DORA TLPT explained: threat-led penetration testing
TLPT is the most demanding part of DORA’s testing regime — a realistic, intelligence-led attack simulation against live production systems. It applies only to the financial entities competent authorities identify, but for them it is mandatory.
What TLPT is
Threat-led penetration testing simulates the tactics, techniques and procedures of real threat actors against an entity’s own environment. Article 26(2) of Regulation (EU) 2022/2554 fixes two things that make it different from ordinary penetration testing: it covers several or all critical or important functions, and it is performed on live production systems. The scoping assessment is not yours to settle alone either — the same paragraph has it validated by the competent authorities.
So TLPT does not measure a system, it measures an organisation. A vulnerability assessment asks whether a flaw exists; a TLPT asks whether your defenders notice an adversary using it, how long that takes and whether the response holds. The baseline programme in Articles 24 and 25 stays in place underneath: TLPT is added on top, never instead.
Who is actually in scope
DORA has no category called "significant entities". The phrase is market shorthand, and treating it as a legal class leads to the wrong scoping conclusion. Article 26(8) has competent authorities identify the entities required to perform TLPT, using the Article 4(2) criteria and an assessment of:
- impact-related factors;
- possible financial stability concerns, including the systemic character of the entity;
- the specific ICT risk profile, level of ICT maturity or technology features involved.
The one place "significant" is a term of art is narrow: credit institutions classified as significant in accordance with Article 6(4) of Regulation (EU) No 1024/2013 may use only external testers. Two groups are excluded outright — microenterprises, and entities under the simplified ICT risk management framework in Article 16(1). Everyone else waits to be identified rather than self-declaring.
Under Article 26(1), identified entities carry out TLPT at least every three years. The competent authority may require a lower or a higher frequency depending on the entity’s risk profile and operational circumstances, so three years is a default, not an entitlement.
The phases and their statutory clocks
Commission Delegated Regulation (EU) 2025/1190, adopted on 13 February 2025, is where the timings live. They are worth planning against early, because most of them run from an event rather than from a date you choose.
| Phase | What happens | Clock |
|---|---|---|
| Preparation | Initiation information to the authority; scope specification document approved by the management body | 3 months and 6 months — RTS Art 9(2), 9(6); preparation no longer than six months under TIBER-EU |
| Threat intelligence | Bespoke threat scenarios built for the entity and its sector | No statutory clock — it sets the red team brief |
| Red teaming | Active testing against live production systems | At least 12 weeks — RTS Art 11(5) |
| Closure | Red team report; blue team report, replay and purple teaming | 4 weeks and no later than 10 weeks — RTS Art 12(2), 12(4), 12(5) |
| Reporting and remediation | Summary of findings; remediation plans | 8 weeks each — RTS Art 12(7), 13(1) |
| Attestation | Authority issues the attestation enabling mutual recognition | RTS Art 14; DORA Art 26(7) |
Two of these deserve attention when you budget. The scope specification document under Article 9(6) has to be approved by the management body, which means a board slot, not an ICT sign-off. And active red team testing runs for at least twelve weeks under Article 11(5) — a floor on duration, so a test compressed into a fortnight is not a TLPT.
Who is in the room
TIBER-EU, the ECB framework the DORA process is built on and whose current edition dates from January 2025, names five teams. Getting these roles wrong is the most common way a test loses its value:
- Control team — the small internal group that knows the test is happening and manages risk to production throughout.
- Threat intelligence provider — builds the scenarios. Under Article 27(2)(c) it must be external to the financial entity whenever internal testers are used.
- Red team — executes the scenarios against live systems.
- Blue team — the defenders, who under Article 1(3) of the RTS are not aware of the TLPT. That unawareness is the measurement.
- TLPT authority (the TIBER cyber team) — validates scope, oversees the test and issues the attestation.
Tester quality is regulated, not left to procurement. Article 27(1) requires testers of the highest suitability and reputability; demonstrated expertise in threat intelligence, penetration testing and red team testing; certification by an accreditation body in a Member State or adherence to formal codes of conduct or ethical frameworks; independent assurance on sound risk management; and professional indemnity insurance, including against misconduct and negligence. Where internal testers are used, Article 26(8) requires external testers every three tests.
Scenarios, third parties and pooled testing
Good scenarios are built from what actually happens to entities like yours. ENISA analysed 4,875 incidents between 1 July 2024 and 30 June 2025 and found phishing behind roughly 60% of observed intrusion cases, with exploitation of vulnerabilities at 21.3% — which is why a credible TLPT usually starts at the human perimeter rather than at an exotic zero-day.
