Parameter

What is DORA?

Digital Operational Resilience Act

What DORA requires of EU financial entities, including resilience testing, threat-led penetration testing (TLPT) and ICT third-party risk.

01Introduction

Since January 2025, EU banks, insurers, investment firms, payment and crypto-asset providers must prove they can withstand and recover from ICT disruption. DORA makes resilience testing a legal duty, not a best practice. See how this applies to fintech.

02What is DORA?

The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) is an EU regulation that applies from 17 January 2025 to about 20 types of financial entity and their critical ICT providers. It has five pillars: ICT risk management, incident reporting, resilience testing, third-party risk and information sharing.

Entities must test ICT systems supporting critical functions at least yearly. Entities designated as significant must also run threat-led penetration testing (TLPT), based on the TIBER-EU framework, at least every three years using qualified, largely external testers.

03How DORA works

The testing pillar is layered by entity size and criticality.

  1. 1.

    Risk management framework

    Document ICT assets, dependencies and controls, owned by the management body.

  2. 2.

    Baseline testing

    Run vulnerability assessments, scans, source code review and penetration tests on a risk-based program.

  3. 3.

    TLPT

    Significant entities run intelligence-led red team tests on live production systems, overseen by the regulator.

  4. 4.

    Report and remediate

    Classify and report major incidents within tight deadlines and track findings to closure.

04Threats and risks

DORA targets systemic, not just individual, risk.

  • Concentration risk

    Many firms relying on the same cloud or software provider.

  • Supply chain compromise

    Attacks through ICT vendors, covered by the software supply chain pillar.

  • Point-in-time testing

    Annual tests that miss weaknesses introduced between them.

  • Penalties

    National supervisors can impose fines and remedial orders, and management carries responsibility.

05How Parameter helps

Parameter covers the continuous testing DORA expects between formal TLPT exercises. It does not replace a TLPT tester where one is required.

  • Yearly and beyond

    The pentesting agents test critical applications and APIs on every release, not just once a year.

  • TLPT readiness

    Red team as a service finds and fixes the paths a TLPT team would use, before they arrive.

  • Third-party components

    Supply Chain tracks the open source and vendor code in your systems.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your DORA program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.