Blog · M.12 · Compliance

NIS2 vs DORA: penetration testing compared

Two EU regimes, two very different testing bars. DORA is narrow and prescriptive — financial sector, with intelligence-led TLPT red teaming for significant firms. NIS2 is wide and risk-based — many sectors, with testing scaled to risk rather than a fixed exercise. If your group has any EU footprint, one or both may reach you. Here's who each applies to, exactly what testing it wants, and what to do about it.

NIS2DORATLPTTIBER-EUEU Regulation
In brief: DORA = Financial + TLPT Every ~3 Years · NIS2 = Many Sectors + Risk-based Testing · TLPT Built on TIBER-EU · GCC Firms Reached via EU Footprint In brief: DORA = Financial + TLPT Every ~3 Years · NIS2 = Many Sectors + Risk-based Testing · TLPT Built on TIBER-EU · GCC Firms Reached via EU Footprint
// TL;DR

DORA (Digital Operational Resilience Act) is EU financial-sector regulation: it mandates regular ICT testing for all in-scope entities and Threat-Led Penetration Testing (TLPT) — intelligence-led red teaming on the TIBER-EU framework, roughly every three years — for entities their authority designates significant. NIS2 is a broader EU directive across many essential/important sectors: it requires risk-based security testing and assessment of control effectiveness, but doesn't prescribe a fixed test type. So DORA is narrower and more prescriptive about advanced testing; NIS2 is wider and more risk-based. GCC firms are typically reached through an EU entity, subsidiary or supply-chain relationship. Comparison table and action steps below. For the deeper TLPT mechanics see DORA TLPT requirements.

// 01 What each regime is

They're often mentioned together, but they're different instruments. DORA is a regulation — directly applicable, sector-specific — that governs the digital operational resilience of the EU financial sector: banks, insurers, investment firms, payment institutions, crypto-asset providers, and critical ICT third parties serving them. NIS2 is a directive — transposed into each member state's national law — that raises cybersecurity requirements across a broad set of “essential” and “important” sectors: energy, transport, health, digital infrastructure, public administration, manufacturing and more. Where a financial entity could fall under both, DORA generally takes precedence for the financial-specific requirements as the more specialised regime.

// 02 The testing requirements, side by side

DimensionNIS2DORA
TypeDirective (national transposition)Regulation (directly applicable)
WhoMany essential/important sectorsEU financial entities & critical ICT providers
Testing basisRisk-based; assess control effectivenessRegular ICT testing for all in-scope
Advanced testingNot a prescribed TLPT-style exerciseTLPT for significant entities
TLPT frameworkTIBER-EU based, authority-overseen
Advanced cadenceSet by risk / national lawTLPT approx. every 3 years
PrescriptivenessBroad, principles-ledNarrow, detailed

// 03 What NIS2 expects for testing

NIS2 doesn't hand you a test-type and a frequency. Instead it requires in-scope entities to run cybersecurity risk-management measures, explicitly including policies and procedures to assess the effectiveness of those measures. Read plainly, that means a documented, risk-based testing programme: regular vulnerability assessment and penetration testing proportionate to your risk profile, feeding into how you measure whether controls actually work. Because member states transpose NIS2 into national law, the precise expectation varies by country — but the baseline everywhere is that you can show a deliberate testing cadence tied to risk, not an ad-hoc scan when someone remembers. Governance and management accountability are also emphasised, so testing that informs the board matters.

// 04 What DORA expects — and TLPT

DORA is far more specific. Every in-scope financial entity must run a regular programme of ICT testing — vulnerability assessments, scans, and penetration tests appropriate to their systems. On top of that, entities their competent authority identifies as significant must perform Threat-Led Penetration Testing (TLPT): a realistic, intelligence-led red-team exercise against live production critical functions, built on the TIBER-EU framework, using qualified testers and threat-intelligence providers, and overseen by authorities — roughly every three years. TLPT is a serious, months-long undertaking closer to an adversary-simulation red team than a standard pentest. The full mechanics are in DORA TLPT requirements. Note: not every DORA firm does TLPT — but every DORA firm does regular testing.

// 05 How this reaches GCC firms

“EU regulation” doesn't mean “not my problem” in the Gulf. Three routes bring these regimes to GCC organisations. First, an EU entity or subsidiary: a GCC banking or insurance group with an EU-authorised entity can pull that entity into DORA, TLPT included. Second, the supply chain: if you provide services to EU essential/important entities (NIS2) or to EU financial firms (DORA's third-party provisions), those obligations arrive as contractual supplier requirements. Third, customer expectation: EU counterparties increasingly ask for evidence aligned to these regimes even where they don't strictly apply. The practical move is to map your EU footprint and customer base, decide which regime touches which entity, and test accordingly — often alongside your local SAMA or CBB obligations, which share DNA with DORA's resilience-and-red-teaming approach.

// 06 Frequently asked questions

What's the difference between NIS2 and DORA for pentesting?

DORA is financial-sector-specific and mandates regular ICT testing plus, for significant entities, Threat-Led Penetration Testing (TLPT) — intelligence-driven red teaming on the TIBER-EU framework, roughly every three years. NIS2 is a broader directive across many sectors requiring risk-based testing and assessment of control effectiveness, without prescribing a TLPT-style exercise. DORA is narrower and more prescriptive; NIS2 wider and more risk-based.

Does NIS2 require penetration testing?

It requires risk-management measures including procedures to assess the effectiveness of cybersecurity measures — which in practice means regular vulnerability assessment and penetration testing proportionate to risk, even though no fixed test type or frequency is named. Member states transpose it into national law, so exact expectations vary, but a documented risk-based testing programme is the baseline.

What is DORA TLPT and who has to do it?

TLPT is DORA's advanced requirement: a realistic, intelligence-led red-team exercise against live production, built on TIBER-EU and authority-overseen. It applies to financial entities designated significant by their competent authority — not every DORA firm — approximately every three years. All DORA entities still perform the broader regular testing.

Do NIS2 and DORA affect GCC companies?

They can, via EU operations, subsidiaries or supply-chain relationships. A GCC group with an EU financial entity may face DORA and TLPT; a supplier to EU essential/important entities may face NIS2 as contractual requirements. Even where they don't apply directly, EU customers increasingly ask for aligned evidence. Map your EU footprint and customers, and test accordingly.

// 07 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Helps GCC groups with EU footprints map NIS2 and DORA obligations to a testing programme — from risk-based pentests to TLPT-style threat-led red teaming aligned with TIBER-EU and local SAMA/CBB regimes.

EU footprint to test for?

We'll map your NIS2 and DORA obligations to a concrete testing programme — risk-based pentests through to TLPT-style threat-led red teaming — alongside your local SAMA or CBB requirements.

Map your obligations → About DORA TLPT →