The oversight side of DORA has moved from paper to practice, too. The European Supervisory Authorities made their first Critical ICT Third-Party Provider designations on November 18, 2025, marking the point where direct EU-level scrutiny of major cloud and tech vendors started operating for real. This guide covers what DORA-aligned vulnerability scanning needs to cover, how it differs from TLPT, which tools do the job well, and how often scanning genuinely needs to happen.
What is vulnerability scanning under DORA? It’s the recurring, automated process of identifying unpatched software, misconfigurations, and known vulnerabilities across an entity’s ICT estate. Under DORA, it forms the baseline testing layer within Pillar 3, required at least annually, sitting alongside the far more advanced Threat-Led Penetration Testing that significant entities must run at least once every three years.
Source: https://qualysec.com/vulner ...