{"id":601,"date":"2026-06-23T09:18:47","date_gmt":"2026-06-23T09:18:47","guid":{"rendered":"https:\/\/proofit.tech\/blog\/?p=601"},"modified":"2026-07-06T11:59:34","modified_gmt":"2026-07-06T11:59:34","slug":"dora-2026-how-banking-test-automation-will-be-auditable-and-provable","status":"publish","type":"post","link":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/","title":{"rendered":"DORA 2026: This is how banking test automation will be auditable and provable"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"601\" class=\"elementor elementor-601\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-451ab448 e-flex e-con-boxed e-con e-parent\" data-id=\"451ab448\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-3ce35f74 e-con-full e-flex e-con e-child\" data-id=\"3ce35f74\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6056c9b6 elementor-align-left elementor-mobile-align-center elementor-widget-tablet__width-inherit elementor-widget elementor-widget-button\" data-id=\"6056c9b6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-button elementor-size-sm\" role=\"button\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Testing<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-515bd588 elementor-widget__width-inherit elementor-widget elementor-widget-heading\" data-id=\"515bd588\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\"><p>DORA 2026: This is how banking test automation will be\nauditable and provable<\/p><\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-22b6c856 elementor-icon-list--layout-inline elementor-align-start elementor-tablet-align-center elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"22b6c856\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items elementor-inline-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-user-circle\" viewBox=\"0 0 496 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M248 8C111 8 0 119 0 256s111 248 248 248 248-111 248-248S385 8 248 8zm0 96c48.6 0 88 39.4 88 88s-39.4 88-88 88-88-39.4-88-88 39.4-88 88-88zm0 344c-58.7 0-111.3-26.6-146.5-68.2 18.8-35.4 55.6-59.8 98.5-59.8 2.4 0 4.8.4 7.1 1.1 13 4.2 26.6 6.9 40.9 6.9 14.3 0 28-2.7 40.9-6.9 2.3-.7 4.7-1.1 7.1-1.1 42.9 0 79.7 24.4 98.5 59.8C359.3 421.4 306.7 448 248 448z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">ProofIT<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">j\u00fanius 23, 2026<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-77ee9d87 e-flex e-con-boxed elementor-invisible e-con e-parent\" data-id=\"77ee9d87\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;animation&quot;:&quot;fadeInUp&quot;,&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-581fc988 e-flex e-con-boxed elementor-invisible e-con e-child\" data-id=\"581fc988\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;animation&quot;:&quot;fadeInUp&quot;,&quot;animation_delay&quot;:&quot;100&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-58c430fc e-con-full e-flex elementor-invisible e-con e-child\" data-id=\"58c430fc\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;animation&quot;:&quot;fadeInUp&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-170977bc elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"170977bc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Since 17 January 2025, DORA has required the EU financial sector to independently test critical ICT systems at least annually, and institutions subject to TLPT every three years with a threat-driven penetration test. The requirement is not to &#8222;test&#8221;, but to perform testing in a documented, repeatable and audit-provable manner. This is where test automation becomes truly valuable: when all runs are traceable and not chained to a single vendor.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-76236160 elementor-widget elementor-widget-image\" data-id=\"76236160\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"640\" height=\"427\" src=\"https:\/\/proofit.tech\/blog\/wp-content\/uploads\/2026\/06\/satyaprem-bank-4174613_640.jpg\" class=\"attachment-large size-large wp-image-615\" alt=\"DORA 2026_ProofIT_testautomation\" srcset=\"https:\/\/proofit.tech\/blog\/wp-content\/uploads\/2026\/06\/satyaprem-bank-4174613_640.jpg 640w, https:\/\/proofit.tech\/blog\/wp-content\/uploads\/2026\/06\/satyaprem-bank-4174613_640-300x200.jpg 300w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-351683c7 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"351683c7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>A year ago, on June 18, 2025, the RTS (<strong><a href=\"https:\/\/tiber.info\/blog\/2025\/06\/18\/the-dora-threat-led-penetration-testing-rts-has-been-published\/\">Commission Delegated Regulation<\/a> (EU) 2025\/1190<\/strong>) detailing the TLPT was published. Since then, the question has shifted to practice: can daily test automation hold its own in a surveillance audit? This article is about how.