The difference is the question being tested
A conventional penetration test typically examines weaknesses in a defined technical scope. A threat-led penetration test asks a broader question: how would a credible adversary affect the organisation’s critical functions, and how would its people, processes and technology respond?
The distinction is more than duration or intensity. DORA TLPT has an authority process, targeted threat intelligence, requirements for testers, a scope tied to critical or important functions and formal closure work. Calling an exercise “red teaming” does not establish that these requirements were met.
Compare the engagement models
| Dimension | Conventional penetration test | DORA TLPT |
|---|---|---|
| Starting point | Often a technical asset list or defined application scope. | Critical functions, relevant threats and authority-validated scope. |
| Threat basis | May use standard techniques and a general attacker model. | Targeted threat intelligence informs realistic scenarios. |
| Environment | Depends on the agreed assignment. | Relevant critical live production systems. |
| Defensive capability | May be outside the test objective. | Prevention, detection and response form part of the learning. |
| Governance | Defined by the engagement and relevant standards. | DORA, RTS, authority involvement and specific participant roles. |
| Closure | Usually a technical report and agreed follow-up. | Red/blue reporting, replay, purple teaming, summary and remediation process. |
Why organisations may need both
DORA’s general testing programme and its advanced TLPT obligation serve related but different purposes. Routine technical testing can identify weaknesses before they become part of a broader attack path. TLPT can then show whether layers of controls work together under realistic conditions.
Finding a large number of vulnerabilities does not make a test equivalent to TLPT. Equally, a threat-led exercise is not intended to exhaustively inspect every asset for every possible flaw. The objectives and evidence requirements need to remain clear.
Avoid the procurement mismatch
A procurement brief that simply requests a “DORA pentest” is ambiguous. One supplier may price a short application assessment while another assumes a multi-stage TLPT with threat intelligence and extensive closure obligations.
Specify whether the entity has been identified for TLPT, which authority is involved, the likely critical functions, the testing window and the expected deliverables. Ask suppliers to explain how their approach maps to the relevant requirements. Compare equivalent scope, resource and governance assumptions.
Do not buy a test solely because its proposal uses the right acronym. Verify the proposed team and evidence against Article 27, and agree operational safeguards before any testing starts.
Continue your preparation
Primary sources
- DORA · Regulation (EU) 2022/2554
- TLPT RTS · Delegated Regulation (EU) 2025/1190
- ECB · TIBER-EU framework and guidance
General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.
