
What DORA's TLPT requirements actually mean for financial entities, and how they differ from standard penetration testing.
DORA Background The Digital Operational Resilience Act (DORA) came into force on 17 January 2025. It applies to financial entities across the EU, banks, insurers, investment firms, payment providers, and their ICT third-party service providers.
| Metric | Detail |
|---|---|
| Jan 2025 | DORA came into force |
| 3 Years | TLPT testing cycle |
| Article 26 | TLPT requirements |
Not every financial entity requires TLPT. The requirement applies to entities identified by competent authorities as "significant", typically based on:
TLPT isn't a standard pentest. It's an advanced form of testing that simulates the tactics, techniques, and procedures (TTPs) of real threat actors who target the financial sector. DORA explicitly references the TIBER-EU framework as the model.
DORA applies to systemically important financial institutions across the EU.
| Aspect | Standard Pentest | TLPT |
|---|---|---|
| Methodology | Generic checklist-based | Threat intelligence-driven |
| Environment | Test/staging | Live production systems |
| Blue Team | Often aware | Unaware until closure |
| Oversight | Internal only | Regulatory involvement |
| Closure | Report handoff | Mandatory purple team |
Produces a Targeted Threat Intelligence Report identifying threat actors, TTPs, and attack scenarios relevant to the entity.
Executes attack scenarios. Must be external, appropriately certified, and carry professional indemnity insurance.
The entity's own security operations. Operates normally, they don't know testing is occurring until debrief.
Article 26 specifies that TLPT must cover "critical or important functions":
DORA mandates TLPT at least every three years. More frequent testing may be required for:
After TLPT completion, entities must:
Maybe. TLPT requires specific qualifications and TIBER experience. Standard pentest providers may not have the required certifications or experience in threat intelligence-led operations.
If critical functions rely on third-party ICT providers, those systems may be in scope. This requires coordination with providers and potentially joint testing arrangements.
DORA supersedes previous national requirements. If you were already conducting CBEST, TIBER-NL, or similar, those frameworks align with DORA's TLPT requirements.
We deliver TLPT engagements aligned with DORA Article 26 and TIBER-EU requirements. From threat intelligence through red team execution to purple team closure.
One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.