01Introduction
Since January 2025, EU banks, insurers, investment firms, payment and crypto-asset providers must prove they can withstand and recover from ICT disruption. DORA makes resilience testing a legal duty, not a best practice. See how this applies to fintech.
02What is DORA?
The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) is an EU regulation that applies from 17 January 2025 to about 20 types of financial entity and their critical ICT providers. It has five pillars: ICT risk management, incident reporting, resilience testing, third-party risk and information sharing.
Entities must test ICT systems supporting critical functions at least yearly. Entities designated as significant must also run threat-led penetration testing (TLPT), based on the TIBER-EU framework, at least every three years using qualified, largely external testers.
03How DORA works
The testing pillar is layered by entity size and criticality.
- 1.
Risk management framework
Document ICT assets, dependencies and controls, owned by the management body.
- 2.
Baseline testing
Run vulnerability assessments, scans, source code review and penetration tests on a risk-based program.
- 3.
TLPT
Significant entities run intelligence-led red team tests on live production systems, overseen by the regulator.
- 4.
Report and remediate
Classify and report major incidents within tight deadlines and track findings to closure.
04Threats and risks
DORA targets systemic, not just individual, risk.
Concentration risk
Many firms relying on the same cloud or software provider.
Supply chain compromise
Attacks through ICT vendors, covered by the software supply chain pillar.
Point-in-time testing
Annual tests that miss weaknesses introduced between them.
Penalties
National supervisors can impose fines and remedial orders, and management carries responsibility.
05How Parameter helps
Parameter covers the continuous testing DORA expects between formal TLPT exercises. It does not replace a TLPT tester where one is required.
Yearly and beyond
The pentesting agents test critical applications and APIs on every release, not just once a year.
TLPT readiness
Red team as a service finds and fixes the paths a TLPT team would use, before they arrive.
Third-party components
Supply Chain tracks the open source and vendor code in your systems.

