Back to Publications
Regulatory Brief · DORA

DORA Stress Testing Gets Simpler: What CTOs Need to Know About ESMA's MMF Guidance

30 May 2026By NexCyber Editorial DORA

The European Securities and Markets Authority (ESMA) has introduced a simplified approach to money market fund (MMF) stress test parameters, reducing the operational burden on fund managers. While this change primarily targets asset managers, CTOs across financial entities must understand its ripple effects on ICT resilience testing under DORA Chapter III. The guidance alters stress test frequency, scope, and documentation requirements—key components of your DORA compliance framework. This artic

The European Securities and Markets Authority (ESMA) has introduced a simplified approach to money market fund (MMF) stress test parameters, reducing the operational burden on fund managers. While this change primarily targets asset managers, CTOs across financial entities must understand its ripple effects on ICT resilience testing under DORA Chapter III. The guidance alters stress test frequency, scope, and documentation requirements—key components of your DORA compliance framework. This article breaks down what you need to adjust in your testing roadmap, where simplification may create hidden compliance risks, and how to align these changes with broader DORA obligations like threat-led penetration testing (TLPT).

---

Why ESMA's MMF Simplification Matters to Your DORA Compliance

ESMA’s *Final Report on Guidelines on Stress Test Scenarios under the MMF Regulation* (published 29 April 2024) reduces the number of stress test scenarios from 17 to 11 and extends the testing frequency from quarterly to semi-annually for certain MMFs. At first glance, this appears to be a sector-specific relief. However, DORA’s cross-sectoral reach means these changes have broader implications for ICT resilience testing.

The DORA-MMF Overlap

DORA Article 25(1) requires financial entities to "regularly test" their ICT systems, including through stress testing. While ESMA’s guidance does not directly amend DORA, it sets a precedent for proportionality in testing requirements. The European Supervisory Authorities (ESAs) have signaled that they will consider sector-specific guidelines when assessing compliance with DORA’s testing obligations. For CTOs, this means:

  • Reduced testing frequency for MMFs may influence how regulators interpret "regular" testing under DORA for other financial instruments.
  • Simplified parameters could lower the bar for what constitutes an "appropriate" stress test under DORA Article 25(2), which mandates tests that reflect "the entity’s risk profile."

Regulatory Expectations Are Shifting

ESMA’s move reflects a broader regulatory trend toward proportionality, particularly for smaller or less complex entities. However, DORA’s testing requirements remain risk-based. If your entity manages MMFs—or relies on third-party MMF managers—you must document how ESMA’s simplified approach aligns with your DORA-mandated testing scope. Failure to do so could result in gaps during supervisory reviews, where regulators will expect justification for deviations from standard practices.

---

The Proportionality Principle: Stress Testing Scope Under DORA

DORA’s testing framework is built on proportionality, but ESMA’s guidance refines what that means in practice. Understanding this principle is critical to avoiding over-testing or, conversely, under-testing.

What Proportionality Means Under DORA

DORA Article 25(2) states that testing must be "proportionate to the size, business, and risk profile of the financial entity." ESMA’s simplification operationalizes this by:

  1. 1Reducing scenario complexity: The 11 remaining stress test scenarios focus on liquidity, credit, and market risks, omitting less relevant or redundant parameters. For CTOs, this means your ICT stress tests can prioritize scenarios that directly impact operational resilience (e.g., liquidity crunches leading to payment system failures).
  2. 2Adjusting frequency: Semi-annual testing for low-volatility MMFs suggests that DORA’s "regular" testing may not always mean quarterly. However, this does not apply universally—high-risk entities (e.g., those managing public debt MMFs) must still test quarterly.

Key Takeaways for CTOs

  • Not all entities benefit equally: If your entity manages high-risk MMFs or relies on MMFs for liquidity, you may still need quarterly testing. Document your rationale for adopting semi-annual cycles.
  • Proportionality ≠ minimalism: Simplified parameters do not excuse inadequate testing. DORA Article 25(3) requires tests to cover "all critical or important functions," including third-party dependencies. If your MMF manager reduces testing, ensure your own tests compensate for any gaps in third-party resilience.
  • Regulatory scrutiny will focus on justification: Supervisors will expect clear evidence that your testing scope aligns with your risk profile. ESMA’s guidance provides a template—use it to structure your own proportionality assessments.

---

How Simplified Parameters Change Your ICT Resilience Testing Roadmap

ESMA’s guidance directly impacts three areas of your DORA testing roadmap: scope, frequency, and documentation. Here’s how to adapt.