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7efc9f94 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"7efc9f94\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h2 class=\"wp-block-heading\">What does DORA require from testing?<\/h2>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2ad4fb5b elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"2ad4fb5b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The DORA <a href=\"https:\/\/proofit.tech\/blog\/the-hidden-roi-of-automated-testing\/\">testing<\/a> requirement consists of three layers, each built on top of the other. It is worth treating them separately, as compliance covers all three.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-732c715d elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"732c715d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h3><strong>General testing programme (Art. 24)<\/strong><\/h3><p>A risk-based, comprehensive testing programme for ICT<br \/>systems supporting critical\/important functions.<\/p><p><strong>Frequency<\/strong>: at least annually.<\/p><p><strong>Who applies<\/strong>: All financial entities except micro-enterprises<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1905746d elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"1905746d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h3><strong>Testing Types (Art. 25)<\/strong><\/h3><p>Vulnerability Testing, Source Code Review, Scenario-Based Testing, Performance Testing, End-to-End Testing, Penetration Testing.<\/p><p><strong>Frequency<\/strong>: As per the Program<\/p><p><strong>Who Applies to<\/strong>: All Financial Entities Except Micro-Enterprises<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-138167ed elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"138167ed\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h3><strong>TLPT (Art. 26)<\/strong><\/h3><p>Threat-driven penetration testing on live, production systems<\/p><p><strong>Frequency<\/strong>: At least every three years<\/p><p><strong>Applicable to<\/strong>: Designated, significant institutions<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7c78fea8 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"7c78fea8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>DORA Article 24. emphasizes that it is essential that <strong>tests are conducted by an independent party<\/strong>. The independent tester can be an internal or external testing team. If internal testing is conducted, the company must avoid conflicts of interest during the planning and execution. This is not an organizational formality, but rather means that the <strong>results of the test should not depend on who ran it and on what device<\/strong>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1ae6e463 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"1ae6e463\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h2>&#8222;We test&#8221; vs &#8222;we provably test&#8221;<\/h2>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7b6f3f9b elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"7b6f3f9b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Most financial organizations have <a href=\"https:\/\/proofit.tech\/blog\/benefits-of-performance-testing\/\">test automation<\/a>. DORA does not examine the organizational solution used to perform testing. The audit looks at whether we can retrieve evidence of testing months later regarding:<\/p>\n<ul>\n<li><strong>What did we test?<\/strong><\/li>\n<li><strong>Which critical functions, which build, which environment?<\/strong><\/li>\n<li><strong>When and how often?<\/strong><br \/>&#8222;At least annually&#8221; can only be justified if there is a time-stamped trace of the runs.<\/li>\n<li><strong>Who did it, independently?<\/strong><br \/>Can it be ruled out that the developer painted his own code green in his own tool.<\/li>\n<li><strong>What was the result and what happened to the errors?<\/strong><br \/>Can the fate of the found deviations be traced until they are fixed?<\/li>\n<\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-751ad52 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"751ad52\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>If the answer to these questions is a screenshot and a &#8222;yes&#8221;, there is no test from an audit perspective. Auditability is not report generation at the end. The <strong>trail must be generated during the test run, unmanipulated<\/strong>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2b005b79 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"2b005b79\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h2 class=\"wp-block-heading\">The three pillars of auditability<\/h2>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-502e139e elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"502e139e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h3 class=\"wp-block-heading\">1. Traceability from requirement to execution<\/h3>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-74c8920b elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"74c8920b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>An auditor doesn&#8217;t want to see test cases, but that the critical business function is covered. To do this, the test needs to be linked to the requirement, and the run should be recorded with a timestamp, environment ID, and result. The chain should work in two directions: from the requirement I can tell where the test is, and from a run I can trace back which function it verified.