Compliance · DORA

DORA tabletop exercises: tested response capability is the evidence that counts

DORA, Regulation (EU) 2022/2554, has applied to financial entities and critical ICT third-party providers since 17 January 2025. It demands more than plans for the ICT worst case: it demands digital operational resilience testing, and a reporting chain whose first deadline sits at four hours. A documented crisis exercise is the most tangible proof that your response capability has actually been tested.

17 Jan 2025
DORA applicable, financial sector only
Regulation (EU) 2022/2554
4 h
initial report after classification as major, at the latest 24 h after awareness
RTS (EU) 2025/301
72 h
intermediate report, final report after 1 month
RTS (EU) 2025/301
Art. 25/26
digital operational resilience testing, incl. scenario-based tests
Regulation (EU) 2022/2554
Scope

Who falls under DORA, and who does not

DORA is sector regulation in the strictest sense: it applies exclusively to financial entities and critical ICT third-party providers. For every other industry, NIS2 sets the bar.

As an EU regulation, DORA applies directly: no national transposition law, no national leeway on the core duties. Whether your organisation counts as a financial entity follows from the regulation itself; if in doubt, that classification belongs at the start of any resilience project, not at its end. What is certain: for those in scope, the duties are already live, there has been no grace period since 17 January 2025.

Group A

Financial entities

The core of the scope: financial-sector firms covered by the regulation. For them, the DORA duties apply in full, from ICT risk management through the reporting chain to digital operational resilience testing.

Group B

Critical ICT third-party providers

DORA does not stop at the company boundary: critical ICT third-party providers are covered too. Providing critical services to financial entities puts you inside the regulation's focus, not merely inside your customers' contracts.

Status 2026

Applicable since 17 January 2025: the clock has long been running

Unlike NIS2, DORA never waited for national transposition: the regulation has applied since 17 January 2025. If you cannot evidence tested response capability today, you are not working towards an upcoming deadline, you are behind a duty that already applies. The difference is more than rhetorical: at the next supervisory enquiry, what counts is what is on file.

RTS (EU) 2025/301

The DORA reporting chain: 4 h / 24 h / 72 h / 1 month

For major ICT-related incidents, DORA requires a three-stage report to the competent authority. The deadlines are specified by regulatory technical standard RTS (EU) 2025/301, and the first one is tighter than most crisis plans assume.

Stage
Deadline
What it means in practice
Initial report
4 h after classification as major, at the latest 24 h after awareness
The clock starts with your own classification decision. Dragging out the classification buys no time: the 24-hour ceiling from awareness runs in parallel.
Intermediate report
at 72 h
The situation has moved on: the authority expects an updated picture while containment and recovery are still in progress.
Final report
after 1 month
The conclusive account of the incident, built from what was actually logged during the crisis. What went undocumented is close to impossible to reconstruct a month later.

The most delicate decision comes first, and it is not a technical one: is this incident major? That classification starts the four-hour clock, and it lands in the most chaotic phase of the crisis, while the same team is isolating systems, checking payment flows and calming customers. A team that faces the classification question for the first time in a real incident answers it too late.

That is exactly what a Verdus exercise rehearses: the banking scenario confronts your crisis team with the classification call and the initial-report window under time pressure, every decision is captured with a timestamp, and the debrief shows in black and white whether your initial report would have made the four-hour window.

Articles 25/26

Testing is a core duty, not a recommendation

DORA requires digital operational resilience testing, including scenario-based tests and, at the demanding end, threat-led penetration testing (TLPT).

The same honesty applies here as everywhere on this page: DORA does not prescribe a tabletop exercise with any particular tool, and a tabletop exercise replaces neither a TLPT nor technical testing. What the regulation demands is tested resilience: not only systems but the organisation's response capability has to prove itself under realistic conditions, scenario-based tests included.

That is where the crisis exercise comes in. It tests the layer no pentest reaches: does your crisis team classify the incident as major in time? Does the initial report make the four-hour window? Do fraud, legal, treasury and communications decide on one cadence, or on four? A documented exercise turns the claim of being response-ready into managed evidence: with dates, decisions, times and findings.

In practice

How a Verdus exercise pays into DORA

Five building blocks turn an exercise hour into defensible DORA evidence. All five are built into Verdus Cyber.

01A banking scenario on the DORA clockSWIFT compromise and data exfiltration: your crisis team classifies the incident, drafts the initial report inside the exercise window, and keeps payments, fraud investigation and market communication on track at once.
02Reporting-chain injectsThe 4 h / 24 h / 72 h / 1 month deadlines are built in as dedicated injects: your team decides under time pressure whether, when and what to report, exactly as in a real incident.
03Realistic pressure65+ injects across 20+ categories: from the SIEM alert to the journalist's enquiry and the customer with a drained account. The exercise escalates live in the browser: phones ring, the clock runs.
04Decision timestampsEvery decision is captured with a timestamp: who, when, on what basis. Whether the classification came in time is no longer a matter of memory: it is a line in the timeline.
05A debrief with DORA mappingThe debrief scores every decision across eight competencies and maps the results to frameworks: alongside NIST CSF, ISO 27001 and MITRE ATT&CK, explicitly including DORA. The exercise becomes a report that fits your testing and evidence documentation.
Scope note

And NIS2? In finance, DORA takes precedence.

For financial entities, DORA is the more specific regime, lex specialis: where DORA applies, it sets the bar for ICT risk management, incident reporting and resilience testing. For every other sector, NIS2 and its national transpositions remain the reference, with their own reporting chain (early warning within 24 h, incident notification within 72 h, final report after 1 month) and personal duties for the management body.

If you are not only financial sector (say, a group with entities across several industries), our NIS2 guide is worth a look: same exercise logic, different reporting chain.

Read the NIS2 guide
FAQ

Frequently asked questions

Does DORA mandate tabletop exercises?

Not literally, and we do not claim it does. DORA requires digital operational resilience testing, including scenario-based tests (Articles 25/26). A documented crisis exercise is the most practicable way to test your organisation's response capability scenario-based and to make that test evidenceable. The exercise is the path to evidence, not the letter of the law.

Does a tabletop exercise replace a TLPT?

No. A threat-led penetration test probes your technical defences against real attack techniques; a crisis exercise tests your crisis team's ability to decide and report. These are different layers of the testing programme: the exercise complements technical tests, it does not replace them.

Does DORA or NIS2 apply to us?

DORA applies exclusively to financial entities and critical ICT third-party providers; every other sector falls under NIS2 and its national transpositions. For the financial sector, DORA is the more specific regime. If in doubt, we clarify the classification in the first call.

Read the NIS2 guide

When does the four-hour deadline for the initial report start?

With your own classification of the incident as major, at the latest 24 hours after becoming aware of it. That makes the classification call the most critical moment of the reporting chain: it falls under maximum uncertainty and cannot be delegated away. This is precisely the decision an exercise rehearses and documents with a timestamp.

What does the debrief deliver as DORA evidence?

A timeline with decision timestamps, scoring across eight competencies, and a framework mapping that covers DORA alongside NIST CSF, ISO 27001 and MITRE ATT&CK. Participants, scenario, decisions and findings are documented: usable towards supervisors, auditors and your own board.

See the debrief

What does a DORA tabletop exercise cost?

Honest answer: it depends on format and depth, self-moderated, specialist-led or through the partner programme. The three delivery models are on our pricing page; we give you a realistic range in the first call, not after three workshops.

See pricing

Make your DORA testing duty exercise-proof.

In thirty minutes we will show you what a DORA-ready exercise looks like for your institution: banking scenario, four-hour reporting chain, debrief evidence.