
As the European Union’s Digital Operational Resilience Act (DORA) has settled across the financial sector following its introduction in 2025, QA and software testing teams are emerging as key players in ensuring compliance with the regulation’s expanded scope.
Introduced at the start of last year, January 2025, DORA aims to strengthen the operational resilience of banks, insurers, and other financial entities by enforcing uniform standards for ICT risk management, testing, and third-party oversight.
“While financial institutions have previously had to comply with broad EU cybersecurity requirements, DORA raises the bar by introducing even more prescriptive management liability and additional ICT risk management and contracting elements,” according to an August 2025 client alert from law firm Morrison Foerster.
The alert noted that this has caused “a downstream effect, with ICT service providers facing contract remediation and confusion regarding their classification under DORA.”
For QA and testing teams within financial institutions, this shift has turned resilience testing and validation from a best-practice exercise into a regulatory necessity.
Technical standards
The act’s emphasis on testing digital infrastructure under severe conditions requires continuous monitoring, vulnerability scanning, and threat-led penetration testing (TLPT) aligned with the new regulatory technical standards (RTS).
The legal document pointed out that, in 2025, a suite of regulatory technical standards (RTS) came into force, rounding out the regime put in place by the European Supervisory Authorities.”
These RTS, the lawyers added, complete the framework introduced by the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities & Markets Authority (ESMA).
“DORA raises the bar by introducing additional ICT risk management and contracting elements.”
– Morrison Foerster
Among the most notable measures is the RTS on subcontracting ICT services supporting critical or important functions (CIF), which came into effect in July 2025.
The standards “specify the conditions and the criteria to be taken into account by financial entities when subcontracting ICT services supporting CIF throughout the lifecycle of contractual arrangements between financial entities and ICT service providers.”
After the European Commission rejected an earlier draft, the alert pointed out that “the finalised RTS are less rigorous than previously anticipated, in particular, the requirement to monitor subcontracting chains was deemed out of scope of DORA Article 30 and removed.”
Threat-led penetration testing
The RTS on threat-led penetration testing (TLPT), effective 8 July 2025, also tightens expectations around resilience verification.
The regulation “sets out criteria for identifying financial entities required to conduct TLPT, its methodology, scope and process, as well as how it will be supervised,” according to the client alert from law firm Morrison Foerster.
With these provisions now in force, attention has turned to enforcement.
“Financial entities and ICT service providers have likely been digesting these RTS,” the lawyers continued. “Now, interested parties are watching carefully to see how the enforcement regime takes shape.”
The European Commission has yet to publish the list of ICT service providers deemed “critical” under DORA, a designation that will trigger direct regulatory oversight by the European Supervisory Authorities.
“Critical ICT service providers will be subject to a regulatory oversight regime,” the alert stated.
For software testing professionals, the regulation’s operational demands are profound. Under DORA, financial institutions must demonstrate that their QA, monitoring, and recovery capabilities are not only functional but repeatable and independently verifiable.
The new threat-led penetration testing rules, in particular, position QA teams at the forefront of compliance, requiring them to coordinate with regulators, risk officers, and ICT vendors to simulate sophisticated attack scenarios and report measurable outcomes.
COMING IN 2026


Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- AI adoption strains JPMorgan testing
- Can banks ‘outsource’ AI accountability?
- HDFC Bank raises testing stakes
- Is observability banking QA’s next discipline?
- Barclays on AI testing, telemetry and kill switches
WATCH NOW

QA FINANCIAL PODCASTS



