DORA Threat-Led Penetration Testing
Controlled, intelligence-led testing of live production systems for financial entities designated for TLPT under DORA Article 26, following the applicable regulatory technical standards and TIBER-EU guidance.
DORA has applied since 17 January 2025. Financial entities identified by the competent authority under Article 26 must perform TLPT at least every three years, unless the authority adjusts the frequency based on risk and operational circumstances. The test covers critical or important functions and the live production systems that support them.
We can act as the red-team testing provider and coordinate with the entity’s control team, the competent authority and a separate threat-intelligence provider where required. Provider roles, independence, qualifications, insurance and contractual controls are agreed in accordance with the applicable rules.
The engagement includes preparation and scoping, threat-intelligence-led scenarios, controlled red-team testing, closure activities including purple teaming, and the reports and attestation required for supervisory review.
- 8 Jul 2025
- TLPT RTS directly applicable (Reg. (EU) 2025/1190)
- Article 26
- DORA advanced testing requirement
How it works
-
01
Preparation & scoping
Confirm TLPT applicability, identify critical or important functions, and agree the scope specification and rules of engagement with the authority and test control team.
-
02
Threat intelligence
A separate threat-intelligence provider builds a targeted threat profile and attack scenarios grounded in real adversaries facing your institution.
-
03
Red team execution
Covert, intelligence-led testing against live production over a multi-week active phase, with control flags and continuous risk management while the blue team stays unaware.
-
04
Purple-team replay
Mandatory closure phase replaying scenarios alongside your defenders to validate detections, tune response and capture residual risk.
-
05
Reporting & attestation
Prepare the prescribed test summary and remediation evidence for submission to the TLPT authority; the authority issues the attestation where requirements are met.
Packages
- Red Team Provider
- We run the red-team leg against an externally supplied threat-intelligence brief, with purple-team closure.
- TLPT End-to-End Popular
- Full TIBER-EU-aligned engagement with threat intelligence, controlled live-system red-team testing and the required purple-team replay.
- Pooled & Programme
- Pooled TLPT for shared infrastructure and recurring three-year cycles coordinated with your authority.
Frequently asked questions
How does TLPT differ from your DORA Compliance service?
Our DORA compliance service addresses governance and readiness across ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. TLPT is a specific advanced testing process under DORA Article 26 for financial entities designated by the competent authority. It uses threat intelligence and controlled red-team testing of live systems under the TLPT RTS. Readiness work can establish applicability, governance and evidence before the regulated test begins.
Must the threat-intelligence and red-team functions use different providers?
Not necessarily. The TLPT RTS permits both functions to be supplied by the same company, but the assigned staff must be appropriately separated and must not report to one another for the same test. The control team and TLPT authority assess whether the selected providers and personnel meet the competence, independence, insurance and conflict-of-interest requirements. We confirm the delivery model and evidence during scoping rather than assuming automatic acceptance.
Will testing against live production put our critical functions at risk?
TLPT is designed to test live systems supporting critical or important functions, but it is conducted under a formal risk-management and control structure. The control team, test managers and providers agree the scope, rules, escalation paths, stop conditions and restoration measures before active testing. The objective is realistic measurement without intentionally disrupting critical or important functions; residual risk still has to be assessed and accepted.
What do we receive at the end, and is it accepted by our regulator?
Deliverables include the provider reports and evidence needed for the financial entity’s test-summary report and remediation plan, together with the results of the required purple-team phase. The financial entity submits the prescribed material to the TLPT authority. The authority assesses the test and, where the requirements are met, issues the Article 26(7) attestation; a service provider cannot guarantee that outcome.
Helpful tools
- Scope a test
Create a scoped brief in one minute
- Security maturity assessment
Assess your organization across six domains
All services
- Security Audits
Identify exploitable weaknesses and prioritise remediation.
- Red Team & Adversary Emulation
Test whether the organisation can prevent, detect and respond to a goal-driven attack.
- Social Engineering Assessment
Measure resilience to phishing, voice fraud and other social-engineering techniques.
Scope a test
[email protected] +371 2256 5353
Direct access to a senior specialist · Reply within 24 hours · NDA available on request