DORA
DORA Chapter IV: Digital Operational Resilience Testing

DORA DORA-Art.26: Advanced testing of ICT tools, systems and processes based on TLPT

Only financial entities that their competent authority has identified for TLPT (under Article 26(8), third subparagraph, on impact, financial stability and ICT risk profile, applying Article 4(2)) must carry out threat-led penetration testing; Article 16(1) entities and microenterprises are excluded. Identified entities test at least every 3 years, a frequency the authority may shorten or extend for the entity's risk profile. Each test covers some or all of the critical or important functions on live production systems, including outsourced ones; the entity's scoping assessment is validated by the authority; ICT third-party providers in scope take part, or join pooled testing where their participation would harm other customers; risk management controls limit impact on data, assets and services; after testing, a summary of findings, remediation plans and documentation go to the TLPT authority, which issues an attestation. Testers meet Article 27; entities using internal testers contract external testers every third test, and significant credit institutions use only external testers.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 15 controls across 9 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 3 controls

  • CA-8 Penetration Testing
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • CA-8(2) Penetration Testing | Red Team Exercises (CA-8(2))

FedRAMP Moderate · 3 controls

  • CA-8 Penetration Testing
  • CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team (CA-8(1))
  • CA-8(2) Penetration Testing | Red Team Exercises (CA-8(2))

CIS Controls v8 · 2 controls

  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • TIBER-2.3 Active red team testing on live production
  • TIBER-3.8 Results sharing and mutual recognition

ISO 27001:2022 · 1 control

  • 8.34 Protection of information systems during audit testing 

ISO 27002:2022 · 1 control

  • 8.34 Protection of information systems during audit testing

NIS2 Directive · 1 control

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter IV: Digital Operational Resilience Testing

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.26 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 15 it maps to, and the evidence behind each claim, over MCP and REST.