DORA requires most EU financial entities to run an annual testing programme covering the ICT systems that support critical or important functions. We deliver that baseline testing and the audit trail it needs to leave behind.
Every engagement includes reporting written for direct submission, not internal notes you have to reformat before your auditor can use them.
Manual testing of the ICT systems and applications supporting your critical or important functions, structured to satisfy the Article 24 testing-programme requirement.
We run the penetration testing and vulnerability assessment components named in Article 25(1), scoped to your application and API layer.
Article 24(4) expects testers to be independent and suitably qualified. We provide documentation of independence and methodology for your risk function's file.
If your competent authority hasn't designated you for threat-led penetration testing under Articles 26–27, a standard Article 24–25 programme is what's expected. If you have been designated, that's a separate, TIBER-EU-governed engagement requiring specific accreditation.
Tell us your entity type and whether you've been designated for TLPT, and you'll get a proposal scoped to what actually applies to you.