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2b828b99 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"2b828b99\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h3 class=\"wp-block-heading\">2. Repeatability and determinism<\/h3>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-535e3b97 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"535e3b97\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>A flaky test here costs more than a tense minute. If the same test is green today and red tomorrow, with unchanged code, then neither run proves anything. DORA expects repeatable, reliable testing, and determinism provides the basis for this: as long as the results of the critical test suite are unpredictable, there is nothing to refer to in the audit.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-419a2cd4 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"419a2cd4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h3 class=\"wp-block-heading\">3. Vendor independence<\/h3>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5317a96c elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"5317a96c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>This pillar is the one that organizations realize the last and learn the most expensively. If test automation is done in a closed format by a single tool vendor, the risk is concentrated in the audit when the evidence is collected.<\/p><p>It is risky to leave the audit trail in the vendor\u2019s system. This is because if the contract with the testing company ends or the support for the tool is discontinued, the<strong> availability of evidence going back years becomes questionable<\/strong>.<\/p><p>In addition, there is the concentration risk, which DORA specifically addresses. Article 30(3)(d) requires that <strong>outsourced automated testing providers be contractually obligated to cooperate in the TLPT<\/strong>, and a closed test tool must also comply with the DORA guidelines.<\/p><p>The third key risk is migration debt: if a test tool needs to be changed and the test assets are not portable, the continuity of compliance with the third pillar of DORA is interrupted precisely during the change.<\/p><p>Vendor independence is therefore primarily a matter of ownership. The test assets and audit trail must remain the bank&#8217;s, even if the test tool changes.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-631eda8d elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"631eda8d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h2 class=\"wp-block-heading\">ACE: Solution for DORA compliance<\/h2>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2ce41b1d elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"2ce41b1d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Our automated testing tool, <a href=\"https:\/\/proofit.tech\/services\/testautomation\/\"><strong>ACE<\/strong><\/a>, is designed to <strong>address the above three requirements as part of its operation<\/strong>.<\/p><p>The intention of auditability is that the trace of the execution is generated during runtime and can be traced in a chain from the requirement through the test to the result. The goal of vendor independence is that the test assets and the audit trail remain the bank&#8217;s, and that a change in the choice of tool does not block access to previous evidence. All this is aimed at the area where &#8222;almost good&#8221; is not an option: banking and business-critical systems.<\/p><p>This approach is a practical translation of DORA Articles 24-26 into engineering language. The goal is a continuous compliance routine, in which each release leaves its own trail.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-25e0fef0 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"25e0fef0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<h2 class=\"wp-block-heading\">Practical steps for implementing DORA<\/h2>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5036571c elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"5036571c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ol>\n<li><strong>Map critical and important functions.<\/strong><br>DORA focuses on these. What is not critical is not a priority right now.<\/li>\n<li><strong>Link tests to features.