Compliance · DORA

DORA compliance: digital operational resilience testing and ICT risk management

DORA - Regulation (EU) 2022/2554 on digital operational resilience - has applied since 17 January 2025 to banks, insurers, investment firms, payment institutions and other financial entities. DORA compliance requires an ICT risk management framework, a resilience testing programme and, for selected entities, threat-led penetration testing (TLPT). We carry out testing under Arts. 24-25 and assess ICT risk management frameworks and TLPT readiness.

01Scope

The DORA regulation: who it applies to

DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022. It is directly applicable in every EU Member State - no national transposition is needed - and has applied since 17 January 2025.

The Regulation covers 20 categories of financial entities (Art. 2(1)(a)-(t)), including:

  • credit institutions (banks)
  • payment institutions and electronic money institutions
  • investment firms and crypto-asset service providers
  • insurance and reinsurance undertakings
  • insurance intermediaries (other than micro, small and medium-sized enterprises)
  • institutions for occupational retirement provision
  • central securities depositories, central counterparties and trading venues
  • management companies and managers of alternative investment funds

Obligations apply in proportion to an entity's size and overall risk profile and to the nature, scale and complexity of its activities (Art. 4). A microenterprise within the meaning of DORA employs fewer than 10 persons, and its annual turnover or annual balance sheet total does not exceed EUR 2 million. Microenterprises and certain smaller entities have simplified requirements - among other things, they are not required to carry out TLPT.

DORA in Poland

The competent authority for Polish financial entities is the Polish Financial Supervision Authority (KNF), and major incidents are reported to the KNF. Poland adapted its national law to the Regulation through the Act of 25 June 2025 (Dz.U. 2025 item 1069), which came into force on 7 August 2025. Among other things, it added provisions on TLPT and fines to the Polish Financial Market Supervision Act.

02Requirements

DORA compliance requirements: the main areas

The Regulation sets out its requirements chapter by chapter. Market materials often refer to these chapters as the five pillars of DORA.

Chapters II-VI of DORA
Chapter Title Articles What it covers
II ICT risk management Arts. 5-16 ICT risk management framework, responsibility of the management body, protection, detection, response, backups
III ICT-related incident management, classification and reporting Arts. 17-23 Incident management process, classification and reporting of major incidents to the authority
IV Digital operational resilience testing Arts. 24-27 Testing programme, tests under Art. 25 and advanced testing (TLPT)
V Managing of ICT third-party risk Arts. 28-44 Strategy, register of information on contractual arrangements, contractual provisions, oversight of critical providers
VI Information-sharing arrangements Art. 45 Voluntary exchange of cyber threat information

The requirements are specified further in delegated and implementing acts, including Commission Delegated Regulations (EU) 2024/1774 on the ICT risk management framework, (EU) 2025/301 on incident reporting and (EU) 2025/1190 on TLPT. The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it (Art. 5(2)). How we assess the framework against Arts. 5-16 is explained on our ICT risk management framework assessment page.

03Testing

DORA testing: which tests are required

Chapter IV of DORA sets out two levels of testing: a testing programme for every entity except microenterprises, and advanced TLPT for entities identified by the competent authority.

Testing programme (Art. 24)

  • Financial entities other than microenterprises establish a risk-based digital operational resilience testing programme.
  • Tests are carried out by independent parties, whether internal or external.
  • All ICT systems and applications supporting critical or important functions are tested at least once a year.
  • Issues revealed by the tests are classified and remedied according to established procedures.

Further detail in RTS 2024/1774

  • Automated vulnerability scanning of ICT assets supporting critical or important functions at least once a week.
  • The systems development procedure includes source code reviews covering static and dynamic testing, including security testing of internet-exposed applications.

Tests under Art. 25(1)

The programme provides for appropriate tests, such as:

  • vulnerability assessments and scans
  • open source analyses
  • network security assessments
  • gap analyses
  • physical security reviews
  • questionnaires and scanning software solutions
  • source code reviews where feasible
  • scenario-based tests
  • compatibility testing
  • performance testing
  • end-to-end testing
  • penetration testing

The list is not exhaustive - which tests you run depends on your risk assessment and on how critical each system is.

04Incidents and fines

Incident reporting and fines

Reporting deadlines for a major ICT-related incident
Report Deadline
Initial notification within 4 hours of classifying the incident as major, but no later than 24 hours after becoming aware of it
Intermediate report no later than 72 hours after the initial notification
Final report no later than one month after the intermediate report

The deadlines are set by Art. 19(4) DORA and Art. 5 of Delegated Regulation (EU) 2025/301. In Poland, reports go to the KNF.

For breaches of the rules on ICT risk management, incidents, testing and third-party providers, among others, the KNF can fine an entity up to PLN 20,869,500 or 10% of total annual turnover, and a management board member up to PLN 3,042,410 (Art. 18zm(1) of the Financial Market Supervision Act).

05How we help

Our services for entities in scope of DORA

We bring together a security testing team and a software house that builds systems for regulated industries.

Every test ends with a report containing technical evidence, a risk rating and recommendations, and we map the findings to DORA requirements. Once the issues are fixed, we run a retest, so your testing programme also holds evidence that they have been resolved. We do not carry out TLPT ourselves - we help you prepare for it and assess proposals from TLPT providers.

06ICT providers

DORA requirements for ICT third-party service providers

A financial entity remains responsible for compliance even when it relies on third-party providers. That is why DORA requirements end up in contracts with IT companies.

