← All articles

consultant

ENISA Cybersecurity Exercise Methodology and DORA Article 24 Compliance

ENISA released a cybersecurity exercise methodology and toolkit that directly meet DORA Article 24 scenario-based testing requirements, with concrete artifacts to evidence compliance.

On 16 February 2026, ENISA released its Cybersecurity Exercise Methodology and a ready-to-use toolkit. Good news: this framework precisely meets DORA Article 24 expectations for digital resilience testing — including tabletop formats.

The facts

On 16 February 2026, the EU Agency for Cybersecurity (ENISA) published a Cybersecurity Exercise Methodology with a toolkit (objective templates, scenarios, injects, evaluation grids, improvement plan). The official announcement (“Cybersecurity preparedness DIY: Build your own cybersecurity exercise”) highlights a “practical and comprehensive” approach to simulate crises and train teams, from design to lessons learned and corrective action plan (ENISA, news 16/02/2026; methodology + toolkit).

Two signals confirm its rapid adoption:

  • ENISA states that Cyber Europe 2026, the large-scale pan-European exercise, relies on the same methodology, with formal evaluation and lessons-learned analysis (ENISA, 11/06/2026).
  • Several sector outlets echoed the announcement and recommended the turn-key kit, confirming operational value for public and private organisations (e.g., Digital Forensics Magazine, 18/02/2026).

In short: this is not yet another theoretical guide. ENISA’s pack provides concrete artifacts to build and evidence a cybersecurity exercise programme, modular (tabletop, role play, tool-based simulation) and risk-proportionate.

The applicable legal framework

For financial entities in Luxembourg, Belgium, France, and Germany, the obligation stems from DORA — Regulation (EU) 2022/2554, in force since 17 January 2025. Chapter IV requires an operational resilience testing programme covering, “to assess preparedness and identify weaknesses and gaps,” appropriate testing that explicitly includes scenario-based tests (tabletop), end-to-end tests, code reviews “where possible,” and advanced penetration testing (TLPT) for some actors (Arts. 24–27). Reference: eur‑lex (DORA, Arts. 24–27) and an overview of the applicable DORA framework.

What do supervisors emphasise?

  • Art. 24: establish, maintain and review a testing programme integrated into ICT risk management (proportionality, frequency, coverage of critical functions, tester competence, and evidence of remediation).
  • Art. 26: for certain profiles, threat-led testing (TLPT) complements the setup — but tabletop/scenario-based exercises remain the core building block, reusable annually and across entities.

Bottom line: a structured tabletop per ENISA is strong evidence of compliance with Art. 24 (scenario-based tests), especially when it yields a tracked action plan and a follow-up verification run.

The technical solution to deploy

DORA-ready tabletop exercises with the ENISA methodology: in practice, implement a PDCA cycle of exercises aligned to the IS and business processes.

How it works in practice

  1. Plan: define measurable objectives (e.g., detection time, CSSF/ILR escalation decision, BCP switchover), scope (assets, critical third parties), roles (executive team, CISO, DPO, crisis cell), success criteria, and expected evidence. ENISA templates provided (objectives, roles, schedule).
  2. Design the scenario: build realistic injects (e.g., HR SaaS compromise via OAuth, customer data leak through a logistics provider, core‑banking outage + ransomware) and the timeline. ENISA offers models to harmonise the exercise storyline.
  3. Execute (tabletop): 2–4 h facilitated session, role play with key decisions (activate BCP/DRP, “major incident” criteria, DORA/NIS 2/GDPR notifications, communications, national CSIRT contacts), and collect evidence (decision logs, ITSM screenshots, crisis minutes).
  4. Evaluate: score against objectives, gaps vs. procedures (SOC, EDR/XDR, backups, IAM), and an improvement plan (quick wins, owners, due dates) — ENISA evaluation and reporting templates.
  5. Embed: feed actions into the ICT/BCM risk register, re‑test a sample within 3–6 months.

Controls and reference standards

  • DORA Art. 24: “scenario-based testing,” documented and reviewed programme (eur‑lex).
  • ISO/IEC 27001:2022 — Annex A: A.5.30 ICT readiness for business continuity, A.5.21 Governance of information security, A.5.17 Information security continuity.
  • ISO 22301 (BCMS): continuity exercising and testing, continual improvement.
  • NIST CSF 2.0: RS (Respond) and RC (Recover) — RS.IM improvement and GV decision traceability.

Outcome: a DORA-native evidence pack (plan, scenario, crisis log, metrics, action plan), backed by ENISA templates, readily defensible in inspections.

How Luxgap delivers this

  • Our ISO 27001 governance: Lead Implementers/Auditors structure the annual programme (scope, cadence, priorities by risk map and DORA critical functions) and align deliverables to ISO 27001/22301.
  • Our outsourced DPOs and CISOs: co-design scenarios (exfiltration, unavailability, critical suppliers), embed notification obligations (DORA, GDPR 72 h, NIS 2 24 h to ILR) and facilitate tabletop sessions using the ENISA methodology — explore our cyber steering by an outsourced CISO.
  • Our managed SOC (optional): replays detection/alert paths and documents indicators (MTTD, MTTR), tying the exercise to real capabilities (SIEM/EDR/XDR) and SOAR playbooks.

Deliverables: exercise plan, inject kit tailored to your context, facilitation, a mapped evaluation report to DORA Art. 24 and ISO, and a prioritised action plan tracked in the risk committee.

Use case in Luxembourg or the EU

A Luxembourg financial entity under the CSSF ran a 6‑week “pilot” programme: two tabletop exercises (ransomware stopping a critical service; data leak via a logistics provider). Leveraging ENISA templates, the team:

  • clarified “major” criteria and the alert sequence (DORA, GDPR, NIS 2 / ILR),
  • shortened the escalation chain (added an incident manager and a crisis channel),
  • formalised an improvement plan (restoration tests, critical supplier procedure, communications template),
  • and produced a defensible evidence file for internal audit and the supervisor (plan, signed minutes, metrics, actions) — a use case aligned with DORA in Luxembourg and the CSSF.

Key benefit: measurable compliance with Art. 24 and a demonstrable response capability via indicators.

First concrete steps

  1. Download the ENISA kit and pick 1–2 objective/scenario templates relevant to your context (ENISA, 16/02/2026).
  2. Appoint an Exercise Lead (risk/BCM/CISO) and scope a 2‑hour tabletop with the executive team, CISO, DPO and IT Ops; set 3–4 measurable objectives (detection, notification decision, BCP switchover, communications).
  3. Map expected DORA evidence (plan, decision log, metrics, action plan) and prepare the report template before the exercise.
  4. Plan what’s next: a quarterly exercise calendar (1 “data crisis” tabletop, 1 “unavailability” tabletop, 1 focused technical drill) + risk committee reviews, leveraging your business continuity and disaster recovery plan.
  5. Align with ISO 27001/22301: integrate actions into the risk register and BCP/DRP, with owners and due dates tracked.

Official sources

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →