Industry
SECURITYFRAMEWORKDORA

Pentesting for DORA

DORA is the EU regulation on digital operational resilience. It applies to financial entities such as banks, insurers, investment firms, and payment providers. It requires a testing programme that includes penetration testing, with critical ICT systems tested at least yearly and threat-led testing (TLPT) for selected entities. Non-compliance triggers sanctions from national authorities.

The controls we cover

Requirement summary

Most financial entities must establish, maintain, and review a digital operational resilience testing programme under a risk-based approach, covering tests such as vulnerability assessments, source-code reviews, scenario-based tests, and penetration testing, with critical ICT systems tested at least yearly.

AISafe supports the recurrent testing part of the programme: automated web, API, and code testing with scoped reports and documented retests. It does not perform the separate regulated TLPT exercise.

Requirement summary

Identified financial entities must carry out threat-led penetration testing on live production systems supporting critical or important functions at least every three years, using qualified and independent testers under the prescribed process.

AISafe can help identify critical surfaces and confirm vulnerabilities ahead of a regulated TLPT. The TLPT itself must be run by qualified, independent testers.

Quick facts

ApplicabilityFinancial entities: banks, insurers, investment firms, payment and e-money institutions, and some critical ICT providers.
RequirementYes. A resilience testing programme is mandatory, and TLPT is required for specifically identified entities.
CostApplies regardless of company size, scaled by risk; the test programme and automation keep cost proportional to the entity.
CadenceCritical or important ICT systems at least yearly; TLPT at least every three years.

AISafe Labs delivers on-demand, audit-ready evidence for the Article 24–25 programme: recurrent web, API, and code testing with documented retests , in hours, where other vendors take weeks. AISafe Labs complements, never replaces, the regulated TLPT exercise required for selected entities.

Related frameworks

Get your Audit Evidence right now

Run a security assessment of your system, or contact us if your compliance programme requires additional support.