DORA tabletop exercise: crisis scenario testing for financial entities
October 7, 2026 · 4 min read · Also in Spanish
What DORA asks for (yearly tests, a crisis function, 4-hour reporting), how to build an exercise for a financial entity, and what evidence to keep.
A DORA tabletop exercise tests, with the people who would make the calls, whether a financial entity's ICT business continuity and response plans hold up during a cyber-attack. DORA (Regulation (EU) 2022/2554, applying since 17 January 2025) requires those plans to be tested at least yearly, including cyber-attack scenarios, and sets a reporting clock for major incidents that starts four hours after classification.
This guide explains what DORA asks for, how to build an exercise around it, and what to keep as evidence. It is not legal advice: your competent authority and auditors decide what meets each requirement.
What DORA asks for
The articles that shape an exercise:
- Article 11(6): yearly testing. Financial entities test their ICT business continuity plans and ICT response and recovery plans at least yearly, including scenarios of cyber-attacks and switchovers to redundant capacity.
- Article 11(7): a crisis management function. Entities other than microenterprises need one, with clear procedures for internal and external crisis communications.
- Article 11(8): records. Keep readily accessible records of activities before and during disruptions when the plans are activated.
- Article 13: learning and evolving. Post-incident reviews, lessons from tests, and compulsory resilience training for all staff, including senior management.
- Article 5: governance. The management body bears ultimate responsibility for managing ICT risk.
A tabletop doesn't replace technical testing (Articles 24 to 27 cover the testing programme and, for some entities, threat-led penetration testing). It tests the part technology can't: the decisions.
The reporting clock to rehearse
Article 19 requires three reports for a major ICT-related incident, with time limits set by Delegated Regulation (EU) 2025/301:
- Initial notification: within 4 hours of classifying the incident as major, and no later than 24 hours after becoming aware of it.
- Intermediate report: within 72 hours of the initial notification, updated when the status changes significantly.
- Final report: within one month of the latest intermediate report, once the root cause is known.
The first trap is the classification itself (criteria in Delegated Regulation (EU) 2024/1772): the clock starts when you call it major, and delaying that call is a decision too.
Building the scenario
A DORA exercise works best with events that force each obligation:
- Detection and classification. Payment processing slows; the core banking supplier reports an intrusion. Is it major? Who decides, and how long did that take?
- The switchover. Do you fail over to the secondary site, knowing it may be compromised too? Who authorizes it, and what does it cost?
- Crisis communications. Customers can't pay; social media notices. The crisis function decides what to say, to whom and when, while the 4-hour notification is due.
- Third-party pressure. The ICT provider is slow to share details. What does the contract allow, and who escalates?
A supplier compromise, ransomware on core systems or a DDoS with extortion all fit. Pick the one closest to your critical functions.
Who should take part
- CEO or management body member: ultimate responsibility under Article 5.
- CISO / head of ICT risk: classification and technical response.
- Head of operations or business continuity: the switchover and service recovery.
- Legal / compliance: the notifications to the competent authority.
- Communications: the crisis communication procedures.
- Vendor manager: the ICT third-party provider.
What to keep as evidence
- The decision log, with times: classification, switchover, each notification.
- Late or missed decisions against the 4h, 24h and 72h marks.
- Attendance, including senior management (useful for Article 13 training).
- Lessons and an action plan with owners and dates (Article 13).
- Control coverage: which requirements were exercised and which showed a gap.
Frequently asked questions
Does DORA require a tabletop exercise?
It requires yearly tests of the ICT business continuity and response plans, including cyber-attack scenarios, and a crisis management function. A tabletop is a common way to test the decision-making and communication parts of those plans; technical tests cover the rest.
Who is in scope?
Most EU financial entities: banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and others listed in Article 2, with lighter rules for some smaller entities.
How is it different from NIS2?
DORA is the specific law for the financial sector and has its own reporting timeline. The exercise format is similar; see the NIS2 tabletop exercise guide for the general approach.
Critios runs DORA-style crisis exercises with your leadership team: private, timed decisions per role, escalations that follow what the team chose, and a report with the decision log, attendance and control coverage, including a DORA view. Try the demo or simulate your crises with us.
