DDactic for DORA Compliance
DORA Article 25 mandates network security assessments, penetration testing, and scenario-based attack tests for EU financial entities. DDactic delivers all three, with an OPI Validated score as audit-ready evidence.
What DORA Requires
The Digital Operational Resilience Act (EU Regulation 2022/2554) entered into force on 17 January 2025. It applies to virtually all financial entities operating in the EU and sets binding requirements for ICT resilience testing, including active attack simulation.
"Financial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework."
DORA Article 24(1)"The testing programme referred to in Article 24 shall include... vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing."
DORA Article 25(1)"Threat-led penetration testing shall cover several or all critical or important functions of a financial entity and shall be performed on live production systems supporting such functions."
DORA Article 26(2)The European Supervisory Authorities (ESAs) published Regulatory Technical Standards (RTS) under DORA that explicitly list DDoS simulation as a required scenario in Threat-Led Penetration Testing (TLPT) for significant financial entities.
How DDactic Satisfies DORA Requirements
DDactic maps directly to the test types enumerated in Article 25 and the TLPT scenarios required under Article 26.
| DORA Requirement | Article / RTS | DDactic Coverage |
|---|---|---|
| Network security assessment | Art. 25(1) | Passive recon pipeline: CDN presence, WAF vendor, origin IP exposure, open ports, TLS configuration across all discovered subdomains |
| Vulnerability assessments and scans | Art. 25(1) | Identifies DDoS-relevant vulnerabilities: unprotected origins, rate-limit gaps, HTTP/2 Rapid Reset exposure, QUIC attack surface |
| Penetration testing | Art. 25(1) | Active L3/L4/L7 DDoS simulation from a 24-provider bot fleet using 213+ attack vectors against live production systems |
| Scenario-based tests | Art. 25(1) | Pre-built attack scenarios: SYN flood, HTTP flood, cache bypass, Slowloris, DNS amplification, QUIC flooding, and more; all configurable per scope |
| Performance testing | Art. 25(1) | OPI Operational Resilience component measures availability degradation, latency increase, and false positive rate under sustained attack load |
| TLPT DDoS scenario | Art. 26 + ESA RTS | Full OPI Validated assessment with attacker-perspective origin discovery included; produces TLPT-compatible evidence artifact (score + PDF report) |
| Attack surface discovery | Art. 26(2) (live systems) | 13-source recon pipeline discovers all exposed subdomains, origin IPs behind CDN, and API endpoints before simulation begins |
| Hardening and remediation | Art. 25(3) (follow-up) | Vendor-specific hardening commands for Cloudflare, Akamai, Imperva, AWS Shield, and Azure DDoS Protection; not a generic PDF |
Evidence DDactic Produces
DORA requires financial entities to document their testing programme and results. DDactic generates audit-ready artifacts at the conclusion of every assessment.
The OPI Validated score is a 0-100 composite index across six weighted components: Defense Coverage, L7 Resilience, L3/L4 Resilience, Protocol Resilience, Operational Resilience, and Evasion Resistance.
It is calculated from active attack test results, not passive estimates, and can be presented to auditors as a quantified measure of DDoS resilience at a point in time.
- 📄PDF Assessment ReportFull methodology, test scope, results per vector, and component score breakdown with timestamps
- 🛠Vendor-Specific Hardening StepsCLI commands and configuration changes specific to your CDN, WAF, and scrubbing provider
- 📋Attack Surface InventoryAll discovered subdomains, origin IPs, and exposed assets mapped before testing began
- 📅Timestamped Retest EvidenceRerun after remediation to produce a before/after OPI score delta for auditors
Who Must Comply with DORA
DORA applies to a broad range of financial entities operating in the EU. Article 2 lists over 20 entity types.
Article 26 TLPT requirements apply to significant entities designated by the competent authority. Basic testing under Article 25 applies to all entities, with proportionality based on size and risk profile.
Why an Independent Tool Matters
Vendor-Neutral Scoring
OPI is an open standard (Apache 2.0) not tied to DDactic's commercial interests. The same methodology can be implemented by any tool, giving auditors confidence the score is not self-graded.
Attacker's Perspective
DORA Article 26 requires testing from a threat actor's vantage point. DDactic starts from your company name, discovers the full attack surface including CDN bypass paths, and simulates what an actual DDoS attacker would target.
Repeatable and Documented
The same scope and methodology can be re-run after remediation, producing a documented before/after record. DORA requires annual testing; DDactic supports continuous retesting at any frequency.
Other compliance frameworks: NIS2 · PCI DSS 4.0 · ISO 27001 · SOC 2 · All standards