Testing under Arts. 24-25
Penetration testing
Penetration testing of applications, APIs and infrastructure, source code reviews, vulnerability and network security assessments - as part of your testing programme.
Compliance · DORA
DORA - Regulation (EU) 2022/2554 on digital operational resilience - has applied since 17 January 2025 to banks, insurers, investment firms, payment institutions and other financial entities. DORA compliance requires an ICT risk management framework, a resilience testing programme and, for selected entities, threat-led penetration testing (TLPT). We carry out testing under Arts. 24-25 and assess ICT risk management frameworks and TLPT readiness.
01Scope
DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022. It is directly applicable in every EU Member State - no national transposition is needed - and has applied since 17 January 2025.
The Regulation covers 20 categories of financial entities (Art. 2(1)(a)-(t)), including:
Obligations apply in proportion to an entity's size and overall risk profile and to the nature, scale and complexity of its activities (Art. 4). A microenterprise within the meaning of DORA employs fewer than 10 persons, and its annual turnover or annual balance sheet total does not exceed EUR 2 million. Microenterprises and certain smaller entities have simplified requirements - among other things, they are not required to carry out TLPT.
The competent authority for Polish financial entities is the Polish Financial Supervision Authority (KNF), and major incidents are reported to the KNF. Poland adapted its national law to the Regulation through the Act of 25 June 2025 (Dz.U. 2025 item 1069), which came into force on 7 August 2025. Among other things, it added provisions on TLPT and fines to the Polish Financial Market Supervision Act.
02Requirements
The Regulation sets out its requirements chapter by chapter. Market materials often refer to these chapters as the five pillars of DORA.
| Chapter | Title | Articles | What it covers |
|---|---|---|---|
| II | ICT risk management | Arts. 5-16 | ICT risk management framework, responsibility of the management body, protection, detection, response, backups |
| III | ICT-related incident management, classification and reporting | Arts. 17-23 | Incident management process, classification and reporting of major incidents to the authority |
| IV | Digital operational resilience testing | Arts. 24-27 | Testing programme, tests under Art. 25 and advanced testing (TLPT) |
| V | Managing of ICT third-party risk | Arts. 28-44 | Strategy, register of information on contractual arrangements, contractual provisions, oversight of critical providers |
| VI | Information-sharing arrangements | Art. 45 | Voluntary exchange of cyber threat information |
The requirements are specified further in delegated and implementing acts, including Commission Delegated Regulations (EU) 2024/1774 on the ICT risk management framework, (EU) 2025/301 on incident reporting and (EU) 2025/1190 on TLPT. The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it (Art. 5(2)). How we assess the framework against Arts. 5-16 is explained on our ICT risk management framework assessment page.
03Testing
Chapter IV of DORA sets out two levels of testing: a testing programme for every entity except microenterprises, and advanced TLPT for entities identified by the competent authority.
The programme provides for appropriate tests, such as:
The list is not exhaustive - which tests you run depends on your risk assessment and on how critical each system is.
04Incidents and fines
| Report | Deadline |
|---|---|
| Initial notification | within 4 hours of classifying the incident as major, but no later than 24 hours after becoming aware of it |
| Intermediate report | no later than 72 hours after the initial notification |
| Final report | no later than one month after the intermediate report |
The deadlines are set by Art. 19(4) DORA and Art. 5 of Delegated Regulation (EU) 2025/301. In Poland, reports go to the KNF.
For breaches of the rules on ICT risk management, incidents, testing and third-party providers, among others, the KNF can fine an entity up to PLN 20,869,500 or 10% of total annual turnover, and a management board member up to PLN 3,042,410 (Art. 18zm(1) of the Financial Market Supervision Act).
05How we help
We bring together a security testing team and a software house that builds systems for regulated industries.
Testing under Arts. 24-25
Penetration testing of applications, APIs and infrastructure, source code reviews, vulnerability and network security assessments - as part of your testing programme.
ICT risk management framework assessment
A comparison of your framework against Arts. 5-16 DORA and Delegated Regulation (EU) 2024/1774: a compliance matrix and an action plan.
