DORA Chapter IV: Digital Operational Resilience Testing
DORA DORA-Art.25: Testing of ICT tools and systems
The testing programme provides, proportionately under Article 4(2), for appropriate tests such as penetration and end-to-end tests, performance and compatibility testing, scenario-based tests, review of source code where feasible, scans and vulnerability assessments, analysis of open-source components, gap analyses, assessments of network security, reviews of physical security, and questionnaires with scanning software. Central securities depositories and central counterparties also run vulnerability assessments before deploying or redeploying applications or infrastructure components, and ICT services behind critical or important functions (Art. 25(2)). Microenterprises plan their tests by pairing a risk-based approach with strategic planning, weighing the resources and time spent against urgency, risk type, criticality and their capacity to take calculated risks (Art. 25(3)). The at least yearly testing of systems supporting critical or important functions is an Article 24(6) duty on entities other than microenterprises.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 54 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
You are reading one control. How much of DORA have you already done?
DORA DORA-Art.25 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.