Skip to content

DORA · DDOS RESILIENCE TESTING

DORA: prove your resilience against DDoS attacks

DORA requires every financial entity to test all ICT systems supporting critical or important functions at least once a year. A documented DDoS resilience test is one of the cleanest ways to satisfy several obligations at once.

  • Performance & scenario-based testing under Art. 25(1)
  • Documented, risk-based testing programme — not just an annual pentest
  • Clear evidence for auditors and supervisors
Cypurge eagle, symbol of vigilance

DORA · REGULATION (EU) 2022/2554

ART. 24–25

Verified security & trust Cypurge trust certification Cypurge trust certification Cypurge trust certification Cypurge trust certification

DORA SCOPE

DORA does not look at your size — it looks at your licence

Unlike NIS-2, DORA does not key off turnover, balance sheet total or headcount. It keys off entity type under Art. 2 DORA, with 21 categories of financial entities. If you hold the corresponding licence, you are in scope — regardless of size.

Not sure if you are in scope? Ask our experts
01

21 entity categories

02

Art. 2 DORA scope

03

In force since 17 Jan. 2025

One licence is enough to be in scope

  • Credit institutions
  • Payment & e-money institutions
  • Investment firms
  • AIFMs & UCITS ManCos
  • Insurance & reinsurance undertakings
  • Insurance intermediaries
  • IORPs (pension funds)
  • Credit rating agencies
  • Crypto-asset service providers
  • Trading venues
  • Crowdfunding service providers
  • …and more under Art. 2
DDoS resilience testing operations

ART. 24–25

BASIC TESTING PROGRAMME

A DDoS test is not TLPT — the distinction matters

Clients frequently conflate the two. Getting it right saves budget and avoids audit findings.

DDoS resilience test

  • Part of the basic testing programme (Art. 24–25)
  • Applies to every financial entity
  • Annual, risk-based frequency
  • Performance & availability focus
  • Run by Cypurge with your team

TLPT (Art. 26)

  • Threat-led penetration testing
  • Only for entities designated by authorities
  • Every 3 years, on live production systems
  • Red-team focus with TCT involvement
  • Requires qualified external testers
Request your quote

What a Cypurge DDoS resilience test delivers

Realistic attack simulation

Volumetric, protocol and application-layer scenarios tailored to your exposure.

Capacity & performance baseline

Measured breaking points and degradation behaviour of your critical systems.

Documented evidence

A structured report that maps results to Art. 24–25 and DelReg 2024/1774.

Remediation roadmap

Prioritised measures to raise your availability protection.

METHODOLOGY

From scoping to audit-ready evidence

Request your quote Cypurge DORA consulting
  1. 01

    Scoping

    We identify the ICT systems supporting your critical or important functions.

  2. 02

    Test design

    Attack scenarios and load profiles matched to your risk profile.

  3. 03

    Execution

    Controlled DDoS simulation with continuous monitoring and abort criteria.

  4. 04

    Reporting

    Documented results and a remediation roadmap, mapped to DORA.

Frequently asked questions

Does DORA apply to my organisation?

If you hold a licence for one of the 21 entity categories under Art. 2 DORA, yes — regardless of your turnover or headcount.

Is a DDoS test mandatory under DORA?

Not by name. But annual, risk-based testing of all critical ICT systems is mandatory, and a DDoS resilience test is one of the cleanest ways to cover performance and scenario-based testing.

Is a DDoS test the same as TLPT?

No. TLPT (Art. 26) is threat-led penetration testing for designated entities every three years. A DDoS resilience test belongs to the basic testing programme under Art. 24–25 and applies to everyone.

How often should we test?

At least annually for systems supporting critical or important functions, and proportionate to your risk profile.

Make DORA testing measurable. Start today.

Request your quote for a Cypurge DDoS resilience test, or start with a DORA gap assessment to see where you stand.

DORA · Art. 24–25 · DelReg (EU) 2024/1774

Request your quote

Tell us about your organisation. We will get back to you shortly.

No commitment. Your data is used only to respond to your request.

Request your quote

Request your quote

No commitment. Your data is used only to respond to your request.