Financial sector resilienceAtlant Security
TLPT/DORABY ATLANT SECURITY

WORKING RESOURCE / SCOPE & PROCUREMENT

Build a DORA TLPT scoping brief

Turn an authority notification or an early planning discussion into a useful starting brief. Identify the functions and dependencies that need clarification before a TLPT scope can be agreed.

Define the objective.
Set the boundaries.
Leave with a working brief.

  • No signup required
  • Copy, download or print
  • Your draft stays in this page

Keep it high level. The brief is a planning aid. It is not an approved TLPT scope, an assessment of provider eligibility or a DORA compliance determination.

Your choices are processed in your browser. They are not sent, saved in browser storage or shared with AI. Copy or download your brief before leaving.

01 The decision you need

A conventional pentest and a statutory DORA TLPT have different purposes. This brief does not decide designation or replace authority validation.

02 The assessment boundary

Choose the areas you want to discuss. Final coverage is agreed during scoping.

For example: shared providers, cross-border functions, control-team availability or an authority testing window.

03 Timing and permissions

WHAT TO INCLUDE / DORA TLPT

Scope choices that change the test.

Assessment areaWhat to describeWhat useful evidence answers
Critical functionsName the business outcome and the systems, people and providers that support it.A function-to-system map and scope assumptions for the authority process.
Threat-led scenariosDescribe relevant threat concerns and the functions at risk.Scenario objectives tied to targeted threat intelligence; not a generic vulnerability list.
Governance and closureIdentify the authority process, control-team lead and required outputs.A delivery responsibility matrix, test safeguards and closure/remediation plan.

BEFORE THE SCOPING CALL

Bring the right context.

  • Authority correspondence and applicable test arrangements
  • An initial map of critical functions and ICT dependencies
  • Named governance, confidentiality and stop-authority roles
  • Provider due-diligence evidence and expected closure outputs
Open the full readiness checklist ↗

THE NEXT DECISION

From the brief to an agreed TLPT scope

Confirm the authority process and provider suitability, then validate the functions, responsibilities and safeguards before any testing begins.

Coverage, environments, role combinations, supplier coordination and retesting affect effort. A brief helps expose those assumptions; it is not a price or delivery commitment.

See how the evidence is reported ↗

Method and source references

Read the scope guide · Evaluate a provider · How we publish our guidance