AI Pentest for DORA: a new approach to testing digital resilience

Published in Security on 30 Jul 2026 by Nina

The Digital Operational Resilience Act (DORA) is an EU regulation that, as of January 2025, sets mandatory rules for cybersecurity and digital resilience in the financial sector. It applies to financial entities regulated in the EU and to their ICT service providers.

The regulation requires companies to carry out regular testing of their digital resilience, which includes, among other, penetration testing (pentesting). DORA's penetration testing requirements are divided into two levels, depending on how critical the institution is. In this article, we will look at the general testing program that applies to all financial institutions and their partners, and at how our AI Pentest can help companies meet this requirement of the regulation.

Penetration testing under DORA: key requirements

DORA does not establish a separate mandatory pentesting methodology and does not define a single standard for how it should be carried out. The regulation mentions penetration testing as one of the methods for assessing digital resilience (Article 25) and sets out a group of requirements that such testing must meet (Article 24). It is these requirements that determine whether a pentest meets the goals of the regulation.

There are five key requirements.

Independence of the tester. Testing is carried out by independent testers, either external or internal. If it is performed by an internal team, the company must allocate sufficient resources and prevent any conflict of interest at every stage.

Risk-based approach. The scope of testing is defined by how critical the systems are. The depth and priorities of the assessment depend on the current threat landscape, the company's specific risks, and the importance of its systems and services. The greatest attention is given to critical and important functions.

Classification, prioritization, and remediation of findings. All identified vulnerabilities must be classified and prioritized, and then remediated. Finding weaknesses is only the first step. The regulation requires that they be fixed and that the result be confirmed through a follow-up assessment.

Regularity. Critical and important functions are tested at least once a year. This sets a minimum frequency and turns pentesting into an ongoing process rather than a one-time project.

Systematic approach. A pentest must be part of a systematic digital resilience testing program, not a single stand-alone check. The regulation treats testing as a component of ICT risk management, so a company must have a defined plan: which systems are tested, how often, and for what purpose.

In short, DORA requires complete, regular and documented testing that involves an independent tester, requires findings to be remediated and includes validation that the findings have been fully addressed.

How A42's AI Pentest ensures compliance with DORA

AI Pentest by A42 is a penetration testing service built on a multi-agent architecture. The pentest is carried out by more than 130 specialized AI agents, managed by an orchestrator agent and supervised by an experienced pentester. The methodology is based on a documented workflow with 100 proprietary attack scenarios. AI Pentest takes up to four days, and as a result clients receive a report that prioritizes vulnerabilities and defines how critical each one is. The service starts at $1,000 (approximately €900) and the price depends on the size of the infrastructure and the type of testing.

Our AI Pentest meets exactly the requirements that DORA sets for penetration testing processes and for reporting on their results.

Independence of the tester

A42 acts as an external, independent party, as DORA requires. Companies that do not have the resources to maintain a full internal team free of conflicts of interest get a ready-made solution that meets this requirement simply by bringing in A42.

Risk-based approach

assessment must depend on how critical the systems are, and the entire AI Pentest process is built on this principle. It begins with passive reconnaissance: the agents collect data about the target from open sources only and build a complete map of the external attack surface. At this same stage, they identify the subdomains that are most critical to the business, for example those related to payments or to key processes. It is for these that in-depth testing is carried out, covering a far larger number of checks.

Next, active reconnaissance and automated scanning are used to identify vulnerabilities across the client's entire infrastructure, including deeper scanning of critical subdomains. All findings are checked for exploitability and validated by a human.

Prioritization, classification and remediation of findings

DORA compliance requires more than just listing identified issues, they must be categorized by criticality. The AI Pentest report follows this exact approach: vulnerabilities are classified by criticality level, backed by concrete evidence and actionable remediation guidance. Additionally, clients can order a dedicated technical consultation with A42 specialists to guide their remediation process.

Under DORA, identifying vulnerabilities is only the first step. Organizations must prove that vulnerabilities have been fixed. To help clients meet this requirement, AI Pentest offers an optional full re-test covering the original scope at half the price of the initial assessment. This comprehensive re-assessment verifies that all findings have been remediated without introducing new risks, while the re-test report provides auditors with clear proof of compliance.

Regularity

DORA requires critical functions to be tested at least once a year. But an annual assessment today is more of a minimum than real protection: modern development cycles have become many times faster, and a system tested in January may change significantly within a few months. A pentest once a year is simply not enough to keep risks under control, which is why the recommendations of respected cybersecurity organizations are shifting toward continuous testing. Thanks to the speed and cost of AI Pentest, continuous testing becomes entirely realistic.

Systematic approach

DORA requires penetration testing to be part of a broader, systematic testing program rather than a standalone exercise. AI Pentest aligns with this requirement through a documented, repeatable workflow with clearly defined stages and a pre-agreed scope. Clients maintain complete visibility into what is being tested, how, and why, with the flexibility to adjust the scope as needed. This gives the company a ready, repeatable foundation for its annual testing cycle.

AI Pentest by A42: what you get

To sum up what AI Pentest delivers in practice and why it meets DORA's penetration testing requirements

Clear methodology and a well-defined scope. A documented workflow with defined stages meets DORA's requirement to have a systematic testing program with a clear methodology.

Safe proof of concept. Every vulnerability is confirmed in practice, under controlled conditions agreed with the client, without harming the infrastructure. You receive a report that contains only confirmed vulnerabilities, with zero false positives.

Report with prioritization, in which every finding is classified by how critical it is. Ready-made evidence for an audit.

A full re-test at half price as proof of remediation for auditors. At the client's request, we re-test the entire scope for 50% of the cost of the first scan to confirm to auditors that the findings have been remediated.

Ready to check whether your company meets DORA's requirements? Book a discovery call with the A42 technical team.