Law / European Union

DORA, Articles 24-27 (Digital Operational Resilience Testing and Threat-Led Penetration Testing)

Regulation (EU) 2022/2554, Arts. 24-27

In force since .

A sector security regimes rule binding private bodies.

Private right of action
No
Obligation class
Security, Governance

As of .

What it requires

  • It reaches you if you are a financial entity under Article 2(1), points (a) to (t), of Regulation (EU) 2022/2554, unless Article 2(3) takes you out of the Regulation or your Member State has excluded you under Article 2(4). The testing program duties of Article 24 apply to you unless you are a microenterprise. The threat-led penetration testing duty of Article 26(1) applies to you only if your competent authority has identified you under Article 26(8) and you are neither a microenterprise nor an entity named in Article 16(1), first subparagraph. An ICT third-party service provider that is in the scope of a test takes part through the financial entity, which keeps full responsibility (Article 26(3)).
  • Unless you are a microenterprise, establish, maintain and review a sound and comprehensive digital operational resilience testing program as an integral part of your ICT risk-management framework, follow a risk-based approach that takes account of the evolving landscape of ICT risk and the criticality of your information assets and services, and ensure that tests are undertaken by independent parties, internal or external, with sufficient resources and no conflict of interest where the tester is internal (Article 24(1) to (4)).
  • Unless you are a microenterprise, establish procedures and policies to prioritize, classify and remedy all issues the tests reveal, set up internal validation methodologies to ascertain that all identified weaknesses, deficiencies or gaps are fully addressed, and ensure at least yearly that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions (Article 24(5) and (6)).
  • Include in the program a range of appropriate tests, such as vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing (Article 25(1)). If you are a central securities depository or central counterparty, perform vulnerability assessments before any deployment or redeployment of applications and infrastructure components and of the ICT services supporting critical or important functions (Article 25(2)). If you are a microenterprise, combine a risk-based approach with strategic planning of ICT testing (Article 25(3)).
  • If your competent authority has identified you for threat-led penetration testing, carry out advanced testing by TLPT at least every 3 years, or at the frequency your competent authority sets, cover several or all critical or important functions on live production systems, assess which critical or important functions need to be covered, and have the scope validated by the competent authorities (Article 26(1) and (2)).
  • Take the necessary measures and safeguards to ensure the participation of any ICT third-party service provider in the scope of the test, keep full responsibility for compliance with the Regulation, and apply effective risk management controls to mitigate the risks of any impact on data, damage to assets and disruption to critical or important functions, services or operations (Article 26(3) and (5)).
  • When the testing ends and reports and remediation plans are agreed, give the designated authority a summary of the relevant findings, the remediation plans and the documentation demonstrating that the TLPT was conducted in accordance with the requirements, and notify your competent authority of the attestation you receive, the summary and the remediation plans (Article 26(6) and (7)).
  • Contract only testers that meet Article 27(1): of the highest suitability and reputability, with technical and organizational capabilities and specific expertise in threat intelligence, penetration testing and red team testing, certified by an accreditation body in a Member State or adhering to formal codes of conduct or ethical frameworks, able to provide an independent assurance or an audit report on the sound management of the risks of TLPT, and covered by professional indemnity insurance. Use internal testers only with the approval of your competent authority or the designated single public authority, contract external testers every three tests, use only external testers if you are a credit institution classified as significant under Regulation (EU) No 1024/2013, and ensure that the threat intelligence provider is external to you (Article 26(8) and Article 27(1) and (2)).
  • Ensure that contracts with external testers require a sound management of the TLPT results and that any data processing, including generation, storage, aggregation, drafting, reporting, communication or destruction, does not create risks to you (Article 27(3)).

Who enforces it

Enforcement body

The competent authority designated for each category of financial entity under Article 46, which ensures compliance with the Regulation in accordance with the powers granted by the respective legal acts.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 24(1) requires a financial entity other than a microenterprise to establish, maintain and review a sound and comprehensive digital operational resilience testing program as an integral part of its ICT risk-management framework. Article 24(4) requires a financial entity other than a microenterprise to ensure that tests are undertaken by independent parties, whether internal or external.

Article 24(6) requires a financial entity other than a microenterprise to ensure, at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions. Article 25(1) requires the testing program to provide for appropriate tests such as vulnerability assessments and scans, network security assessments, source code reviews where feasible, scenario-based tests and penetration testing.

Article 25(2) requires central securities depositories and central counterparties to perform vulnerability assessments before any deployment or redeployment of new or existing applications and infrastructure components, and ICT services supporting critical or important functions. Article 25(3) requires a microenterprise to perform the Article 25(1) tests by combining a risk-based approach with a strategic planning of ICT testing.

Article 26(1) requires the financial entities that a competent authority identifies under Article 26(8), other than microenterprises and the entities named in Article 16(1), first subparagraph, to carry out advanced testing by means of threat-led penetration testing (TLPT) at least every 3 years. Article 26(1) also lets the competent authority, where necessary and based on the entity's risk profile and operational circumstances, request the entity to reduce or increase that frequency.

Article 26(8) has competent authorities identify the financial entities that must perform TLPT on an assessment of impact-related factors, possible financial stability concerns including systemic character, and the entity's specific ICT risk profile, level of ICT maturity or technology features.

Article 26(2) requires each threat-led penetration test to cover several or all critical or important functions of the financial entity and to be performed on live production systems supporting those functions. Article 26(3) requires the financial entity to take the necessary measures and safeguards to ensure the participation of ICT third-party service providers included in the scope of TLPT, and to retain at all times full responsibility for compliance with the Regulation.

Article 26(4) lets the financial entity and the ICT third-party service provider, where the provider's participation in the TLPT is reasonably expected to have an adverse impact on the quality or security of its services to customers outside the scope of the Regulation or on the confidentiality of the data related to those services, agree in writing that the provider contracts directly with an external tester, under the direction of one designated financial entity, for a pooled TLPT involving several financial entities.

Article 26(6) requires the financial entity and any external testers, once reports and remediation plans have been agreed, to give the designated authority a summary of the relevant findings, the remediation plans and the documentation demonstrating that the TLPT was conducted in accordance with the requirements.

Article 26(8) requires a financial entity that uses internal testers to contract external testers every three tests, and requires a credit institution classified as significant under Regulation (EU) No 1024/2013 to use only external testers.

Article 27(1) requires testers for TLPT to be of the highest suitability and reputability, to have technical and organizational capabilities and specific expertise in threat intelligence, penetration testing and red team testing, to be certified or adhere to formal codes of conduct, to provide independent assurance or an audit report, and to be covered by professional indemnity insurance.

Article 27(2) allows internal testers only with the approval of the competent authority or the designated single public authority, requires the competent authority to have verified sufficient dedicated resources and the avoidance of conflicts of interest, and requires the threat intelligence provider to be external to the financial entity.

Article 26(11) tasks the European Supervisory Authorities, in agreement with the ECB, with developing joint draft regulatory technical standards in accordance with the TIBER-EU framework that specify the TLPT criteria, scope and methodology further. Article 50(3) requires Member States to lay down rules establishing appropriate administrative penalties and remedial measures for breaches of the Regulation, which must be effective, proportionate and dissuasive. Article 64 applies the Regulation from .

When LexLint raises it

When your app profile says your app provides financial services.

Back to the example  ·  Lint your app