Testing programme and TLPT readiness assessment
A review of the testing programme under Arts. 24-27: scope, frequency, tester independence, handling of results, and assessment of TLPT providers against Art. 27.
Secure software
As a software house, we build systems with code reviews and security testing throughout the development lifecycle - as Delegated Regulation (EU) 2024/1774 expects.
Every test ends with a report containing technical evidence, a risk rating and recommendations, and we map the findings to DORA requirements. Once the issues are fixed, we run a retest, so your testing programme also holds evidence that they have been resolved. We do not carry out TLPT ourselves - we help you prepare for it and assess proposals from TLPT providers.
06ICT providers
A financial entity remains responsible for compliance even when it relies on third-party providers. That is why DORA requirements end up in contracts with IT companies.
In Poland, the financial entity notifies the KNF of a planned contract for ICT services supporting critical or important functions no later than 14 days before entering into it. Critical ICT third-party service providers are overseen directly by the European Supervisory Authorities - the first list of 19 providers was published on 18 November 2025.
If you are choosing a software house for a system in the financial sector, ask about these provisions as early as the proposal stage. In our projects we work under contracts with an NDA and an SLA, we keep data and infrastructure in EU data centres, and security testing is built into the development lifecycle - see how we build secure software.
On 5 October 2026, the Office of the Polish Financial Supervision Authority (UKNF) published recommendations for financial market entities on the security review of SaaS services and ICT third-party risk management - in connection with attacks on providers of software made available as a service and disclosed breaches of the security of the data they process (UKNF recommendations of 5 October 2026, introduction).
To the financial entities listed in Art. 2(1) of the Regulation, including banks, payment and electronic money institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings, larger insurance intermediaries and institutions for occupational retirement provision. It also applies to ICT third-party service providers, as regards the oversight framework for critical providers. Obligations apply in proportion to each entity's size and risk profile.
Financial entities other than microenterprises run a testing programme that provides for appropriate tests, such as vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, source code reviews, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing (Art. 25). Systems supporting critical or important functions are tested at least once a year (Art. 24), and entities identified by the competent authority carry out TLPT at least every three years (Art. 26).
No. A penetration test is one of the tests listed in Art. 25, whereas DORA requires a risk-based testing programme with procedures for handling the results and independent testers. On top of that come the ICT risk management framework, incident management and the management of ICT third-party risk. The testing we carry out is described on our penetration testing page.
Indirectly - through contracts. A financial entity must sign contracts with its ICT third-party service providers that include the minimum provisions set out in Art. 30 (such as assistance with incidents, cooperation with the authorities and audit rights), and it remains responsible for compliance itself. Direct oversight by EU bodies applies to critical providers designated by the European Supervisory Authorities - the first list was published on 18 November 2025.
To both, in different respects. For essential and important entities in the banking and financial market infrastructure sectors, DORA replaces the provisions of the Polish National Cybersecurity System Act (KSC Act) on the security management system and incident reporting, but obligations such as registration, contact persons and training for the head of the entity still apply (Art. 8i of the KSC Act). More on our NIS2/KSC audit page.
The Polish Financial Supervision Authority (KNF). The KNF receives reports of major ICT-related incidents, identifies by decision the entities required to carry out TLPT and can impose fines - of up to PLN 20,869,500 or 10% of total annual turnover on an entity and up to PLN 3,042,410 on a management board member (Polish Financial Market Supervision Act, Arts. 18zg, 18zk and 18zm).
DORA · TLPT
Threat-led penetration testing (TLPT) under DORA: Arts. 26-27, RTS 2025/1190, who must test and how often, the red team process and tester requirements.
DORA · ICT risk
DORA ICT risk management framework assessment against Arts. 5-16 and RTS 2024/1774: scope, the simplified framework, method, compliance matrix and action plan.
Cybersecurity · Penetration testing
Penetration testing services for web and mobile apps, APIs, infrastructure, cloud and source code. OWASP and PTES, evidence-based reports and retests.
Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.
or call +48 575 621 877