Skip to content

DORA · DDOS RESILIENCE TESTING

Prove your DDoS resilience in line with DORA

DORA requires financial entities (except microenterprises) to test all ICT systems supporting critical or important functions at least annually. A documented DDoS resilience test satisfies several of the required test types at once.

  • Performance and scenario-based testing under Art. 25(1) DORA
  • Documented, risk-based testing programme — not just an annual pentest
  • Clear evidence for auditors and supervisors
Cypurge eagle, symbol of vigilance

DORA · REGULATION (EU) 2022/2554

ART. 24–25

Verified security & trust Cypurge trust certification Cypurge trust certification Cypurge trust certification Cypurge trust certification

DORA SCOPE

Size is not what decides — your authorisation is

What matters is whether your company belongs to one of the categories listed in Art. 2 DORA. Unlike NIS-2, there are no general size thresholds — but the extent of the obligations follows the principle of proportionality.

Not sure if you are in scope? Ask our experts
01

21 categories

02

No size threshold

03

In force since 17 January 2025

One licence is enough to be in scope

  • Credit institutions
  • Payment & e-money institutions
  • Investment firms
  • AIFMs & UCITS management companies
  • Insurance & reinsurance undertakings
  • Insurance intermediaries
  • IORPs (pension funds)
  • Credit rating agencies
  • Crypto-asset service providers
  • Trading venues
  • Crowdfunding service providers
  • …and more under Art. 2
DDoS resilience testing operations

ART. 24–25

BASIC TESTING PROGRAMME

A DDoS test is not TLPT — the distinction matters

Clients frequently conflate the two. Getting it right saves budget and avoids audit findings.

DDoS resilience test

  • Part of the basic testing programme (Art. 24–25)
  • Applies to every financial entity
  • Annual, risk-based frequency
  • Performance & availability focus
  • Run by Cypurge with your team

TLPT (Art. 26)

  • Threat-led penetration testing
  • Only for entities designated by authorities
  • Every 3 years, on live production systems
  • Red-team focus with TCT involvement
  • Requires qualified external testers
Request your quote

What a Cypurge DDoS resilience test delivers

Realistic attack simulation

Volumetric, protocol and application-layer scenarios tailored to your exposure.

Capacity & performance baseline

Measured breaking points and degradation behaviour of your critical systems.

Documented evidence

A structured report that maps results to Art. 24–25 and DelReg 2024/1774.

Remediation roadmap

Prioritised measures to raise your availability protection.

METHODOLOGY

From scoping to audit-ready evidence

Request your quote Cypurge DORA consulting
  1. 01

    Scoping

    We identify the ICT systems supporting your critical or important functions.

  2. 02

    Test design

    Attack scenarios and load profiles matched to your risk profile.

  3. 03

    Execution

    Controlled DDoS simulation with continuous monitoring and abort criteria.

  4. 04

    Reporting

    Documented results and a remediation roadmap, mapped to DORA.

Frequently asked questions

Does DORA apply to my organisation?

If you hold a licence for one of the 21 categories under Art. 2 DORA, yes — regardless of turnover or headcount.

Is a DDoS test mandatory under DORA?

Not by name. But annual, risk-based tests of all ICT systems that support critical or important functions are mandatory, and a DDoS resilience test covers performance and scenario-based testing particularly cleanly.

Is a DDoS test the same as TLPT?

No. TLPT (Art. 26) is threat-led penetration testing for designated entities every three years. A DDoS resilience test belongs to the basic testing programme under Art. 24–25 and applies to all financial entities except microenterprises.

How often should we test?

At least annually for systems supporting critical or important functions, and proportionate to your risk profile.

Make DORA testing measurable. Start today.

Request your quote for a Cypurge DDoS resilience test, or start with a DORA gap assessment to see where you stand.

DORA · Art. 24–25 · DelReg (EU) 2024/1774

Request your quote

Tell us about your organisation. We will get back to you shortly.

No commitment. Your data is used only to respond to your request.

Request your quote

Request your quote

No commitment. Your data is used only to respond to your request.