including Article 25 annual testing obligations.
- July 2025: Commission Delegated Regulation (EU) 2025/1190 became enforceable, providing the technical standards for TLPT scope and methodology under Article 26.
- Late 2025 to early 2026: National competent authorities began issuing TLPT selection notifications to systemically important entities.
- 2026 to 2027: First wave of TLPT engagements underway across major EU financial institutions. Article 25 annual testing obligations are now fully in their first full 12-month cycle.
- 2027 and beyond: Ongoing enforcement. Entities that cannot demonstrate a functioning Article 25 testing program face supervisory scrutiny.
The Article 25 obligation is not theoretical. It is in effect now. If your organization has not completed an annual ICT penetration test in 2025 or 2026, you are behind.
DORA penetration testing at a glance
| Requirement | Article 25 | Article 26 (TLPT) |
|---|---|---|
| Who it applies to | All 22,000 covered entities | Selected systemically important entities only |
| Frequency | At least once per year | At least once every three years |
| Scope | Critical and important functions | Entire organization, including third parties |
| Environment | Test or production | Live production systems only |
| Duration | Flexible | 6 to 12 months total, 12-week minimum active phase |
| When to use StealthNet | Article 25 annual testing and pre-TLPT prep | Pre-TLPT hardening and remediation |
Ready to meet your DORA Article 25 penetration testing obligation?
StealthNet AI delivers AI-assisted and hybrid penetration tests purpose-built for DORA Article 25 compliance. Human-validated findings, audit-ready reports, and 48-hour delivery. AI-only engagements start at $1,500 and hybrid engagements start from $5,000.
Get a DORA pentest quote or explore our broader compliance coverage including SOC 2 penetration testing, external network pentesting, and cloud security assessments.
Frequently Asked Questions
Does DORA require an annual penetration test?
Yes. DORA Article 25 requires all in-scope EU financial entities to perform appropriate ICT security testing, including penetration testing, at least annually on ICT systems and applications supporting critical or important functions. This applies to banks, payment service providers, crypto-asset service providers, insurance firms, investment firms, and many other financial entities regulated in the EU.
What is the difference between DORA Article 25 and Article 26 (TLPT)?
Article 25 covers annual ICT security testing for all financial entities, including vulnerability assessments, scenario-based tests, and penetration testing of critical systems. Article 26 introduces Threat-Led Penetration Testing (TLPT) and only applies to significant financial entities designated by their competent authority. TLPT follows the TIBER-EU framework, runs every three years, and requires red team engagements against production systems. Most firms only need to satisfy Article 25.
Who needs to comply with DORA?
DORA applies to over 22,000 financial entities operating in the EU, including credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers (CASPs) under MiCA, insurance and reinsurance undertakings, central securities depositories, trading venues, credit rating agencies, and critical ICT third-party service providers serving the financial sector.
What does a DORA-compliant penetration test report need to include?
A DORA Article 25 pentest report should include: scope and methodology aligned to OWASP, NIST SP 800-115, or PTES; an executive summary mapped to ICT risk categories; detailed findings with CVSS scoring and business impact; reproduction steps and evidence; remediation guidance; and a retest attestation once fixes are deployed. The report must be retained as evidence for regulators and shared with the management body as part of the ICT risk management framework.
How often does DORA require penetration testing?
Article 25 requires penetration testing at least annually on critical and important ICT systems, plus after any major change to the ICT environment. Vulnerability assessments are required more frequently. TLPT under Article 26 runs on a three-year cycle for designated significant entities.
Can AI-assisted penetration testing satisfy DORA Article 25?
Yes, when human-validated. DORA does not prescribe a specific testing method, only that testing be risk-based, proportionate, and performed by independent testers with the appropriate expertise. AI-assisted pentests with senior human validation meet these requirements, deliver faster turnaround (48 hours for AI-only, longer for hybrid), and produce the audit-ready evidence regulators expect.
What are the penalties for DORA non-compliance?
Competent authorities can impose administrative fines, public censure, and orders to cease infringing conduct. For critical ICT third-party providers, fines can reach up to 1 percent of average daily worldwide turnover. Senior management can be held personally accountable for ICT risk management failures, and significant incidents must be reported to the relevant authority within strict timelines.
When did DORA come into force?
DORA entered into application on 17 January 2025. EU financial entities and their ICT third-party providers have been required to comply since that date, with supervisory authorities now actively reviewing ICT risk management, testing, and third-party oversight programs.