DORA’s baseline testing programme can draw on several methods. Two of the most common are vulnerability assessments and network penetration tests. DORA lists these as appropriate options — the right mix depends on your risks and the systems supporting your critical or important functions.
This page looks at the specific testing methods behind DORA’s baseline obligation. For the obligation itself, see DORA resilience testing.
Vulnerability assessments
A vulnerability assessment systematically identifies known weaknesses across your systems — missing patches, misconfigurations, weak settings — and prioritises them. It is broad and repeatable, and a natural regular component of a baseline programme.
Network penetration testing
A network penetration test goes further, with a tester actively attempting to exploit weaknesses to demonstrate real impact. It validates which vulnerabilities genuinely matter and how far an attacker could get.
Choosing the right methods
DORA does not mandate every method for every entity. The appropriate mix is driven by risk and by the systems supporting your critical or important functions, tested at least annually for non-micro entities. Smaller entities take a proportionate approach.
A sensible entry point
For many smaller Irish firms, a regular vulnerability assessment plus periodic network penetration testing is a practical, proportionate baseline. CyberLabs can scope this to your obligation.
Want a proportionate baseline testing programme? See our DORA testing services.