Forefront IT Security Services
BlogCompliance
Compliance

DORA Article 26: Threat-Led Penetration Testing Explained

November 2025Forefront IT Security Services2 min read

What DORA's TLPT requirements actually mean for financial entities, and how they differ from standard penetration testing.

DORA Background The Digital Operational Resilience Act (DORA) came into force on 17 January 2025. It applies to financial entities across the EU, banks, insurers, investment firms, payment providers, and their ICT third-party service providers.

MetricDetail
Jan 2025DORA came into force
3 YearsTLPT testing cycle
Article 26TLPT requirements

Who Must Conduct TLPT?

Not every financial entity requires TLPT. The requirement applies to entities identified by competent authorities as "significant", typically based on:

  • Systemic importance to the financial sector
  • Size and complexity of ICT systems
  • Interconnectedness with other financial entities
  • Critical or important functions provided

What is TLPT?

TLPT isn't a standard pentest. It's an advanced form of testing that simulates the tactics, techniques, and procedures (TTPs) of real threat actors who target the financial sector. DORA explicitly references the TIBER-EU framework as the model.

TIBER-EU Framework Phases

  1. Preparation Phase Scope definition, threat intelligence procurement, team selection
  2. Testing Phase Red team executes attack scenarios based on threat intelligence
  3. Closure Phase Purple team replay, remediation planning, reporting to authorities

DORA applies to systemically important financial institutions across the EU.

Key Differences from Standard Pentesting

AspectStandard PentestTLPT
MethodologyGeneric checklist-basedThreat intelligence-driven
EnvironmentTest/stagingLive production systems
Blue TeamOften awareUnaware until closure
OversightInternal onlyRegulatory involvement
ClosureReport handoffMandatory purple team

The Three Teams

Threat Intelligence Provider

Produces a Targeted Threat Intelligence Report identifying threat actors, TTPs, and attack scenarios relevant to the entity.

Red Team

Executes attack scenarios. Must be external, appropriately certified, and carry professional indemnity insurance.

Blue Team / Defenders

The entity's own security operations. Operates normally, they don't know testing is occurring until debrief.

Scope Requirements

Article 26 specifies that TLPT must cover "critical or important functions":

  • Payment processing, core banking, trading
  • Customer-facing services
  • Third-party connections
  • Cloud infrastructure if hosting critical functions

Frequency

DORA mandates TLPT at least every three years. More frequent testing may be required for:

  • Risk profile changes
  • Major ICT incidents
  • Significant system changes
  • Sector-wide threats

Reporting Requirements

After TLPT completion, entities must:

  • Submit summary report to competent authorities
  • Document all findings and remediation plans
  • Complete remediation within agreed timeframes
  • Provide evidence of remediation to authorities

Common Questions

Can we use our existing pentest provider?

Maybe. TLPT requires specific qualifications and TIBER experience. Standard pentest providers may not have the required certifications or experience in threat intelligence-led operations.

What about third parties in scope?

If critical functions rely on third-party ICT providers, those systems may be in scope. This requires coordination with providers and potentially joint testing arrangements.

How does this interact with other regulations?

DORA supersedes previous national requirements. If you were already conducting CBEST, TIBER-NL, or similar, those frameworks align with DORA's TLPT requirements.

DORA-Compliant Testing

We deliver TLPT engagements aligned with DORA Article 26 and TIBER-EU requirements. From threat intelligence through red team execution to purple team closure.

Security Front Door

Find the right level of security for your business.

One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.

Forefront
UK Penetration Testing & Red Team Operations
Loading...