<\/strong> <br>Every critical feature should have traceable test coverage, not just test case count.<\/li>\n<li><strong>Make the critical test suite deterministic.<\/strong><br>Flaky testing here is not technical debt, but a lack of evidence.<\/li>\n<li><strong>Record the audit trail of runs while they are running.<\/strong><br>Timestamp, environment, result, and the fate of bugs until fixed.<\/li>\n<li><strong>Check ownership of the evidence.<\/strong><br>Do you have access to the audit trail regardless of the vendor, going back years.<\/li>\n<li><strong>Synchronize the testing cycle with the DORA frequency.<\/strong><br>&#8222;Annually&#8221; is only valid if the trace can be verified.<\/li>\n<\/ol>\n<h2>&nbsp;<\/h2>\n<h2>FAQ<\/h2>\n<h3>Is test automation mandatory under DORA?<\/h3>\n<div>DORA does not prescribe a specific tool, but Article 25 lists the types of testing (vulnerability testing, end-to-end testing, performance testing, penetration testing), and Article 24 requires testing critical systems annually. Maintaining this frequency and coverage manually, in a repeatable and demonstrable manner, is almost impossible. Therefore, test automation is unavoidable in practice, even if the law does not specifically require it.<\/div>\n<h3>Why is it a problem if test automation is tied to a single vendor?<\/h3>\n<div>In this case, the audit trail and test assets can easily remain in the vendor&#8217;s system. When switching devices or when support ends, the availability of evidence becomes questionable, just when the continuity of compliance should be proven.<\/div>\n<h3>When does DORA apply?<\/h3>\n<div>DORA has been applicable to EU financial institutions since 17 January 2025. The RTS on TLPT has been directly applicable since 8 July 2025.<\/div>\n<div>&nbsp;<\/div>\n<div>(This article is based on the publicly available text of DORA and the referenced professional sources. For specific compliance issues, please refer to the guidance of your own supervisory authority.)<\/div>\n<div><br><\/div>\n<div>If you have any further questions about the DORA compliance on test automation, please contact us with confidence at&nbsp;<span style=\"font-weight: bolder;\">business@proofit.tech or +44 73 6048 4722<\/span><span style=\"font-weight: bolder;\">. Our expert team can help your complex and critical or urgent functional and performance testing process.<\/span><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5fd39e41 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"5fd39e41\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Sources: <span style=\"color: #38c7ff;\"><a style=\"color: #38c7ff;\" href=\"http:\/\/href=&quot;https:\/\/www.digital-operational-resilience-act.com\/Article_24.html&quot;&gt;DORA Article 24 - General testing requirements\" data-wplink-url-error=\"true\">1<\/a> <a style=\"color: #38c7ff;\" href=\"http:\/\/href=&quot;https:\/\/www.digital-operational-resilience-act.com\/Article_25.html&quot;&gt;DORA Article 25 - Testing types and methodologies\" data-wplink-url-error=\"true\">2<\/a> <a style=\"color: #38c7ff;\" href=\"http:\/\/href=&quot;https:\/\/tiber.info\/blog\/2025\/06\/18\/the-dora-threat-led-penetration-testing-rts-has-been-published\/&quot;&gt;TLPT RTS published (Commission Delegated Regulation (EU) 2025\/1190)\" data-wplink-url-error=\"true\">3<\/a> <a style=\"color: #38c7ff;\" href=\"http:\/\/href=&quot;https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2554\/oj\/eng&quot;&gt;Regulation 2022\/2554 (DORA) - EUR-Lex\" data-wplink-url-error=\"true\">4<\/a> <a href=\"http:\/\/href=&quot;https:\/\/www.secalliance.com\/blog\/threat-led-penetration-testing-dora-financial-institutions&quot;&gt;Threat-Led Penetration Testing under DORA - secalliance\" data-wplink-url-error=\"true\">5<\/a><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Since 17 January 2025, DORA has required the EU financial sector to independently test critical ICT systems at least annually, and institutions subject to TLPT every three years with a threat-driven penetration test. The requirement is not to &#8222;test&#8221;, but to perform testing in a documented, repeatable and audit-provable manner. This is where test automation becomes truly valuable: when all runs are traceable and not chained to a single vendor.<\/p>\n","protected":false},"author":3,"featured_media":615,"comment_status":"open","ping_status":"open","sticky":false,"template":"elementor_header_footer","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[41,43,47,49,45],"class_list":["post-601","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-en-en","tag-dora-2026","tag-dora-testautomation","tag-dora-testing","tag-fintech-testautomation","tag-testautomation"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DORA 2026: This is how banking test automation will be auditable and provable - ProofIT Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/\" \/>\n<meta property=\"og:locale\" content=\"hu_HU\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DORA 2026: This is how banking test automation will be auditable and provable - ProofIT Blog\" \/>\n<meta property=\"og:description\" content=\"Since 17 January 2025, DORA has required the EU financial sector to independently test critical ICT systems at least annually, and institutions subject to TLPT every three years with a threat-driven penetration test. The requirement is not to &quot;test&quot;, but to perform testing in a documented, repeatable and audit-provable manner. This is where test automation becomes truly valuable: when all runs are traceable and not chained to a single vendor.