September 11, 2026
Article 26 isn't DORA's scenario-testing article
DORA's scenario testing is routinely cited to Article 26. Article 26 is threat-led penetration testing, for firms a supervisor identifies, every three years. Your exercise program sits under Article 24.
Ask where DORA puts scenario testing and the answer you'll most often get is Article 26. It's the wrong article, and the error isn't a citation slip. It points at the wrong obligation, for the wrong firms, on the wrong clock.
Article 26 is threat-led penetration testing. It applies only to financial entities a competent authority has specifically identified. It runs at least every three years, and the authority can ask for it more or less often.¹ DORA's own definition, at Article 3(17), leaves no doubt about what kind of test it is:
"a framework that mimics the tactics, techniques and procedures of real-life threat actors… a controlled, bespoke, intelligence-led (red team) test of the financial entity's critical live production systems."²
That is a red-team engagement against production. It isn't a facilitated exercise, and nothing in it describes an exercise program.
The European Supervisory Authorities draw the line themselves, in their final report on the technical standards for Article 26: TLPT is advanced testing, and **"less advanced testing is already covered by Article 24 of DORA."**¹
Article 24 is where your program lives. Paragraph 6 sets the only general-testing interval in the regulation:
"Financial entities, other than microenterprises, shall ensure, at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions."³
And scenario-based testing? It appears in Article 25(1), in the list of appropriate tests the Article 24 programme provides for, alongside vulnerability assessments and penetration testing, among others.³ The list is introduced by "such as". Scenario-based tests are one option inside it, not a standalone mandate on a clock of their own.
So the honest version is less dramatic than the usual one. DORA doesn't require an annual exercise, an annual tabletop or an annual scenario test. It requires appropriate tests, at least yearly, on the systems supporting critical or important functions. Scenario-based testing is one of the kinds available to you.
Getting the article wrong costs something either way. A firm that reads Article 26 as its testing rule, and hasn't been identified for TLPT, can conclude it owes nothing. It still owes the yearly floor in Article 24. A firm that has been identified, and plans for Article 26 as though it were an exercise, is preparing for the wrong kind of test.
The rest is in one place: who counts as a financial entity and who is carved out, how "critical or important function" sets the reach of the yearly floor, who may run the tests, and what has to happen after them. What DORA actually asks of your exercise program.
Regulatory references current as of September 2026. This piece is scheduled for re-verification by March 2027.
¹ European Supervisory Authorities Joint Committee, Final Report on Draft Regulatory Technical Standards on threat-led penetration testing under Article 26(11) of Regulation (EU) 2022/2554 (JC 2024 29, 17 July 2024), which quotes Article 26(1) verbatim and states the Article 24 / Article 26 division. Article 26(1) is summarised above.
² Regulation (EU) 2022/2554 (DORA), Article 3. Article 3(17) is quoted verbatim.
³ Regulation (EU) 2022/2554 (DORA), Articles 24 and 25. Article 24(6) is quoted verbatim; Article 25(1) is summarised.