Every contract for ICT services (Art. 30(2))

  • a clear description of the services and of the conditions for subcontracting
  • locations where services are provided and data is processed
  • data protection, access to data and its return when the contract ends
  • service level descriptions
  • assistance with ICT incidents at no additional cost or at a cost determined in advance
  • full cooperation with the supervisory authorities
  • termination rights and minimum notice periods
  • the provider's participation in the financial entity's security awareness programmes and training

Services supporting critical or important functions (Art. 30(3))

  • full SLAs with measurable performance targets
  • testing of contingency plans and ICT security measures on the provider's side
  • the provider's participation in the financial entity's TLPT
  • unrestricted rights of access, inspection and audit
  • exit strategies with a transition period

In Poland, the financial entity notifies the KNF of a planned contract for ICT services supporting critical or important functions no later than 14 days before entering into it. Critical ICT third-party service providers are overseen directly by the European Supervisory Authorities - the first list of 19 providers was published on 18 November 2025.

If you are choosing a software house for a system in the financial sector, ask about these provisions as early as the proposal stage. In our projects we work under contracts with an NDA and an SLA, we keep data and infrastructure in EU data centres, and security testing is built into the development lifecycle - see how we build secure software.

On 5 October 2026, the Office of the Polish Financial Supervision Authority (UKNF) published recommendations for financial market entities on the security review of SaaS services and ICT third-party risk management - in connection with attacks on providers of software made available as a service and disclosed breaches of the security of the data they process (UKNF recommendations of 5 October 2026, introduction).

Frequently asked questions

Who does DORA apply to?

To the financial entities listed in Art. 2(1) of the Regulation, including banks, payment and electronic money institutions, investment firms, crypto-asset service providers, insurance and reinsurance undertakings, larger insurance intermediaries and institutions for occupational retirement provision. It also applies to ICT third-party service providers, as regards the oversight framework for critical providers. Obligations apply in proportion to each entity's size and risk profile.

What testing does DORA require?

Financial entities other than microenterprises run a testing programme that provides for appropriate tests, such as vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, source code reviews, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing (Art. 25). Systems supporting critical or important functions are tested at least once a year (Art. 24), and entities identified by the competent authority carry out TLPT at least every three years (Art. 26).

Is a penetration test enough for DORA compliance?

No. A penetration test is one of the tests listed in Art. 25, whereas DORA requires a risk-based testing programme with procedures for handling the results and independent testers. On top of that come the ICT risk management framework, incident management and the management of ICT third-party risk. The testing we carry out is described on our penetration testing page.

Does DORA apply to IT companies that serve banks?

Indirectly - through contracts. A financial entity must sign contracts with its ICT third-party service providers that include the minimum provisions set out in Art. 30 (such as assistance with incidents, cooperation with the authorities and audit rights), and it remains responsible for compliance itself. Direct oversight by EU bodies applies to critical providers designated by the European Supervisory Authorities - the first list was published on 18 November 2025.

Is a bank in Poland subject to DORA or to the Polish KSC Act?

To both, in different respects. For essential and important entities in the banking and financial market infrastructure sectors, DORA replaces the provisions of the Polish National Cybersecurity System Act (KSC Act) on the security management system and incident reporting, but obligations such as registration, contact persons and training for the head of the entity still apply (Art. 8i of the KSC Act). More on our NIS2/KSC audit page.

Who supervises DORA in Poland?

The Polish Financial Supervision Authority (KNF). The KNF receives reports of major ICT-related incidents, identifies by decision the entities required to carry out TLPT and can impose fines - of up to PLN 20,869,500 or 10% of total annual turnover on an entity and up to PLN 3,042,410 on a management board member (Polish Financial Market Supervision Act, Arts. 18zg, 18zk and 18zm).

Sources

  1. Regulation (EU) 2022/2554 of the European Parliament and of the Council on digital operational resilience for the financial sector (DORA), OJ L 333, 27.12.2022 ()
  2. Corrigendum to the Polish language version of Regulation (EU) 2022/2554 (DORA), OJ L 2024/90177, 12.3.2024 (in Polish) ()
  3. Commission Delegated Regulation (EU) 2024/1774 - ICT risk management tools, methods, processes and policies and the simplified ICT risk management framework ()
  4. Commission Delegated Regulation (EU) 2025/1190 - regulatory technical standards on threat-led penetration testing (TLPT) ()
  5. Commission Delegated Regulation (EU) 2025/301 - content and time limits for the notification of and reports on major ICT-related incidents ()
  6. Act of 25 June 2025 amending certain acts in connection with ensuring the digital operational resilience of the financial sector and the issuance of European green bonds (Dz.U. 2025 item 1069) (in Polish) ()
  7. ESAs - list of critical ICT third-party service providers designated under DORA (18 November 2025) ()
  8. UKNF (Office of the Polish Financial Supervision Authority) - Recommendations for financial market entities on the security review of SaaS services and ICT third-party risk management (5 October 2026) (in Polish) ()
  9. Act of 5 July 2018 on the National Cybersecurity System (KSC Act; Dz.U. 2018 item 1560, as amended) - ISAP, unofficial consolidated text prepared by the Chancellery of the Sejm (in Polish) ()

Legal status as of Updated

Related services

Let's talk about your project or audit

Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.

or call +48 575 621 877