Operational resilience regulation increasingly expects more than a written plan. Testing should identify weaknesses, create evidence and lead to corrective action.

DORA: a programme, not a one-off event

The EU Digital Operational Resilience Act requires many financial entities to establish and maintain a risk-based digital operational resilience testing programme. Article 24 focuses on preparedness, weaknesses, deficiencies and gaps, while Article 25 identifies scenario-based and end-to-end tests among the available approaches.

Read the official text in Regulation (EU) 2022/2554. Legal obligations vary by entity and jurisdiction; this article is not legal advice.

NIS2 implementation: test procedures and involve the organisation

ENISA's 2025 technical implementation guidance recommends testing incident-response procedures at planned intervals, using different incident types and involving different departments and relevant external stakeholders. It also highlights management participation where necessary, post-test review and procedure updates.

That combination matters. A cyber incident does not respect organisational boundaries, so a credible test should include the people who own business continuity, legal assessment, communications, suppliers and leadership decisions.

What evidence should an exercise produce?

  • Exercise objectives mapped to relevant risks and obligations
  • A record of injects, decisions, actions and simulated time
  • Evidence of participation across required functions
  • Findings linked to expected procedures or obligations
  • Prioritised remediation with accountable owners
  • A retest plan for material weaknesses

Scenario realism should support evaluation

Realism is useful when it changes behaviour or reveals a control gap. A regulatory clock, customer impact or supplier dependency should create a decision that can be observed—not simply add drama.

From compliance activity to resilience evidence

A well-designed exercise can support regulatory readiness while improving the organisation. The critical shift is from documenting participation to demonstrating how the organisation performed, what changed afterward and whether the weakness was successfully retested.

For supervisory context, ENISA's Handbook for Cyber Stress Tests provides guidance for authorities overseeing resilience in critical sectors.

COMMON QUESTIONS

Frequently asked questions

Does DORA require digital operational resilience testing?

Yes. DORA establishes a digital operational resilience testing programme for in-scope financial entities, with requirements proportionate to risk and entity maturity.

What does ENISA guidance say about incident-response testing?

ENISA guidance recommends planned testing of incident-response procedures, varied scenarios, cross-department participation, management involvement where needed and post-test lessons learned.

Is an exercise alone enough for compliance?

No single exercise proves compliance. Organisations should map tests, evidence, remediation and governance to their specific legal and supervisory obligations.