DORA — Articles 24 & 25
EU financial entities, excluding microenterprises
The requirement
A documented testing programme covering every ICT system supporting a critical or important function, exercised at least once a year — vulnerability assessment, network security review, source code analysis and scenario-based testing among them.
What we deliver
We run the annual programme and produce the evidence: scope rationale, methodology, findings, remediation tracking and retest.
This is the Article 24/25 testing programme. The separate Article 26/27 threat-led testing regime requires an accredited provider, which we are not — if you are in scope for TLPT we will tell you so and point you at a firm that is.