Financial sector resilienceAtlant Security
TLPT/DORABY ATLANT SECURITY

Requirements

Article 27: what to verify in a TLPT provider

Translate DORA’s tester requirements into evidence requests for your provider and the team that will actually deliver the test.

A methodology description is not due diligence

DORA Article 27 sets requirements for the testers used to conduct TLPT. Procurement should obtain evidence against those requirements and evaluate the actual delivery arrangements. A badge, a broad statement of experience or a reference to TIBER-EU is not a substitute.

The assessment needs to cover the organisation and the named people proposed for the work. Ensure the evidence remains relevant if the provider changes its team or introduces a subcontractor.

Suitability and specific expertise

Article 27 addresses suitability and reputation, technical and organisational capability, and specific expertise in threat intelligence, penetration testing and red-team testing. Ask how that expertise maps to the proposed roles and scenarios.

Relevant experience should be described at an appropriate level without breaching another client’s confidentiality. A procurement team can agree a secure channel for references, supporting records and team information rather than relying entirely on public marketing pages.

Certification and ethical frameworks

The legal provision refers to certification by an accreditation body in a Member State or adherence to formal codes of conduct or ethical frameworks. Do not reduce this wording to a claim that one particular commercial certificate is universally mandatory or sufficient.

Ask which basis the provider relies on, what it covers and how it applies to the work. Personal qualifications can be relevant evidence of skills, but they do not automatically satisfy every organisational requirement.

Risk assurance and insurance

Independent assurance or audit evidence must address the sound management of risks associated with TLPT, including protection of confidential information and redress for business risks. The financial entity should understand the scope, date and relevance of the assurance provided.

Professional indemnity insurance also matters. Review whether the proposed activities, parties and risks fall within the coverage. The existence of a policy alone does not establish that an engagement is appropriately covered.

Internal testers require a separate analysis

Internal testing is subject to conditions, including relevant authority approval, independence and safeguards under DORA and the RTS. Significant credit institutions must use external testers under Article 26. The choice cannot be decided solely by resource availability.

For other entities using internal testers under permitted arrangements, the applicable requirements include periodic use of external testers. Review the precise legal conditions and authority expectations for the entity before selecting the model.

Build a traceable procurement decision

Record the requirement, the evidence requested, the assessment, any gap and the decision owner. Make unresolved conditions explicit in procurement governance. Contractual commitments, named resources and evidence-handling arrangements should match what was evaluated.

Continue your preparation

Primary sources

General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your critical functions. Your authority’s requirements. A clear starting point for your TLPT engagement.

Discuss your TLPT