Digital Operational Resilience Testing Under DORA

DORA requires a digital operational resilience testing programme. Testing should show whether ICT systems and processes can support critical services through disruption. A collection of technical scans does not by itself demonstrate operational resilience.

Published 2026-09-09 | Updated 2026-09-09 | GoalTech Ltd

Testing should answer a business question

Build a risk-based programme

DORA also provides for threat-led penetration testing for financial entities that meet the applicable criteria. This is a specialised activity with requirements for scope and testers and should not be confused with routine vulnerability testing.

  • Map critical services to applications, infrastructure, data and third parties.
  • Select tests according to risk, change and previous findings.
  • Include technical, procedural and scenario-based testing where appropriate.
  • Define independent review, evidence and acceptance criteria.
  • Record findings, owners, deadlines and retesting.
  • Report material weaknesses and overdue actions to management.

Consulting and specialist delivery

GoalTech can help design the programme, connect tests with risk and continuity plans, coordinate specialist testers and review remediation evidence. Where penetration testing or another specialist assessment is required, the engagement should identify the relevant competence, independence and reporting requirements.

Ask GoalTech to review your digital operational resilience testing programme.

Request a consulting discussion

Request a consultation with GoalTech