DORA · Article 44

Threat-led penetration testing

Summary

Financial entities identified by competent authorities shall carry out threat-led penetration testing on their critical or important functions at least every three years.

threat ledpenetration testinglive systemscritical functions

Read the full official text: https://eur-lex.europa.eu/eli/reg/2022/2554/oj

Track DORA article 44 as evidence

eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.

Start free trial