Financial sector resilienceAtlant Security
TLPT/DORABY ATLANT SECURITY

Requirements

TLPT vs penetration testing: what changes under DORA?

Why a conventional penetration test does not automatically meet the requirements of a DORA threat-led exercise.

The difference is the question being tested

A conventional penetration test typically examines weaknesses in a defined technical scope. A threat-led penetration test asks a broader question: how would a credible adversary affect the organisation’s critical functions, and how would its people, processes and technology respond?

The distinction is more than duration or intensity. DORA TLPT has an authority process, targeted threat intelligence, requirements for testers, a scope tied to critical or important functions and formal closure work. Calling an exercise “red teaming” does not establish that these requirements were met.

Compare the engagement models

DimensionConventional penetration testDORA TLPT
Starting pointOften a technical asset list or defined application scope.Critical functions, relevant threats and authority-validated scope.
Threat basisMay use standard techniques and a general attacker model.Targeted threat intelligence informs realistic scenarios.
EnvironmentDepends on the agreed assignment.Relevant critical live production systems.
Defensive capabilityMay be outside the test objective.Prevention, detection and response form part of the learning.
GovernanceDefined by the engagement and relevant standards.DORA, RTS, authority involvement and specific participant roles.
ClosureUsually a technical report and agreed follow-up.Red/blue reporting, replay, purple teaming, summary and remediation process.

Why organisations may need both

DORA’s general testing programme and its advanced TLPT obligation serve related but different purposes. Routine technical testing can identify weaknesses before they become part of a broader attack path. TLPT can then show whether layers of controls work together under realistic conditions.

Finding a large number of vulnerabilities does not make a test equivalent to TLPT. Equally, a threat-led exercise is not intended to exhaustively inspect every asset for every possible flaw. The objectives and evidence requirements need to remain clear.

Avoid the procurement mismatch

A procurement brief that simply requests a “DORA pentest” is ambiguous. One supplier may price a short application assessment while another assumes a multi-stage TLPT with threat intelligence and extensive closure obligations.

Specify whether the entity has been identified for TLPT, which authority is involved, the likely critical functions, the testing window and the expected deliverables. Ask suppliers to explain how their approach maps to the relevant requirements. Compare equivalent scope, resource and governance assumptions.

Do not buy a test solely because its proposal uses the right acronym. Verify the proposed team and evidence against Article 27, and agree operational safeguards before any testing starts.

Continue your preparation

Primary sources

General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your critical functions. Your authority’s requirements. A clear starting point for your TLPT engagement.

Discuss your TLPT