Pentest for DORA: The Scoping & Evidence Checklist (2026 Guide)
Pentestas Team
Security Analyst

💫 Pentest for DORA — the short version
- Start from your critical and important functions and scope every ICT system that supports them — external and internal, application and network.
- Keep a five-part evidence folder: scope + methodology, findings with proof, re-test results, tester independence, and a dated remediation log.
- The usual reason a first test fails review is incomplete scope — internal APIs, admin panels and isolation controls left untested.
- Every exploitable finding must be fixed and re-tested, with before/after evidence retained for your assessor.
“We need a pentest for DORA” is where most teams start — and then get stuck on what, exactly, to test and what the assessor will want to see. DORA does not hand you a checklist, so this is one. It turns the regulation's testing obligations into the concrete scope, evidence, and workflow you need to pass review without a scramble.
This is the practical companion to the requirements: what to scope, what to keep, why first attempts fail, and how to keep the whole thing current instead of re-doing it from scratch every cycle.
Step 1 — scope
Scope from the function down, not the asset up
DORA anchors on critical and important functions — the business capabilities whose failure would materially harm your operations, your customers, or market stability. Start there. For each function, map every ICT system that supports it: the customer-facing app, the internal APIs and admin tooling behind it, the infrastructure it runs on, the identities that can reach it, and the third parties woven through it.
Then test that map from two directions and at two layers: the external internet-facing surface and the internal surface behind your firewall, at both the network and application layers. Skip a quadrant and you have scoped a demo, not a DORA test.
Map functions before you scope
Step 2 — evidence
The five-part evidence folder
An assessor is not grading vibes; they open a folder. Make sure it contains all five parts. (1) Scope and methodology, signed off, showing the function-to-system map. (2) Findings with real proof — working exploit evidence, not just a scanner's ‘possible’ flag. (3) Re-test results proving each exploitable issue was fixed, with before-and-after. (4) Tester independence — evidence the tester is separated from the systems under test. (5) A dated remediation log with owners and closure dates.
What your assessor opens first
Step 3 — avoid the misses
Why first attempts fail review
Three failure modes account for most rejected first attempts. Incomplete scope: the public website was tested but the internal APIs, admin panels, and the controls that isolate sensitive systems were not. No re-test: findings were reported but never proven fixed — DORA wants the loop closed, not just opened. Stale coverage: the test was accurate on the day it ran, but the environment moved and nobody re-tested after the change, so ‘after significant change’ quietly went unmet.
The fix for all three is the same shape: broaden the scope to the full map, always close the re-test loop, and make testing continuous rather than annual.
Step 4 — keep it current
Make the checklist self-maintaining
The version of this checklist that actually survives contact with a growing environment is the one that re-runs itself. If your testing fires after every deploy, the evidence folder is never more than a day old, the ‘after significant change’ obligation is met by default, and the re-test loop closes automatically the next time the scan runs.
Pentestas is pentesting as a service built for exactly this checklist: an AI penetration testing system that re-runs internal and external tests continuously so the evidence folder is always current. Under the hood it is penetration testing with AI — penetration testing with Claude for deep reasoning on chained flaws and penetration testing with DeepSeek for broad, cheap coverage — delivered as a B2B SaaS pentest platform that hands your assessor a clean, mapped report instead of a stale PDF.
Cost of staying in-scope
FAQ
Pentest for DORA, quick answers
What exactly do I scope for a DORA pentest?
Every ICT system supporting a critical or important function — tested external and internal, at both the network and application layers. Scope from the business function down to each supporting system, including internal APIs, admin panels, and the third parties in the path.
What evidence does a DORA assessor want?
Five things: signed-off scope and methodology, findings backed by real exploit proof, re-test results showing fixes work, evidence of tester independence, and a dated remediation log.
Why did our first DORA pentest fail review?
Almost always incomplete scope (internal surface untested), a missing re-test loop (findings reported but not proven fixed), or stale coverage that was never re-run after a significant change.
How often do we need to test for DORA?
At least yearly for the ICT systems behind critical functions, plus after every significant change. Designated entities also owe a TLPT at least every three years. Continuous testing covers the ‘after significant change’ obligation automatically.
A straight answer on manual vs. AI
A senior human pentester is still the highest-value assessment you can buy for a DORA programme, and it typically costs 20-30× more than an AI-driven platform — both have a place. Use continuous, AI-driven pentesting to keep this checklist green every day: full-scope coverage, an always-current evidence folder, and automatic re-tests after every change. Commission a manual pentest for the deep, creative milestone your assessor and your board want to see. The strongest DORA programmes run both.
Bottom line: a pentest for DORA is not one PDF a year — it is a full-scope test of every system behind your critical functions, backed by a five-part evidence folder and a closed re-test loop. Keep it continuous and the checklist stays green on its own, at a fraction of the cost of redoing it each cycle.
Keep your DORA pentest evidence green every day
Continuous, full-scope internal + external testing with automatic re-tests and an assessor-ready report, from $79/month.
See plans & pricing
Alexander Sverdlov
Founder of Pentestas. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.
