calmdrill

A Sandpiper Technology product

DORA scenario testing for ICT providers

DORA has applied since 17 January 2025. It asks EU financial entities to test their ICT business continuity plans and their response and recovery plans at least yearly (Article 11(6)). Through Article 30, it lets them write testing and training obligations into contracts with their ICT suppliers. If you sell software to EU finance, that clause is heading your way.

What DORA-style testing looks for

DORA at a glance

Framework
EU DORA (Regulation 2022/2554)
References
Art. 11(6)
Where testing comes up
Art. 11(6), testing of ICT business continuity and response and recovery plans. Art. 24 and 25, the testing programme. Art. 30, contract terms for ICT providers.
Does the text require it?
Yes, for in-scope financial entities. SaaS suppliers may be required to take part by contract.
How often
At least yearly.

Note: Calmdrill does not replace a DORA testing programme, threat-led penetration testing or legal advice. It is designed to help you run and document scenario-based exercises.

  • Severe but plausible scenarios, including cyber-attacks and third-party failures
  • Crisis communications, tested alongside the technical response
  • Documented results, with deficiencies reported to management
  • Plans updated in the light of the results

Scenarios that fit

Each runs in Team, Solo on-call or Leadership mode. Leadership mode puts the management decisions in front of the people who make them.

Scenarios for DORA-style testing
ScenarioWhy
CD-⁠05 Somebody Else’s OutageA third-party ICT failure cascading into your service
CD-⁠03 Region GreyA switchover decision with RPO trade-offs
CD-⁠09 Poisoned PackageA supply-chain cyber-attack
CD-⁠10 The Open DoorCrisis communications and management-body decisions (Leadership mode)

Results and deficiencies, for management

Every Calmdrill After-Action Report has a section for deficiencies and a management sign-off. Pro’s board summary template turns a year of drills into a one-page report for your management body or a customer’s due-diligence questionnaire.

The extract beside this comes from the sample report: an internal scripted playtest of CD-⁠01 at Harbourline, a fictional company.

Read the full sample report

After-Action ReportExtract: sections 5, 7 and 11
5. Results against the rubric, scored 1 to 4
Detection and triage3
Coordination and roles3
Communication3
Technical response2
Decisions under uncertainty2
Recovery and obligations2
7. What to improve (three of six)
  • Restart approved without evidence (T+00:12). Login success fell from 41.5% to about 5%.
  • Status page cadence. At T+01:15 the page still said "next update 03:20" and was past that time.
  • Break-glass single point of failure. Tom, the third approver, was unreachable, and there was no fallback approver or phone list.
11. Sign-offReport prepared with the Calmdrill Game Master (AI-facilitated).
Reviewed and approved by
Role
Date

The Game Master writes the report. The signature is yours.

Start with one drill

The Kit has all twelve scenarios, the Game Master and the evidence templates. $149 once, for your whole organisation. Pro adds the Annual Drill Programme and the board summary template for $349.

Load the Game Master into a Claude or ChatGPT project, choose a scenario and tell it the exercise is for DORA. It notes that in the report header.

Read the sample report