DORA TLPT.
Threat-led penetration testing (TLPT) is the advanced testing regime under Articles 26 and 27 of the Digital Operational Resilience Act (Regulation (EU) 2022/2554). It is delivered against the TIBER-EU framework (European Central Bank), updated to align with the DORA TLPT RTS: Commission Delegated Regulation (EU) 2025/1190, OJ L 2025/1190, 18 June 2025. This page sets out what the RTS asks of providers, and how this practice is structured against that.
// 01 · Scope
DORA designates certain financial entities (credit institutions, investment firms, and other entities identified by their national competent authority as core to the financial system) to undergo TLPT under Article 26. Designation, scope and cadence are set by the entity's competent authority and TLPT authority, not by the testing provider. This page does not state which or how many entities are designated; that determination sits with the supervisory authorities.
// 02 · What Article 7 requires
Article 7 sets the due diligence a financial entity's control team must perform on any external tester before a TLPT begins, and the operating constraints that apply to the provider during and after the test:
Team composition · red team
A team manager with at least five years' experience in penetration testing and red team testing, plus at least two further testers each with at least two years. The team's combined track record must cover five or more prior assignments, and demonstrate reconnaissance, exploit development, physical penetration, social engineering and vulnerability analysis, together with knowledge of the entity's business.
Team composition · threat intelligence
A manager with at least five years' experience in threat intelligence, plus at least one further member with at least two years. The team's combined track record must cover three or more prior assignments in a penetration testing or red team context.
CVs & certifications
Documented evidence of the qualifications and track record of the individuals actually assigned to the test, not the firm in the abstract.
Professional indemnity insurance
Cover in place for misconduct and negligence arising from the testing activity.
References
External testers must provide at least five verifiable references from comparable engagements; threat intelligence providers at least three.
No concurrent blue team work
Staff performing the red team role on a given TLPT may not simultaneously perform defensive (blue team) tasks for the same tested entity.
Threat intel / testing separation
Staff assigned to threat intelligence must be separate from, and not report to, staff supplying the red team testers for the same test, and vice versa.
Mandatory post-test restoration
Backdoors and other malware are removed, and command-and-control infrastructure is deactivated. Kill switches and scope/date controls are implemented by the testers as engagement-bounding controls: they aren't artefacts left behind to be cleaned up. Any credentials obtained or created during the test are securely deleted.
Prohibited activities
- Unauthorised destruction of equipment
- Uncontrolled modification of assets
- Intentional disruption of critical or important functions
- Unauthorised inclusion of out-of-scope systems
- Unauthorised disclosure of results
The RTS anticipates that a fully compliant provider won't always be reasonably available. Article 7(3) gives the financial entity, not the provider, a route to proceed in that situation, subject to notifying its TLPT authority and documenting the reasoning. It's an exception the entity invokes; it isn't something a provider can offer in place of meeting the criteria.
// 03 · How this practice is structured
This practice is not currently an Article 7 TLPT provider, and does not present itself as one.
Article 7 sets team-composition floors for external testers and threat intelligence providers: a manager with five years in the discipline, additional members with two, minimum reference counts, indemnity cover. Those criteria attach to the individuals assigned to a specific test. A provider that cannot evidence them at procurement puts the entity's testing cycle at risk, so the honest position is worth stating plainly rather than discovered during due diligence.
Where this practice sits is on the entity side of the control team boundary.
DORA places responsibility for the test, and for managing its risk, on the financial entity, not on the provider. That responsibility is discharged by the control team, and it is substantial: scoping critical functions, selecting and vetting providers against Article 7, agreeing risk measures with the TLPT authority before testing begins, maintaining separation from the blue team throughout, and carrying the exercise through to attestation and remediation.
Support offered to control teams:
- Article 7 provider due diligence: assessing tester and threat intelligence submissions against the RTS criteria, including staff separation and reporting-line requirements where both roles come from one provider
- Scoping critical or important functions and the systems in scope
- Control team governance and blue team separation
- TLPT authority engagement and pre-testing risk measures
- Review of threat intelligence reports and red team test plans
- Closure, purple teaming and remediation tracking through to attestation
Credentials. DORA Foundations and DORA TLPT Tester. Working knowledge drawn from the RTS text and the TIBER-EU framework directly, not from secondary summaries.
Offensive practice. Penetration testing and red team work is delivered outside the TLPT regime, where Article 7 does not apply. It is not offered to entities where this practice holds a control team or advisory role.
// 04 · Phase mapping
The RTS follows the TIBER-EU framework's structure exactly: three phases, gated by the entity's control team. Testing splits into two sub-phases: threat intelligence, then the red team test. Restoration isn't a separate phase; it's an Article 7 obligation carried out at closure.
Preparation
Scope, legal basis and control-team governance agreed with the TLPT authority before any testing activity begins.
Testing · Threat Intelligence
Targeted threat intelligence report built around realistic adversaries relevant to the entity's sector and footprint.
Testing · Red Team Test
Live testing against production systems, following the scenarios set out in the threat intelligence report.
Closure
Consolidated reporting, replay/purple-teaming, remediation planning, and the Article 7 restoration obligations, closed out with the control team and authority through to attestation.
Scoping a TLPT programme? Let's talk.
Initial calls are free. This page describes the framework; the scoping conversation covers your entity's specific requirements.