DORA has applied since 17 January 2025, and it reaches UK businesses through the European clients they serve. If you supply ICT services to an EU financial entity, or you run the UK arm of a group inside scope, threat-led penetration testing is now part of your world. The regulation expects vulnerability assessment every year and advanced testing every three years for the firms their regulator designates.

What DORA actually asks for
DORA requires every in-scope financial entity to run a digital operational resilience testing programme, not a single annual assessment. Articles 24 and 25 set the base layer: vulnerability assessments and scans of the ICT systems supporting critical or important functions, carried out at least yearly by independent parties. Article 26 sits above that and applies to a smaller group, the entities their competent authority identifies for advanced testing. Those firms run threat-led penetration testing at least every three years, following the TIBER-EU model. The European Supervisory Authorities published the final draft regulatory technical standards for that testing on 17 July 2024, and they are specific about tester independence and about the intelligence work that shapes the scenario.
Which UK organisations get pulled in
You are in scope in practice if you are the ICT provider or the group subsidiary, even though DORA is EU law. A payment processor in Milton Keynes serving a Dutch bank will find the obligation arriving through the contract, because the financial entity must include testing participation in its written arrangements and list the provider in its register of information.
Read More: HCP Segmentation for Pharma Success
UK groups with EU subsidiaries face the same pull from the other direction. The domestic picture matters too, since the Bank of England has run CBEST intelligence-led testing for years and the FCA and PRA operational resilience rules required firms to be operating within their impact tolerances by 31 March 2025.
“Most firms I speak to discover DORA through a client questionnaire rather than through their own compliance team, and by then the deadline belongs to the client. Read your financial services contracts now and look for the clause that commits you to support testing, because that clause decides whether your production environment is about to be part of somebody else’s red team exercise.”
William Fieldhouse, Director, Aardwolf Security Ltd

How threat-led testing differs from a standard engagement
Threat-led penetration testing recreates the behaviour of a named adversary against live production systems, using threat intelligence to build the scenario first. A standard test checks an agreed scope for exploitable weaknesses and tells you what it found. The differences are practical. A TLPT runs for months rather than days, and it opens with a targeted threat intelligence report on your firm and sector. Your defending team stays unaware while a small control group manages the risk. Regulators expect that structure, and they expect testers independent of anyone who built or defends the systems. The external network penetration test that most firms buy each year is not a substitute, though it remains the sensible way to keep the perimeter honest between cycles.
What to sort out before your first TLPT
Fix the ordinary problems before paying for a red team, because a threat-led exercise is a poor way to discover that your patching is late. Start with the asset picture. DORA leans on an accurate register of information, and firms that cannot list their critical functions and the providers behind them struggle with everything after that. Then close the routine findings. Regular vulnerability scanning services satisfy the annual requirement in Article 25 and clear the noise that would otherwise waste red team days. Run a scoped internal assessment too, since an attacker who lands a phishing click moves laterally, and that is where most exercises succeed or stall.
Frequently asked questions about DORA and threat-led penetration testing
These questions come up whenever a UK supplier receives its first DORA questionnaire.
Does DORA apply to UK companies?
Not directly, because it is EU law. It reaches UK firms through contracts with in-scope financial entities and through EU subsidiaries, which in commercial terms amounts to the same obligation with a different route.
How long does a threat-led exercise take?
Plan for three to six months from intelligence gathering to closure report. The testing window itself is usually around twelve weeks, with preparation and remediation planning either side of it.
Does an annual penetration test satisfy DORA?
It satisfies part of the programme, no more. Annual assessment covers Article 25, while designated entities still owe advanced testing every three years.
Read More: Multi-LLM Platform: Why Cognis Is Changing the Way We Work with AI
