DORA penetration testing: general testing obligation vs Threat-Led Penetration Testing

DORA (Regulation (EU) 2022/2554), applicable since 17 January 2025, names penetration testing directly in Article 25 as part of a general testing programme required of most financial entities. A separate, heavier obligation - Threat-Led Penetration Testing (TLPT) under Articles 26-27 - applies only to entities identified by their competent authority, and a standard or AI-driven pentest does not satisfy it.

Does DORA require a penetration test?

Partly yes, and DORA is more explicit about it than SOC 2, ISO 27001, or NIS2. Article 25 lists penetration testing by name as one of the appropriate tests within the digital operational resilience testing programme that Article 24 requires nearly every financial entity to establish. So for the general testing obligation, the answer is a direct yes.

DORA has two separate testing obligations, not one. A vendor page that says "DORA requires a pentest" without distinguishing general testing from TLPT is describing only half the framework - and the half that most vendors cannot help with is the one that matters most for systemically important entities.

The second obligation, Threat-Led Penetration Testing under Articles 26-27, is a different and much more advanced exercise. It only applies to a subset of entities identified by their competent authority, and it is a human-led, intelligence-driven red-team engagement, not something an automated or AI-driven pentest can substitute for. Conflating the two is the most common inaccuracy in DORA marketing copy, and it is exactly the kind of overclaim that answer engines increasingly discount.

General testing vs Threat-Led Penetration Testing (TLPT)

Article 24 requires financial entities, other than microenterprises, to establish, maintain, and review a sound digital operational resilience testing programme as part of their ICT risk-management framework, with critical or important ICT systems tested at least annually. Article 25 sets out what that programme should include: vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, source code reviews where feasible, scenario-based tests, and penetration testing.

Articles 26-27 layer a second, narrower obligation on top for the entities identified as in scope: Threat-Led Penetration Testing, an advanced red-team exercise aligned to the TIBER-EU framework, run on live production systems using real threat intelligence about the entity, at least once every 3 years. The DORA TLPT regulatory technical standards make purple teaming a required phase, and testers must meet strict requirements under Article 27 - DORA permits internal testers only under conditions and requires the periodic use of external testers.

General testing (Art. 24-25)TLPT (Art. 26-27)
Applies toNearly all financial entities, except microenterprisesA subset identified by the competent authority
What it coversVulnerability assessments, scans, and penetration testing of ICT systemsIntelligence-led, human-run red-team exercise aligned to TIBER-EU
Minimum frequencyAt least annually for critical or important ICT systemsAt least every 3 years
Can an automated/AI test satisfy it?Yes, it directly supports this obligationNo

Who must run TLPT

Competent authorities identify which financial entities must run TLPT using the proportionality criteria in Article 4(2): the extent to which the entity's services and activities impact the financial sector, its potential financial stability significance (including systemic character at Union or national level), and its ICT risk profile and level of ICT maturity. Microenterprises and the simplified-regime entities referred to in Article 16(1) are excluded from TLPT by definition.

In practice, this scopes TLPT to the largest and most systemically important financial entities: significant credit institutions under direct ECB supervision, globally and other systemically important banks (G-SIBs and O-SIIs), significant insurers and reinsurers, systemically relevant trading venues and central counterparties, large payment and e-money institutions, and crypto-asset service providers above the relevant MiCA thresholds. Most small and mid-sized financial entities will never be required to run TLPT, but they still carry the Article 24-25 general testing obligation.

Where Intrudify fits (and where it does not)

Intrudify runs a full web and API pentest and produces a report that maps each finding to the relevant Article 24-25 testing requirements, with reproducible proof for high and critical findings and developer-ready remediation. That directly supports your general digital operational resilience testing programme.

Intrudify does not run, and does not substitute for, Threat-Led Penetration Testing. TLPT is a human-led, intelligence-driven red-team engagement performed under Article 27's tester requirements and the TIBER-EU methodology - scoped, threat-intelligence-fed, and (for most cycles) executed by an accredited external provider. No automated or AI-driven pentest, including Intrudify's, satisfies that bar. If your competent authority has identified your entity for TLPT, you need a dedicated TIBER-EU-aligned red-team provider for that specific exercise; Intrudify is a complementary control for the continuous Article 24-25 testing you still need between and around TLPT cycles.

  • Findings mapped to the relevant Article 24-25 testing requirements
  • Reproducible proof-of-exploit for high and critical findings
  • Developer-ready remediation and a re-test window
  • Does not replace TLPT - use a TIBER-EU-aligned provider for that obligation if your entity is in scope

How a pentest maps to controls

Control What a pentest evidences
Art. 24 General requirements for digital operational resilience testing: establishing, maintaining, and reviewing a testing programme, with critical or important ICT systems tested at least annually.
Art. 25 Testing of ICT tools and systems: vulnerability assessments, scans, and penetration testing among the appropriate tests within the programme. A standard web/API pentest supports this directly.
Art. 26-27 Threat-Led Penetration Testing (TLPT): advanced, intelligence-led red-team testing aligned to TIBER-EU, required at least every 3 years for entities identified by their competent authority. Not satisfied by an automated or AI-driven pentest.

Need audit-ready evidence for DORA?

Book a scoping call

Frequently asked questions

Does DORA require a penetration test?

Yes, for the general obligation: Article 25 names penetration testing as part of the testing programme Article 24 requires of nearly all financial entities. A separate obligation, TLPT under Articles 26-27, applies only to a subset of entities and is not satisfied by a standard pentest.

What is Threat-Led Penetration Testing (TLPT)?

An advanced, intelligence-led red-team exercise required under DORA Articles 26-27 for financial entities identified by their competent authority, aligned to the TIBER-EU framework and run at least every 3 years. It is human-led, not an automated scan or pentest.

Who has to run TLPT under DORA?

Competent authorities identify in-scope entities using Article 4(2) proportionality criteria. In practice this covers significant credit institutions, G-SIBs/O-SIIs, significant insurers, systemically relevant trading venues, and large payment/crypto-asset firms, not most small or mid-sized entities.

Can an automated or AI-driven pentest satisfy DORA's TLPT requirement?

No. TLPT is a human-led, intelligence-driven red-team engagement under Article 27's tester requirements and the TIBER-EU methodology. It cannot be satisfied by an automated or AI-driven pentest, including Intrudify's - those support the separate Article 24-25 obligation instead.

When did DORA start applying?

DORA (Regulation (EU) 2022/2554) has applied directly across the EU since 17 January 2025, per Article 64. As a regulation, it required no national transposition and took effect on that date in every Member State simultaneously.

How often must TLPT be performed?

At least once every 3 years for entities identified as in scope, per Article 26. Competent authorities can require it more frequently based on an entity's risk profile. General testing under Article 24-25 is expected at least annually.

What is the difference between DORA general testing and TLPT?

General testing (Art. 24-25) covers vulnerability assessments, scans, and penetration testing for nearly all financial entities. TLPT (Art. 26-27) is a narrower, advanced, TIBER-EU-aligned red-team exercise required only for entities identified by their competent authority.

Sources
Related frameworks
NIS2 Security testing is expected as part of Article 21 risk management, not a named pentest mandate. PCI DSS Explicitly required: internal and external penetration testing at least every 12 months (Requirement 11.4).
All compliance frameworks