DORA (Digital Operational Resilience Act) is EU financial-sector regulation: it mandates regular ICT testing for all in-scope entities and Threat-Led Penetration Testing (TLPT) — intelligence-led red teaming on the TIBER-EU framework, roughly every three years — for entities their authority designates significant. NIS2 is a broader EU directive across many essential/important sectors: it requires risk-based security testing and assessment of control effectiveness, but doesn't prescribe a fixed test type. So DORA is narrower and more prescriptive about advanced testing; NIS2 is wider and more risk-based. GCC firms are typically reached through an EU entity, subsidiary or supply-chain relationship. Comparison table and action steps below. For the deeper TLPT mechanics see DORA TLPT requirements.
// 01 What each regime is
They're often mentioned together, but they're different instruments. DORA is a regulation — directly applicable, sector-specific — that governs the digital operational resilience of the EU financial sector: banks, insurers, investment firms, payment institutions, crypto-asset providers, and critical ICT third parties serving them. NIS2 is a directive — transposed into each member state's national law — that raises cybersecurity requirements across a broad set of “essential” and “important” sectors: energy, transport, health, digital infrastructure, public administration, manufacturing and more. Where a financial entity could fall under both, DORA generally takes precedence for the financial-specific requirements as the more specialised regime.
// 02 The testing requirements, side by side
| Dimension | NIS2 | DORA |
|---|---|---|
| Type | Directive (national transposition) | Regulation (directly applicable) |
| Who | Many essential/important sectors | EU financial entities & critical ICT providers |
| Testing basis | Risk-based; assess control effectiveness | Regular ICT testing for all in-scope |
| Advanced testing | Not a prescribed TLPT-style exercise | TLPT for significant entities |
| TLPT framework | — | TIBER-EU based, authority-overseen |
| Advanced cadence | Set by risk / national law | TLPT approx. every 3 years |
| Prescriptiveness | Broad, principles-led | Narrow, detailed |
// 03 What NIS2 expects for testing
NIS2 doesn't hand you a test-type and a frequency. Instead it requires in-scope entities to run cybersecurity risk-management measures, explicitly including policies and procedures to assess the effectiveness of those measures. Read plainly, that means a documented, risk-based testing programme: regular vulnerability assessment and penetration testing proportionate to your risk profile, feeding into how you measure whether controls actually work. Because member states transpose NIS2 into national law, the precise expectation varies by country — but the baseline everywhere is that you can show a deliberate testing cadence tied to risk, not an ad-hoc scan when someone remembers. Governance and management accountability are also emphasised, so testing that informs the board matters.
// 04 What DORA expects — and TLPT
DORA is far more specific. Every in-scope financial entity must run a regular programme of ICT testing — vulnerability assessments, scans, and penetration tests appropriate to their systems. On top of that, entities their competent authority identifies as significant must perform Threat-Led Penetration Testing (TLPT): a realistic, intelligence-led red-team exercise against live production critical functions, built on the TIBER-EU framework, using qualified testers and threat-intelligence providers, and overseen by authorities — roughly every three years. TLPT is a serious, months-long undertaking closer to an adversary-simulation red team than a standard pentest. The full mechanics are in DORA TLPT requirements. Note: not every DORA firm does TLPT — but every DORA firm does regular testing.
// 05 How this reaches GCC firms
“EU regulation” doesn't mean “not my problem” in the Gulf. Three routes bring these regimes to GCC organisations. First, an EU entity or subsidiary: a GCC banking or insurance group with an EU-authorised entity can pull that entity into DORA, TLPT included. Second, the supply chain: if you provide services to EU essential/important entities (NIS2) or to EU financial firms (DORA's third-party provisions), those obligations arrive as contractual supplier requirements. Third, customer expectation: EU counterparties increasingly ask for evidence aligned to these regimes even where they don't strictly apply. The practical move is to map your EU footprint and customer base, decide which regime touches which entity, and test accordingly — often alongside your local SAMA or CBB obligations, which share DNA with DORA's resilience-and-red-teaming approach.
// 06 Frequently asked questions
What's the difference between NIS2 and DORA for pentesting?
DORA is financial-sector-specific and mandates regular ICT testing plus, for significant entities, Threat-Led Penetration Testing (TLPT) — intelligence-driven red teaming on the TIBER-EU framework, roughly every three years. NIS2 is a broader directive across many sectors requiring risk-based testing and assessment of control effectiveness, without prescribing a TLPT-style exercise. DORA is narrower and more prescriptive; NIS2 wider and more risk-based.
Does NIS2 require penetration testing?
It requires risk-management measures including procedures to assess the effectiveness of cybersecurity measures — which in practice means regular vulnerability assessment and penetration testing proportionate to risk, even though no fixed test type or frequency is named. Member states transpose it into national law, so exact expectations vary, but a documented risk-based testing programme is the baseline.
What is DORA TLPT and who has to do it?
TLPT is DORA's advanced requirement: a realistic, intelligence-led red-team exercise against live production, built on TIBER-EU and authority-overseen. It applies to financial entities designated significant by their competent authority — not every DORA firm — approximately every three years. All DORA entities still perform the broader regular testing.
Do NIS2 and DORA affect GCC companies?
They can, via EU operations, subsidiaries or supply-chain relationships. A GCC group with an EU financial entity may face DORA and TLPT; a supplier to EU essential/important entities may face NIS2 as contractual requirements. Even where they don't apply directly, EU customers increasingly ask for aligned evidence. Map your EU footprint and customers, and test accordingly.
// 07 Related reading
- DORA TLPT requirements — the threat-led testing mechanics in depth.
- Red team vs pen test and SAMA red teaming.
- Pentest requirements by framework and the requirements finder.