DORA tabletop exercises: tested response capability is the evidence that counts
DORA, Regulation (EU) 2022/2554, has applied to financial entities and critical ICT third-party providers since 17 January 2025. It demands more than plans for the ICT worst case: it demands digital operational resilience testing, and a reporting chain whose first deadline sits at four hours. A documented crisis exercise is the most tangible proof that your response capability has actually been tested.
Who falls under DORA, and who does not
DORA is sector regulation in the strictest sense: it applies exclusively to financial entities and critical ICT third-party providers. For every other industry, NIS2 sets the bar.
As an EU regulation, DORA applies directly: no national transposition law, no national leeway on the core duties. Whether your organisation counts as a financial entity follows from the regulation itself; if in doubt, that classification belongs at the start of any resilience project, not at its end. What is certain: for those in scope, the duties are already live, there has been no grace period since 17 January 2025.
Financial entities
The core of the scope: financial-sector firms covered by the regulation. For them, the DORA duties apply in full, from ICT risk management through the reporting chain to digital operational resilience testing.
Critical ICT third-party providers
DORA does not stop at the company boundary: critical ICT third-party providers are covered too. Providing critical services to financial entities puts you inside the regulation's focus, not merely inside your customers' contracts.
Applicable since 17 January 2025: the clock has long been running
Unlike NIS2, DORA never waited for national transposition: the regulation has applied since 17 January 2025. If you cannot evidence tested response capability today, you are not working towards an upcoming deadline, you are behind a duty that already applies. The difference is more than rhetorical: at the next supervisory enquiry, what counts is what is on file.
The DORA reporting chain: 4 h / 24 h / 72 h / 1 month
For major ICT-related incidents, DORA requires a three-stage report to the competent authority. The deadlines are specified by regulatory technical standard RTS (EU) 2025/301, and the first one is tighter than most crisis plans assume.
The most delicate decision comes first, and it is not a technical one: is this incident major? That classification starts the four-hour clock, and it lands in the most chaotic phase of the crisis, while the same team is isolating systems, checking payment flows and calming customers. A team that faces the classification question for the first time in a real incident answers it too late.
That is exactly what a Verdus exercise rehearses: the banking scenario confronts your crisis team with the classification call and the initial-report window under time pressure, every decision is captured with a timestamp, and the debrief shows in black and white whether your initial report would have made the four-hour window.
Testing is a core duty, not a recommendation
DORA requires digital operational resilience testing, including scenario-based tests and, at the demanding end, threat-led penetration testing (TLPT).
The same honesty applies here as everywhere on this page: DORA does not prescribe a tabletop exercise with any particular tool, and a tabletop exercise replaces neither a TLPT nor technical testing. What the regulation demands is tested resilience: not only systems but the organisation's response capability has to prove itself under realistic conditions, scenario-based tests included.
That is where the crisis exercise comes in. It tests the layer no pentest reaches: does your crisis team classify the incident as major in time? Does the initial report make the four-hour window? Do fraud, legal, treasury and communications decide on one cadence, or on four? A documented exercise turns the claim of being response-ready into managed evidence: with dates, decisions, times and findings.
How a Verdus exercise pays into DORA
Five building blocks turn an exercise hour into defensible DORA evidence. All five are built into Verdus Cyber.
And NIS2? In finance, DORA takes precedence.
For financial entities, DORA is the more specific regime, lex specialis: where DORA applies, it sets the bar for ICT risk management, incident reporting and resilience testing. For every other sector, NIS2 and its national transpositions remain the reference, with their own reporting chain (early warning within 24 h, incident notification within 72 h, final report after 1 month) and personal duties for the management body.
If you are not only financial sector (say, a group with entities across several industries), our NIS2 guide is worth a look: same exercise logic, different reporting chain.
Read the NIS2 guideFrequently asked questions
Does DORA mandate tabletop exercises?
Not literally, and we do not claim it does. DORA requires digital operational resilience testing, including scenario-based tests (Articles 25/26). A documented crisis exercise is the most practicable way to test your organisation's response capability scenario-based and to make that test evidenceable. The exercise is the path to evidence, not the letter of the law.
Does a tabletop exercise replace a TLPT?
No. A threat-led penetration test probes your technical defences against real attack techniques; a crisis exercise tests your crisis team's ability to decide and report. These are different layers of the testing programme: the exercise complements technical tests, it does not replace them.
Does DORA or NIS2 apply to us?
DORA applies exclusively to financial entities and critical ICT third-party providers; every other sector falls under NIS2 and its national transpositions. For the financial sector, DORA is the more specific regime. If in doubt, we clarify the classification in the first call.
Read the NIS2 guideWhen does the four-hour deadline for the initial report start?
With your own classification of the incident as major, at the latest 24 hours after becoming aware of it. That makes the classification call the most critical moment of the reporting chain: it falls under maximum uncertainty and cannot be delegated away. This is precisely the decision an exercise rehearses and documents with a timestamp.
What does the debrief deliver as DORA evidence?
A timeline with decision timestamps, scoring across eight competencies, and a framework mapping that covers DORA alongside NIST CSF, ISO 27001 and MITRE ATT&CK. Participants, scenario, decisions and findings are documented: usable towards supervisors, auditors and your own board.
See the debriefWhat does a DORA tabletop exercise cost?
Honest answer: it depends on format and depth, self-moderated, specialist-led or through the partner programme. The three delivery models are on our pricing page; we give you a realistic range in the first call, not after three workshops.
See pricingMake your DORA testing duty exercise-proof.
In thirty minutes we will show you what a DORA-ready exercise looks like for your institution: banking scenario, four-hour reporting chain, debrief evidence.