Questions before an engagement
What is threat-led penetration testing?
TLPT is a controlled, intelligence-led test that uses realistic adversary scenarios against a financial entity’s critical live production systems. It examines people, processes and technology, including prevention, detection and response.
Does every organisation covered by DORA need TLPT?
No. The advanced-testing obligation applies to identified financial entities, subject to Article 26 and the selection criteria in the TLPT RTS. General DORA testing obligations are broader. Confirm your status with the relevant authority.
How often is a DORA TLPT required?
Article 26 sets a baseline of at least once every three years for identified entities. The competent authority can adjust the frequency. This does not create one universal first-test deadline.
How long does a TLPT take?
The active red-team testing phase lasts at least 12 weeks under RTS Article 11(5). Preparation, threat intelligence, reporting, closure and remediation planning add time. A credible timetable is developed around the scope and authority process.
Can an ordinary penetration test satisfy TLPT?
An ordinary penetration test does not automatically satisfy the TLPT requirements. TLPT adds targeted threat intelligence, critical-function scope, governance, controlled adversary scenarios, authority involvement and specific closure requirements.
Is TIBER-EU the same as DORA?
No. DORA and the TLPT RTS set legal requirements. TIBER-EU is an operational framework with guidance and templates that can support their implementation. Applicable authority requirements still govern the engagement.
Will testing take place in production?
DORA TLPT covers the relevant live production systems supporting the functions in scope. The test needs explicit authorisation, risk controls, agreed restrictions and escalation arrangements. A staging-only exercise should not be presented as equivalent without the authority’s agreement.
Does a TLPT result in a DORA compliance certificate?
No. A provider does not certify all DORA obligations through one test. The relevant authority process may issue an attestation concerning the TLPT, including for mutual recognition. Wider compliance and remediation remain the entity’s responsibility.
What determines the price?
Scope, entities and functions, relevant providers, scenarios, delivery resources, reporting and closure work affect the price. An agreed proposal should set out assumptions, inclusions and change control.
What should we include in an initial enquiry?
Your organisation, work contact, whether you have an authority notification, a high-level description of the likely scope and an indicative timeframe. Do not submit credentials, network diagrams, vulnerabilities or sensitive production information.
Primary sources
- DORA · Regulation (EU) 2022/2554
- TLPT RTS · Delegated Regulation (EU) 2025/1190
- ECB · TIBER-EU framework and guidance
General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.