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/\" \/>\n<meta property=\"og:site_name\" content=\"ProofIT Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-23T09:18:47+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-06T11:59:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/proofit.tech\/blog\/wp-content\/uploads\/2026\/06\/satyaprem-bank-4174613_640.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"640\" \/>\n\t<meta property=\"og:image:height\" content=\"427\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Szarka D\u00f3ra\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Szerz\u0151:\" \/>\n\t<meta name=\"twitter:data1\" content=\"Szarka D\u00f3ra\" \/>\n\t<meta name=\"twitter:label2\" content=\"Becs\u00fclt olvas\u00e1si id\u0151\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 perc\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/\"},\"author\":{\"name\":\"Szarka D\u00f3ra\",\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/#\\\/schema\\\/person\\\/67d12391f3be49a5f7508a7f9e8a833d\"},\"headline\":\"DORA 2026: This is how banking test automation will be auditable and provable\",\"datePublished\":\"2026-06-23T09:18:47+00:00\",\"dateModified\":\"2026-07-06T11:59:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/\"},\"wordCount\":1260,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/satyaprem-bank-4174613_640.jpg\",\"keywords\":[\"dora 2026\",\"dora testautomation\",\"dora testing\",\"fintech testautomation\",\"testautomation\"],\"articleSection\":[\"EN\"],\"inLanguage\":\"hu\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/\",\"url\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/\",\"name\":\"DORA 2026: This is how banking test automation will be auditable and provable - ProofIT Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/satyaprem-bank-4174613_640.jpg\",\"datePublished\":\"2026-06-23T09:18:47+00:00\",\"dateModified\":\"2026-07-06T11:59:34+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/#\\\/schema\\\/person\\\/67d12391f3be49a5f7508a7f9e8a833d\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/#breadcrumb\"},\"inLanguage\":\"hu\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"hu\",\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/#primaryimage\",\"url\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/satyaprem-bank-4174613_640.jpg\",\"contentUrl\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/satyaprem-bank-4174613_640.jpg\",\"width\":640,\"height\":427,\"caption\":\"DORA 2026_ProofIT_testautomation\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Kezd\u0151lap\",\"item\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/hu\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DORA 2026: This is how banking test automation will be auditable and provable\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/\",\"name\":\"ProofIT Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"hu\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/#\\\/schema\\\/person\\\/67d12391f3be49a5f7508a7f9e8a833d\",\"name\":\"Szarka D\u00f3ra\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"hu\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4449f92570c78778f06e34af845ed26d1ad72c792e765d9628405d860af6ab2c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4449f92570c78778f06e34af845ed26d1ad72c792e765d9628405d860af6ab2c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4449f92570c78778f06e34af845ed26d1ad72c792e765d9628405d860af6ab2c?s=96&d=mm&r=g\",\"caption\":\"Szarka D\u00f3ra\"},\"url\":\"https:\\\/\\\/proofit.tech\\\/blog\\\/author\\\/dszarkaproofit-hu\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DORA 2026: This is how banking test automation will be auditable and provable - ProofIT Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/","og_locale":"hu_HU","og_type":"article","og_title":"DORA 2026: This is how banking test automation will be auditable and provable - ProofIT Blog","og_description":"Since 17 January 2025, DORA has required the EU financial sector to independently test critical ICT systems at least annually, and institutions subject to TLPT every three years with a threat-driven penetration test. The requirement is not to \"test\", but to perform testing in a documented, repeatable