01 — Prepare and define the scope
Establish the control team, engage with the relevant authority and confirm the basis for testing. Map critical or important functions to people, processes, production systems and ICT providers. Record scope boundaries and dependencies in a form that can be reviewed and validated.
Procurement, confidentiality, authority coordination, risk assessment and rules of engagement are prerequisites for safe execution. Identify who can approve a change, stop activity and resolve a genuine incident during testing.
02 — Develop targeted threat intelligence
Use the organisation’s exposure and threat landscape to identify relevant adversaries and plausible attack scenarios. The intelligence phase should connect the reasons for choosing a scenario to the functions being tested.
Separate established facts, analytical judgments and uncertainty. Agree the intelligence and scenario outputs with the appropriate participants before red-team planning is finalised.
03 — Execute controlled red-team testing
Translate scenarios into a test plan, agreed objectives and controlled actions. The control team maintains oversight while the defenders’ prevention, detection and response capabilities are tested under the applicable methodology.
The active red-team testing phase has a minimum duration of 12 weeks under RTS Article 11(5). Operational circumstances, approved changes and any limited purple teaming must be managed in accordance with the RTS and authority process. This is not permission to shorten or redefine the test unilaterally.
04 — Reconstruct the test and learn
After active testing, disclose the exercise to the blue team through the agreed process. Bring the red-team attack narrative together with the defenders’ account. Replay, collaborative analysis and purple teaming help explain where controls worked, where visibility was missing and what should change.
The RTS sets report content and timing requirements. Plan the red-team report, blue-team report and test summary early rather than assembling them from incomplete notes at the end.
05 — Plan remediation and complete the evidence
Assign remediation ownership and priorities, distinguish immediate fixes from structural improvements, and agree how completion will be evidenced. Submit the required documentation through the financial entity’s authority process.
Closure documentation and any authority attestation concern the test. The entity continues to own its broader DORA obligations and remediation programme. Read more about the outputs and responsibilities.
How TIBER-EU fits
The ECB’s TIBER-EU framework provides operational guidance, participant roles and templates. Use it consistently with DORA, the TLPT RTS and the applicable authority’s implementation. A provider should explain how its approach maps to these requirements, rather than treating the TIBER name as an accreditation.
Primary sources
- DORA · Regulation (EU) 2022/2554
- TLPT RTS · Delegated Regulation (EU) 2025/1190
- ECB · TIBER-EU framework and guidance
General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.