Scope frequently reaches beyond your own estate, because critical or important functions frequently do. Where an ICT third-party provider is involved and its participation in a single entity’s test would have an adverse effect on the quality or security of services to other customers, Article 26(4) allows pooled testing — several financial entities testing the shared provider together, with the provider’s agreement.
Closure: not a pass or fail
The closure phase is where the value is created, and it is deliberately collaborative. The red team report goes out within four weeks of the end of active testing; the blue team report, the replay of the attack path and the purple teaming session follow no later than ten weeks. The replay is the part defenders remember: both teams walk the same timeline side by side and establish where detection broke.
The outcome is not a pass or fail.— European Central Bank, TIBER-EU
That framing is not softness. A test whose purpose is a certificate creates pressure to keep the scope small and the scenario polite — the opposite of what Article 26(2) asks for. The output is a picture of detection and response quality, and a list of things to fix.
Attestation, mutual recognition and what stays yours
Under Article 26(6) and (7), the entity provides the authority with a summary of relevant findings, remediation plans and documentation evidencing that the TLPT was conducted in accordance with the requirements; the authority then issues an attestation, and that attestation enables mutual recognition of the test between competent authorities. One test, properly run and documented, does not have to be repeated jurisdiction by jurisdiction.
What does not transfer is responsibility. The financial entity remains fully responsible for the impact of the tests on live production systems — the control team, the rules of engagement and the risk management around the test are yours, whoever holds the keyboard.
TIBER-EU states that DORA’s TLPT requirements "are included in the detailed TIBER-EU testing process, so that financial entities completing a test under a national or European-level implementation of the TIBER-EU framework will be DORA TLPT-compliant, assuming they fulfil the formal TLPT-related requirements set by the competent authorities". If your jurisdiction runs a TIBER implementation, that is the path of least resistance.
How to prepare
Preparation is mostly not technical. Confirm whether your authority has identified you, and if it has not, keep the baseline programme demonstrably in order. Map the critical or important functions you would put in scope and the third-party dependencies inside them. Get the management body used to seeing testing decisions, because Article 9(6) of the RTS will require its approval of the scope. The entities that find TLPT painful are the ones whose Article 24 programme was thin to begin with.
Sources
- Regulation (EU) 2022/2554 (Digital Operational Resilience Act)Articles 26 and 27 — scope, frequency, pooled testing, attestation and tester requirements.
- Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testingThe statutory clocks: Articles 9, 11, 12, 13 and 14.
- TIBER-EU Framework: How to implement the European framework for Threat Intelligence-Based Ethical Red teamingJanuary 2025 edition — the five teams, the six-month preparation phase and the "not a pass or fail" outcome.
- What is TIBER-EU?Overview of the framework and its relationship to DORA TLPT.
- ENISA Threat Landscape 2025Phishing at roughly 60% of observed intrusion cases — the evidence base for realistic scenarios.
FAQ
Related questions
Is TLPT required for all financial entities?
No. Article 26(8) has competent authorities identify the entities required to perform TLPT, using the Article 4(2) criteria plus impact-related factors, possible financial stability concerns and the entity’s ICT risk profile and maturity. Microenterprises and entities under the simplified framework in Article 16(1) are excluded. Everyone else still runs the baseline programme under Articles 24 and 25.
How often is TLPT required under DORA?
At least every three years under Article 26(1). The competent authority may require a lower or higher frequency depending on the entity’s risk profile and operational circumstances.
What framework is DORA TLPT based on?
TIBER-EU, the ECB framework for threat intelligence-based ethical red teaming, in its January 2025 edition. The ECB states that DORA’s TLPT requirements are included in the TIBER-EU testing process, so an entity completing a test under a national or European-level TIBER-EU implementation will be DORA TLPT-compliant, assuming it meets the formal requirements set by its competent authority.
Do our defenders know the test is happening?
No. Under Article 1(3) of Commission Delegated Regulation (EU) 2025/1190 the blue team is not aware of the TLPT. Only the control team knows, and it manages the risk to live production systems throughout. The defenders learn about the test during the replay and purple teaming session in the closure phase.
Keep reading
More guides
-
DORA testing requirements: what financial entities must test
DORA makes resilience testing a legal duty. Here’s the programme it requires, the test types, the cadence, and who must do the testing.
Read guide -
DORA testing checklist: how to prepare and stay compliant
A practical checklist to build and evidence a DORA-compliant resilience-testing programme — from scoping critical functions to remediation.
Read guide