and audit-provable manner. This is where test automation becomes truly valuable: when all runs are traceable and not chained to a single vendor.","og_url":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/","og_site_name":"ProofIT Blog","article_published_time":"2026-06-23T09:18:47+00:00","article_modified_time":"2026-07-06T11:59:34+00:00","og_image":[{"width":640,"height":427,"url":"https:\/\/proofit.tech\/blog\/wp-content\/uploads\/2026\/06\/satyaprem-bank-4174613_640.jpg","type":"image\/jpeg"}],"author":"Szarka D\u00f3ra","twitter_card":"summary_large_image","twitter_misc":{"Szerz\u0151:":"Szarka D\u00f3ra","Becs\u00fclt olvas\u00e1si id\u0151":"8 perc"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/#article","isPartOf":{"@id":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/"},"author":{"name":"Szarka D\u00f3ra","@id":"https:\/\/proofit.tech\/blog\/#\/schema\/person\/67d12391f3be49a5f7508a7f9e8a833d"},"headline":"DORA 2026: This is how banking test automation will be auditable and provable","datePublished":"2026-06-23T09:18:47+00:00","dateModified":"2026-07-06T11:59:34+00:00","mainEntityOfPage":{"@id":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/"},"wordCount":1260,"commentCount":0,"image":{"@id":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/#primaryimage"},"thumbnailUrl":"https:\/\/proofit.tech\/blog\/wp-content\/uploads\/2026\/06\/satyaprem-bank-4174613_640.jpg","keywords":["dora 2026","dora testautomation","dora testing","fintech testautomation","testautomation"],"articleSection":["EN"],"inLanguage":"hu","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/","url":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/","name":"DORA 2026: This is how banking test automation will be auditable and provable - ProofIT Blog","isPartOf":{"@id":"https:\/\/proofit.tech\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/#primaryimage"},"image":{"@id":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/#primaryimage"},"thumbnailUrl":"https:\/\/proofit.tech\/blog\/wp-content\/uploads\/2026\/06\/satyaprem-bank-4174613_640.jpg","datePublished":"2026-06-23T09:18:47+00:00","dateModified":"2026-07-06T11:59:34+00:00","author":{"@id":"https:\/\/proofit.tech\/blog\/#\/schema\/person\/67d12391f3be49a5f7508a7f9e8a833d"},"breadcrumb":{"@id":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/#breadcrumb"},"inLanguage":"hu","potentialAction":[{"@type":"ReadAction","target":["https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/"]}]},{"@type":"ImageObject","inLanguage":"hu","@id":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/#primaryimage","url":"https:\/\/proofit.tech\/blog\/wp-content\/uploads\/2026\/06\/satyaprem-bank-4174613_640.jpg","contentUrl":"https:\/\/proofit.tech\/blog\/wp-content\/uploads\/2026\/06\/satyaprem-bank-4174613_640.jpg","width":640,"height":427,"caption":"DORA 2026_ProofIT_testautomation"},{"@type":"BreadcrumbList","@id":"https:\/\/proofit.tech\/blog\/dora-2026-how-banking-test-automation-will-be-auditable-and-provable\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Kezd\u0151lap","item":"https:\/\/proofit.tech\/blog\/hu\/blog\/"},{"@type":"ListItem","position":2,"name":"DORA 2026: This is how banking test automation will be auditable and provable"}]},{"@type":"WebSite","@id":"https:\/\/proofit.tech\/blog\/#website","url":"https:\/\/proofit.tech\/blog\/","name":"ProofIT Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/proofit.tech\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"hu"},{"@type":"Person","@id":"https:\/\/proofit.tech\/blog\/#\/schema\/person\/67d12391f3be49a5f7508a7f9e8a833d","name":"Szarka D\u00f3ra","image":{"@type":"ImageObject","inLanguage":"hu","@id":"https:\/\/secure.gravatar.com\/avatar\/4449f92570c78778f06e34af845ed26d1ad72c792e765d9628405d860af6ab2c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4449f92570c78778f06e34af845ed26d1ad72c792e765d9628405d860af6ab2c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4449f92570c78778f06e34af845ed26d1ad72c792e765d9628405d860af6ab2c?s=96&d=mm&r=g","caption":"Szarka D\u00f3ra"},"url":"https:\/\/proofit.tech\/blog\/author\/dszarkaproofit-hu\/"}]}},"_links":{"self":[{"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/posts\/601","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/comments?post=601"}],"version-history":[{"count":35,"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/posts\/601\/revisions"}],"predecessor-version":[{"id":710,"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/posts\/601\/revisions\/710"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/media\/615"}],"wp:attachment":[{"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/media?parent=601"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/categories?post=601"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/proofit.tech\/blog\/wp-json\/wp\/v2\/tags?post=601"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}