Basic testing programme
Every financial entity must test all ICT systems supporting critical or important functions at least annually. Art. 25(1) explicitly names performance testing, end-to-end testing, scenario-based tests and network security assessments — a DDoS load and resilience test is a performance plus scenario-based test.