TLPT (threat-led penetration testing) is DORA's advanced testing requirement. The EU's Digital Operational Resilience Act, which applies from January 2025, requires significant financial entities — those identified by their competent authorities — to run intelligence-led testing of live production systems supporting critical functions at least every three years, based on the TIBER-EU framework. TLPT is closer to a red team than a standard pentest: it emulates the specific adversaries likely to target the entity and tests real detection and response. Smaller entities still face DORA's other testing duties — regular vulnerability assessments and penetration tests — just not full TLPT.
// 01 What DORA and TLPT are
The Digital Operational Resilience Act (DORA) is EU regulation that harmonises how financial entities manage ICT risk, and it applies from 17 January 2025 across a wide swathe of the sector — banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and their critical ICT third parties. Among its requirements is a testing programme, and at the top of that programme, for the most significant entities, sits threat-led penetration testing (TLPT): an advanced, intelligence-led test of the live systems that support critical or important functions. It's the regulator saying, in effect: prove you could detect and withstand a real, targeted attack — not just that you've scanned for bugs.
// 02 Who is in scope
Crucially, TLPT does not apply to every entity DORA covers. It targets those that competent authorities identify as significant based on risk profile and systemic importance — the larger, more critical players whose disruption would matter to the financial system. If you're a smaller entity, DORA still applies to you in full, including its requirements for regular vulnerability assessments and penetration testing — but you're unlikely to be mandated into a full TLPT. The practical first step is confirming your status with your competent authority; being in or out of TLPT scope changes your testing programme substantially.
// 03 TLPT vs a standard penetration test
| Standard Pentest | DORA TLPT | |
|---|---|---|
| Goal | Find & prove vulnerabilities | Emulate a real adversary against critical functions |
| Intelligence-led? | No | Yes (threat intelligence drives scenarios) |
| Environment | Often test/staging | Live production systems |
| Tests detection & response? | Usually not | Yes (blue team often unaware) |
| Framework | PTES / OWASP | TIBER-EU |
| Frequency | Annual + on change | At least every 3 years |
In practice, TLPT resembles a rigorous red team conducted under a regulator-recognised framework — which is why organisations that have only ever run standard pentests find it a step change in scope, coordination and maturity.
// 04 The TIBER-EU basis and how an engagement runs
DORA's TLPT builds on TIBER-EU (Threat Intelligence-based Ethical Red Teaming), the European framework already used by several central banks. A TIBER-style engagement moves through structured phases: a preparation phase (scoping the critical functions and engaging providers), a testing phase split into threat intelligence (building a realistic picture of the actors and scenarios that would target you) and red teaming (executing those scenarios against live systems), and a closure phase (analysis, blue-team debrief and remediation). Testing must be performed by qualified external providers, with threat intelligence and red-team roles appropriately separated. The whole exercise is coordinated with authorities and run carefully to avoid disrupting live critical services.
// 05 How to prepare if you might be in scope
- Confirm your status with your competent authority — are you designated for TLPT?
- Mature your detection and response first — TLPT measures the blue team; weak detection makes it a costly confirmation of gaps. Consider red and purple team exercises to build readiness.
- Keep a conventional testing cadence — regular vulnerability assessments and penetration tests remain required and close the gaps before TLPT surfaces them.
- Identify your critical functions and the systems supporting them — that's what TLPT will target.
Whether or not you're mandated into TLPT, DORA raises the baseline for financial-sector testing — and the entities that treat it as a resilience programme, not a compliance chore, are the ones that come out stronger.
// 06 Frequently asked questions
What is TLPT under DORA?
Threat-led penetration testing: advanced, intelligence-led testing of live production systems supporting critical functions, required of significant financial entities under the EU's DORA (applies from January 2025). It's closer to a red team than a standard pentest — it emulates relevant adversaries and tests detection and response — and is based on the TIBER-EU framework.
Who has to do TLPT?
Only entities that competent authorities identify as significant, based on risk and systemic importance. DORA applies broadly (banks, payment institutions, investment firms, insurers, crypto-asset providers), but the TLPT obligation targets larger, critical entities. Smaller entities still face DORA's other testing duties.
How often is DORA TLPT required?
At least every three years, though authorities can adjust based on risk. It's less frequent than annual pentesting because it's a much larger intelligence-led exercise on live critical systems. Entities still run vulnerability assessments and conventional pentests in between.
How is TLPT different from a normal pentest?
It's intelligence-led and objective-based, run against live production critical systems, emulating the specific threat actors likely to target the entity — much like a red team. It tests real detection and response, often without the blue team's prior knowledge, following the TIBER-EU framework with qualified external providers.
// 07 References
- EU — Digital Operational Resilience Act (DORA); applies from 17 January 2025.
- European Central Bank — TIBER-EU framework.
- Related: what is red teaming and requirements by framework.