EU Regulation 2022/2554

DDactic for DORA Compliance

DORA Article 25 mandates network security assessments, penetration testing, and scenario-based attack tests for EU financial entities. DDactic delivers all three, with an OPI Validated score as audit-ready evidence.

What DORA Requires

The Digital Operational Resilience Act (EU Regulation 2022/2554) entered into force on 17 January 2025. It applies to virtually all financial entities operating in the EU and sets binding requirements for ICT resilience testing, including active attack simulation.

"Financial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework."

DORA Article 24(1)

"The testing programme referred to in Article 24 shall include... vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing."

DORA Article 25(1)

"Threat-led penetration testing shall cover several or all critical or important functions of a financial entity and shall be performed on live production systems supporting such functions."

DORA Article 26(2)

The European Supervisory Authorities (ESAs) published Regulatory Technical Standards (RTS) under DORA that explicitly list DDoS simulation as a required scenario in Threat-Led Penetration Testing (TLPT) for significant financial entities.

How DDactic Satisfies DORA Requirements

DDactic maps directly to the test types enumerated in Article 25 and the TLPT scenarios required under Article 26.

DORA Requirement Article / RTS DDactic Coverage
Network security assessment Art. 25(1) Passive recon pipeline: CDN presence, WAF vendor, origin IP exposure, open ports, TLS configuration across all discovered subdomains
Vulnerability assessments and scans Art. 25(1) Identifies DDoS-relevant vulnerabilities: unprotected origins, rate-limit gaps, HTTP/2 Rapid Reset exposure, QUIC attack surface
Penetration testing Art. 25(1) Active L3/L4/L7 DDoS simulation from a 24-provider bot fleet using 213+ attack vectors against live production systems
Scenario-based tests Art. 25(1) Pre-built attack scenarios: SYN flood, HTTP flood, cache bypass, Slowloris, DNS amplification, QUIC flooding, and more; all configurable per scope
Performance testing Art. 25(1) OPI Operational Resilience component measures availability degradation, latency increase, and false positive rate under sustained attack load
TLPT DDoS scenario Art. 26 + ESA RTS Full OPI Validated assessment with attacker-perspective origin discovery included; produces TLPT-compatible evidence artifact (score + PDF report)
Attack surface discovery Art. 26(2) (live systems) 13-source recon pipeline discovers all exposed subdomains, origin IPs behind CDN, and API endpoints before simulation begins
Hardening and remediation Art. 25(3) (follow-up) Vendor-specific hardening commands for Cloudflare, Akamai, Imperva, AWS Shield, and Azure DDoS Protection; not a generic PDF

Evidence DDactic Produces

DORA requires financial entities to document their testing programme and results. DDactic generates audit-ready artifacts at the conclusion of every assessment.

73 C OPI Validated Score

The OPI Validated score is a 0-100 composite index across six weighted components: Defense Coverage, L7 Resilience, L3/L4 Resilience, Protocol Resilience, Operational Resilience, and Evasion Resistance.

It is calculated from active attack test results, not passive estimates, and can be presented to auditors as a quantified measure of DDoS resilience at a point in time.

  • 📄PDF Assessment ReportFull methodology, test scope, results per vector, and component score breakdown with timestamps
  • 🛠Vendor-Specific Hardening StepsCLI commands and configuration changes specific to your CDN, WAF, and scrubbing provider
  • 📋Attack Surface InventoryAll discovered subdomains, origin IPs, and exposed assets mapped before testing began
  • 📅Timestamped Retest EvidenceRerun after remediation to produce a before/after OPI score delta for auditors

Who Must Comply with DORA

DORA applies to a broad range of financial entities operating in the EU. Article 2 lists over 20 entity types.

Banks and credit institutions Investment firms Insurance and reinsurance undertakings Payment institutions Electronic money institutions Crypto-asset service providers Central counterparties Trading venues Credit rating agencies ICT third-party service providers (critical) Fund managers (UCITS, AIFMs) Pension institutions

Article 26 TLPT requirements apply to significant entities designated by the competent authority. Basic testing under Article 25 applies to all entities, with proportionality based on size and risk profile.

Why an Independent Tool Matters

Vendor-Neutral Scoring

OPI is an open standard (Apache 2.0) not tied to DDactic's commercial interests. The same methodology can be implemented by any tool, giving auditors confidence the score is not self-graded.

Attacker's Perspective

DORA Article 26 requires testing from a threat actor's vantage point. DDactic starts from your company name, discovers the full attack surface including CDN bypass paths, and simulates what an actual DDoS attacker would target.

Repeatable and Documented

The same scope and methodology can be re-run after remediation, producing a documented before/after record. DORA requires annual testing; DDactic supports continuous retesting at any frequency.

Get DORA-Ready Evidence in 48 Hours

Start with a free passive scan of your attack surface. Upgrade to OPI Validated for a full report suitable for your DORA testing programme documentation.

Run Free Scan

Other compliance frameworks: NIS2 · PCI DSS 4.0 · ISO 27001 · SOC 2 · All standards