Insights

DORA - articles on digital operational resilience in the financial sector

DORA has applied since 17 January 2025. Our articles explain its testing requirements - from the digital operational resilience testing programme to TLPT - based on the text of the regulation, the regulatory technical standards and communications from the Polish Financial Supervision Authority (KNF).

01About this category

DORA in practice for banks, insurers and ICT providers

The Digital Operational Resilience Act (DORA) requires financial entities to manage ICT risk, report major ICT-related incidents, test their digital operational resilience regularly and oversee their ICT third-party service providers. These requirements pass down the supply chain to software houses, cloud providers and companies that maintain systems, whose contracts must include the provisions set out in Article 30 of the regulation.

Our article on penetration testing vs TLPT explains the two levels of testing under DORA: the digital operational resilience testing programme under Arts. 24-25, which almost every financial entity has to run, and threat-led penetration testing (TLPT) under Arts. 26-27, which is carried out only by entities designated by the supervisory authority - in Poland, the KNF. It also covers how TLPT works, how to prepare for it before the authority's decision arrives and how to read proposals from TLPT providers.

We write for risk, security and IT teams at financial institutions, and for suppliers who want to know what their financial-sector clients will expect of them.

We take our facts from the text of the regulation, the regulatory technical standards and KNF communications, always with the date of the legal status. Our articles are for information only and are no substitute for legal advice.

How we help financial institutions: DORA compliance, TLPT preparation and ICT risk assessment.

Articles

Sources

  1. Regulation (EU) 2022/2554 of the European Parliament and of the Council on digital operational resilience for the financial sector (DORA), OJ L 333, 27.12.2022 ()
  2. Commission Delegated Regulation (EU) 2025/1190 - regulatory technical standards on threat-led penetration testing (TLPT) ()

Legal status as of Updated

See also

Let's talk about your project or audit

Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.

or call +48 575 621 877