Looking for a penetration test? Fixed-scope engagements for GDPR, NIS2 & DORA.Get a quote today →
Request a Quote
Compliance

DORA Penetration Testing & Articles 24–25 Evidence

DORA requires most EU financial entities to run an annual testing programme covering the ICT systems that support critical or important functions. We deliver that baseline testing and the audit trail it needs to leave behind.

At a Glance
Included WithAny Testing Engagement
Delivery FormatAudit-Ready Report
Best ForBanks, Payment & E-Money Institutions, Investment Firms
FrameworksDORA Art. 24–25

Built for the auditor, not just your team

Every engagement includes reporting written for direct submission, not internal notes you have to reformat before your auditor can use them.

01

Annual Testing Programme Coverage

Core Coverage

Manual testing of the ICT systems and applications supporting your critical or important functions, structured to satisfy the Article 24 testing-programme requirement.

  • Applies to nearly all DORA in-scope entities except microenterprises.
02

Article 25 Test Types

Core Coverage

We run the penetration testing and vulnerability assessment components named in Article 25(1), scoped to your application and API layer.

  • Complements network security assessments and scenario-based tests your broader programme may also require.
03

Independent Tester Documentation

Core Coverage

Article 24(4) expects testers to be independent and suitably qualified. We provide documentation of independence and methodology for your risk function's file.

  • No conflicts of interest with your ICT infrastructure or outsourcing providers.
04

The TLPT Boundary, Handled Honestly

Core Coverage

If your competent authority hasn't designated you for threat-led penetration testing under Articles 26–27, a standard Article 24–25 programme is what's expected. If you have been designated, that's a separate, TIBER-EU-governed engagement requiring specific accreditation.

  • We'll tell you plainly which one applies before we scope anything.

What to expect

What's Included

  • Manual pentest of ICT systems supporting critical or important functions
  • Coverage mapped to the Article 25(1) test types relevant to applications and APIs
  • Documentation of tester independence and methodology for Article 24(4)
  • Annual-cycle structure so next year's test builds on this one's findings

Deliverables

  • Audit-ready report for your ICT risk management framework file
  • Evidence formatted for your competent authority if requested
  • Retest evidence once findings are closed
  • A written independence and methodology statement

Ready to scope your Article 24-25 testing programme?

Tell us your entity type and whether you've been designated for TLPT, and you'll get a proposal scoped to what actually applies to you.