Back to blog
Compliance

DORA for US Financial Firms: When It Applies, and Why Point-in-Time Testing Will Not Get You There

SpartanX Research8 min read
DORA for US Financial Firms: When It Applies, and Why Point-in-Time Testing Will Not Get You There

First, does DORA even apply to you? DORA is an EU regulation, so most purely domestic US firms are not directly subject to it. It reaches a US organization in two cases: you have a branch or subsidiary that is regulated as a financial entity in the EU, or you provide ICT services to EU financial entities, where a provider designated as critical must establish an EU subsidiary; the ESAs published the first list of designated critical ICT third-party providers in November 2025, naming 19 firms including the major cloud platforms. If neither is true, DORA is not your mandate, and your testing obligations live in PCI DSS, NYDFS Part 500, and the GLBA Safeguards Rule instead. If either is true, which it is for most large US banks, insurers, and fintechs with EU operations, read on.

For the US enterprises that do have EU exposure, DORA changes the question regulators ask. The old question was "did you run a penetration test." The new question, embodied in DORA's threat-led penetration testing (TLPT) requirement, is "can you prove you would withstand a real adversary." Those are different questions, and the testing model most firms rely on was never built to answer the second one.

What DORA actually asks of you

TLPT is not a bigger annual pentest. It is a different exercise. Under DORA, threat-led penetration testing is:

  • Threat-led. It is driven by current threat intelligence specific to your organization and sector, so the test reflects the adversaries who actually target you.
  • Adversary-realistic. Red team testers emulate real attacker behavior over an extended engagement, against live production systems, chaining toward your critical or important functions the way a genuine intrusion unfolds.
  • Closed and attested. Once reports and remediation plans are agreed, you submit a summary of the relevant findings, the remediation plans, and documentation showing the test was run to standard. The authority then issues an attestation confirming the test was performed correctly, which is what allows other competent authorities to recognize it.
  • Recurring. It runs at least every three years for the financial entities that competent authorities identify as in scope, and the authority can raise or lower that frequency based on your risk profile. Entities may use internal red-team testers if they meet the conditions in the standard, but must engage external testers for every third test, and the threat intelligence provider must be external in any case. Significant credit institutions must always use external testers.

The throughline is operational resilience, demonstrated against an adversary over time. A clean report from a single engagement does not demonstrate that.

Why traditional penetration testing falls short

A conventional pentest is valuable, but it is the wrong shape for what DORA measures. Put simply, an engagement proves a point and then the clock runs out, while a real adversary runs continuous campaigns and never stops. DORA is trying to measure resilience against the second thing.

It is a snapshot. A point-in-time test, even a thorough one, describes a single moment in an environment that changes every sprint. DORA is about resilience across time, and the months between tests are exactly where exposure accumulates.

It is narrowly scoped. Traditional engagements usually test a defined application or a fixed range. TLPT expects adversary behavior across your environment, including the lateral movement and cross-surface chaining a real attacker uses to reach critical functions.

It is slow and scarce. A full TLPT cycle typically runs six to nine months, with four to six weeks of targeted threat intelligence, a minimum of twelve weeks of active red teaming under DORA, and then the replay, closure, and remediation phases on top. Qualified providers are limited relative to the number of entities being notified. If your only testing muscle is an annual manual engagement, you arrive at the formal exercise cold, with no evidence of resilience in between.

It produces a document, not a posture. A report of findings is not the same as a continuously validated, remediated, and retested security posture, which is what management and regulators increasingly want to see.

How SpartanX supports your DORA program

SpartanX is the first Autonomous Exposure Management (AEM) platform. AEM is the autonomous evolution of Adversarial Exposure Validation: instead of testing one surface at one moment, an autonomous adversary runs the entire exposure loop continuously, the way a real attacker would, and proves every finding with evidence. That is the spirit of threat-led testing, made continuous.

For a DORA program:

  • Adversary-realistic, inside and out. SpartanX emulates real attacker behavior across your external attack surface, including your mobile apps and the APIs behind them, and, with NodeX, inside your environment against production-like systems, chaining toward your important functions, continuously rather than once.
  • Evidence and closure. Every finding is exploit-validated with proof-of-concept evidence, prioritized by business impact, then driven through remediation and retest. Targeted Attack Validation lets you re-point the platform at a specific finding or system on demand to confirm the fix actually held. That maps to DORA's expectation of a management-reviewed closure with remediation tracked to completion.
  • Audit-ready reporting. SpartanX produces the evidence and reporting that your management closure report, and your assessors, require.

One point, stated plainly. SpartanX does not replace the formal TLPT that identified entities must run under their competent authority, with external threat intelligence and, on the required cadence, external testers. It makes you continuously ready for it. Between formal exercises, SpartanX keeps your environment under constant adversary pressure, so the formal test confirms a posture you already maintain, rather than discovering problems for the first time in front of your regulator.

Why now

The technical standard that governs all of this, Commission Delegated Regulation (EU) 2025/1190, has applied since July 2025, and national competent authorities are working through identification now. The first wave of notifications is expected across late 2026 and into 2027. Once notified, an entity has roughly three months to submit initiation documents and several months more to deliver a detailed scope specification, then the test itself. Counted backwards from a three-year cycle that starts with DORA's January 2025 application date, that leaves far less slack than it sounds like. Most institutions are not ready, and not because they lack security maturity. TLPT readiness is a continuous, organizational capability, and it is not something you buy the month before your scope is due.

The threat side is not waiting either. Attackers are now using autonomous AI tooling to map networks and seize privileged access in minutes. Resilience against that adversary is precisely what DORA is trying to ensure. The entities that stand up continuous, adversary-realistic testing now are the ones that will walk into their formal TLPT prepared, and stay resilient in between.

The shift in one line

DORA has redefined the standard from "we tested" to "we can prove we would hold." Point-in-time pentesting answers the first. Autonomous Exposure Management answers the second, every day, with evidence.

SpartanX is The Ultimate Adversary™, pointed at yourself, continuously. Request a guided proof-of-value to see how AEM keeps you TLPT-ready, or learn what Autonomous Exposure Management is.

Ready to see SpartanX in action?

See how a continuous adversary maps your whole attack surface, inside and out, and proves what is actually exploitable.