Article 26 — Advanced testing
Article 26 establishes the TLPT requirement for identified financial entities. It addresses frequency, coverage of critical or important functions, live production systems, third-party participation, tester arrangements, documentation and mutual recognition.
The financial entity assesses and proposes the scope. The relevant authority validates it. Where ICT third-party providers are included, participation and safeguards require attention before testing begins. The entity remains responsible for its obligations.
Article 27 — Tester requirements
Provider selection must consider suitability and reputation, technical and organisational capabilities, and specific expertise in threat intelligence, penetration testing and red teaming.
The article also addresses certification by an accreditation body in a Member State or adherence to formal codes of conduct or ethical frameworks, independent assurance or audit of relevant risk management, and professional indemnity insurance. A website badge alone does not establish eligibility.
Internal testers are subject to additional conditions and authority approval. Significant credit institutions must use external testers as set out in Article 26. Review the precise provisions for your entity.
The TLPT RTS — Regulation (EU) 2025/1190
The RTS provides detailed requirements for selection, internal testers, scope and the testing process, results, closure, remediation and cooperation between authorities.
Among its practical implications: the active red-team testing phase lasts at least 12 weeks; specific information is required in the reports; and closure includes blue-team involvement and purple teaming. Scheduling must account for the whole process, not just active testing.
TIBER-EU and national implementation
TIBER-EU provides a framework, participant guidance and templates to operationalise threat-led testing. It supports DORA TLPT but does not replace the legislation, RTS or applicable authority instructions.
For ECB-supervised significant institutions, the ECB implementation guide provides additional operational context. National arrangements and cross-border cooperation should be clarified at initiation.
What this reference cannot decide
This page cannot determine your designation, approve your scope or assess a provider’s full eligibility. Those decisions require the actual entity, evidence and authority process. TLPT is one component of DORA, which also covers wider ICT risk management, incident reporting and third-party risk.
Continue with who needs TLPT or the procurement guide.
Primary sources
- DORA · Regulation (EU) 2022/2554
- TLPT RTS · Delegated Regulation (EU) 2025/1190
- ECB · TIBER-EU framework and guidance
- ECB · TIBER-EU implementation guide for significant institutions
General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.