1. Scope: Narrowing the Focus

The reduced number of stress test scenarios means your ICT resilience tests can concentrate on high-impact risks. For example:

  • Liquidity risk scenarios: Test payment systems, treasury management tools, and third-party liquidity providers under stress conditions.
  • Market risk scenarios: Simulate disruptions to trading platforms, data feeds, or valuation models.
  • Credit risk scenarios: Assess the resilience of credit assessment tools, collateral management systems, and counterparty risk databases.

Action item: Audit your current stress test scenarios. Remove redundant or low-impact tests and reallocate resources to high-priority areas. Ensure alignment with DORA Article 25(2), which requires tests to reflect "the entity’s risk profile."

2. Frequency: Adjusting the Cadence

ESMA’s semi-annual testing cycle for low-volatility MMFs may allow you to reduce the frequency of certain ICT stress tests. However, this is not a blanket exemption. Consider:

  • Critical functions: DORA Article 25(3) mandates testing for all critical or important functions. If MMFs are part of your liquidity management, semi-annual testing may suffice—but document why quarterly testing is unnecessary.
  • Third-party dependencies: If your MMF manager reduces testing, increase the frequency of your own tests to compensate. DORA Article 28(5) requires financial entities to "ensure that third-party providers comply with appropriate information security standards."
  • Incident history: If your entity has experienced liquidity or market disruptions in the past 24 months, maintain or increase testing frequency.

Action item: Update your testing calendar. For low-risk MMFs, shift to semi-annual testing but retain quarterly tests for high-risk areas. Use DORA’s proportionality principle to justify changes to auditors and supervisors.

3. Documentation: Streamlining Reporting

ESMA’s guidance simplifies reporting requirements, but DORA’s documentation obligations remain stringent. Key changes:

  • Reduced scenario reporting: You no longer need to document all 17 scenarios, but you must still report on the 11 simplified scenarios. Ensure your reports align with DORA Article 25(4), which requires "a report on the outcome of the tests."
  • Proportionality justifications: Document why your testing scope and frequency are appropriate for your risk profile. ESMA’s guidance provides a framework—use it to structure your rationale.
  • Third-party alignment: If your MMF manager reduces testing, document how your own tests compensate for any gaps. DORA Article 28(6) requires financial entities to "monitor the performance of third-party providers."

Action item: Revise your testing documentation templates. Include sections for proportionality justifications and third-party alignment. Ensure reports are accessible to senior management and the board, as required by DORA Article 25(5).

---

Aligning DORA Threat-Led Penetration Testing with Reduced Stress Test Cycles

DORA’s threat-led penetration testing (TLPT) requirements (Article 26) operate independently of stress testing, but ESMA’s guidance may create misalignment if not managed carefully. Here’s how to synchronize the two.

TLPT vs. Stress Testing: Key Differences

  • TLPT focuses on cyber threats and is mandatory for "significant" entities (as defined in DORA Article 26(8)). It must be conducted at least every 3 years.
  • Stress testing assesses operational resilience under financial or market stress. ESMA’s guidance reduces its frequency for certain MMFs.

Where Misalignment Can Occur

  1. 1Testing gaps: If you reduce stress test frequency, ensure TLPT covers the same critical functions. For example, if you test liquidity systems semi-annually under stress tests, your TLPT must still include liquidity-related cyber threats.
  2. 2Resource allocation: Simplified stress testing may free up resources, but TLPT remains a high-priority obligation. Avoid reallocating resources away from TLPT to compensate for other DORA requirements.
  3. 3Third-party risks: If your MMF manager reduces testing, your TLPT must include third-party providers. DORA Article 28(5) requires financial entities to "ensure that third-party providers comply with appropriate information security standards."

Best Practices for Alignment

  • Integrate TLPT and stress test scenarios: Use TLPT to validate the cyber resilience of systems tested under stress scenarios. For example, if a stress test simulates a liquidity crisis, your TLPT should include attacks on payment systems or treasury tools.
  • Coordinate with risk teams: Ensure your risk and cybersecurity teams collaborate on testing schedules. DORA Article 25(5) requires senior management to "approve the testing programme," so alignment is critical.
  • Document overlaps: Maintain a matrix showing how TLPT and stress tests cover the same critical functions. This will be essential during supervisory reviews.

---

Practical Implementation: Updating Your DORA Testing Schedule

Implementing ESMA’s guidance requires a structured approach. Follow these steps to update your testing schedule without creating compliance gaps.

Step 1: Map Your Current Testing Programme

  • Identify all stress tests, TLPTs, and other resilience tests currently in place.
  • Categorize them by criticality (e.g., high, medium, low risk) and frequency (e.g., quarterly, semi-annual, annual).
  • Note which tests are tied to MMFs or other financial instruments affected by ESMA’s guidance