DORA risk testing obligations: The 2026 baseline
Under the European Union’s Digital Operational Resilience Act (DORA), financial institutions must establish a comprehensive digital operational resilience testing programme. Specifically, Article 24 dictates that entities perform a full suite of security audits, including vulnerability assessments and open-source analyses. Furthermore, Article 26 mandates advanced Threat-Led Penetration Testing (TLPT) for critical systems at least once every three years.
The core challenge is the operational gap. Annual or triennial testing leaves a 364-day blind spot where code releases, infrastructure drifts, and new CVEs occur unnoticed. DORA compliance demands a proactive, continuous approach to risk management rather than a simple checkboxes audit exercise.
Mapping AssurePort to DORA testing requirements
| DORA Article | Requirement Description | AssurePort Continuous Capability |
|---|---|---|
| Art. 24.1 | Establish a testing programme covering all ICT systems. | Automated multi-engine scope covering web apps, APIs, GitHub, cloud, and hosts. |
| Art. 24.2 | Perform annual vulnerability assessments. | Continuous agentic scanning with real validation, eliminating static point-in-time limits. |
| Art. 25.1 | Establish appropriate validation for third-party tools. | Direct GitHub supply-chain audits, secrets verification, and Dockerfile posture assessments. |
| Art. 26.2 | TLPT execution on production services. | Safe, non-destructive active exploitation attempts to prove exploitability on actual surfaces. |
Bridging the gap between manual red teaming and AI
Continuous AI penetration testing is not a direct replacement for DORA TLPT, which requires formal human oversight, regulatory authorization, and highly tailored attack simulations. Rather, it serves as the foundation that makes TLPT successful. By executing continuous scans on every code change and infrastructure modification, financial entities can identify and resolve critical exposures before the formal red team engagement begins.
This operational split optimizes security spend: AI agents identify and triage routine authorization flaws, misconfigured endpoints, and supply-chain vulnerabilities, allowing human red teams to focus on bespoke business-logic attack chains.
A note on EU data residency: Financial organizations governed by DORA must ensure that their security data processing matches strict EU sovereign data rules. AssurePort processes and stores all finding records, logs, and AI inference requests inside the European Union (using Cloudflare Workers weur regional parameters and Fly Frankfurt machine instances), ensuring compliance with GDPR Art. 32 and DORA ICT risk management guidelines.
The TLPT timeline is no longer theoretical
DORA has applied across the European Union since 17 January 2025, and the specific rules for threat-led penetration testing arrived shortly after. The Commission Delegated Regulation (EU) 2025/1190 that sets out the TLPT methodology was published in June 2025 and became directly applicable in every Member State on 8 July 2025. The framework is now live, not a future deadline.
The population in scope is deliberately narrow. TLPT is mandatory only for entities that competent authorities designate as significant for financial stability or by the nature of their operations. Industry estimates put the first cycle at roughly 100 to 120 significant banks, 40 to 60 insurance groups, more than 30 market infrastructure operators, and over 20 major payment providers across the 2025 to 2028 window. Every other regulated entity still carries the full Article 24 testing-programme obligation, even where the advanced red-team requirement does not apply.
That split matters for how a security team should budget. A designated bank that runs one triennial TLPT exercise is not compliant on the strength of that single test alone. Article 24 expects a continuous, risk-based programme underneath it, and supervisors increasingly ask to see the evidence trail that connects the two.
What continuous testing hands to a DORA auditor
The value of continuous AI pentesting under DORA is not the scan itself. It is the record the scan produces. Each scan against a code or infrastructure change generates a dated finding, a severity rating, a proof-of-concept where exploitability is proven, and a remediation status. Strung together, those records form the audit trail that Article 24 expects and that a triennial test can never provide on its own.
Consider the practical questions a supervisor asks during a review: How quickly are critical vulnerabilities identified after a release? How is remediation tracked and verified? Where is the evidence that testing scope covers all ICT systems, not just the crown jewels? A point-in-time report answers those questions for one day of the year. A continuous programme answers them for every day.
- Coverage evidence — automated scoping across web apps, APIs, source code and cloud demonstrates the breadth Article 24 requires.
- Time-to-detect metrics — findings dated against release history show the blind spot has been closed, not merely acknowledged.
- Remediation proof — re-scans confirm that a fix actually landed, replacing the “we believe it is resolved” language auditors distrust.
- Threat-informed prioritisation — validated, exploitable findings are separated from theoretical ones so the formal TLPT team starts from a clean surface.
Used this way, continuous testing does not compete with TLPT. It feeds it. The red team walks into a formal engagement already knowing that the routine authorisation flaws, exposed endpoints and supply-chain gaps have been triaged, and it can spend its regulated, expensive hours on the bespoke attack chains that only a human adversary would attempt.
There is a cost dimension too. A formal TLPT exercise runs into six figures and consumes senior security time for weeks. When routine exposures reach that engagement unresolved, the red team burns budget rediscovering problems an automated pipeline could have flagged the same day a developer shipped them. Continuous testing protects the return on the mandated spend: it narrows the formal test to the questions that genuinely need human ingenuity, and it gives the board a defensible answer when a supervisor asks what happens on the other 362 days of the year. For a designated entity, that is the difference between treating DORA as an annual audit event and running it as an operational discipline.
Frequently Asked Questions
When did DORA and its threat-led penetration testing rules become applicable?
DORA has applied across the EU since 17 January 2025. The technical standard that governs threat-led penetration testing, Commission Delegated Regulation (EU) 2025/1190, was published in June 2025 and became directly applicable in all Member States on 8 July 2025, so the detailed TLPT rules are now in force.
Which financial entities must perform TLPT under DORA Article 26?
TLPT is mandatory only for entities designated by competent authorities as significant for financial stability or their operational profile. Industry estimates suggest roughly 100 to 120 significant banks, 40 to 60 insurance groups, 30-plus market infrastructure operators and 20-plus major payment providers will be in scope for the first EU cycle running 2025 to 2028. Entities outside that set still owe the full testing programme under Article 24.
Can continuous AI pentesting replace a formal TLPT engagement?
No. TLPT under DORA requires accredited human testers, threat intelligence, regulator oversight and a live production simulation at least every three years. Continuous AI pentesting is the layer underneath it: it keeps the attack surface clean between engagements so the formal red team spends its time on bespoke business-logic attack chains rather than routine authorisation flaws.
How does continuous testing satisfy the DORA Article 24 testing programme?
Article 24 requires a documented, risk-based testing programme covering all ICT systems, with vulnerability assessments and evidence of remediation. Continuous scanning produces a dated, immutable finding record for every code and infrastructure change, which is exactly the audit trail supervisors ask for when they review the programme.
Does AssurePort keep DORA testing data inside the EU?
Yes. All finding records, logs and AI inference requests are processed and stored inside the European Union using Cloudflare weur regional parameters and Fly Frankfurt machines, which supports the EU data-residency expectations that sit alongside DORA’s ICT risk-management requirements.