The short answer
Not every financial entity within DORA’s scope must perform TLPT. Article 26 applies to financial entities identified through the relevant authority’s process, with the exclusions in that article. The TLPT RTS specifies selection criteria.
Being a bank, insurer, payments business or ICT provider is not, by itself, enough to determine your individual obligation. Confirm your entity classification, the applicable criteria and any designation or notification from your authority.
How the selection works
DORA asks competent authorities to consider the entity’s impact on the financial sector, financial stability implications, ICT risk profile and technological maturity, among the relevant factors. The RTS adds criteria for the identification process.
Article 26 excludes microenterprises and entities referred to in the first subparagraph of Article 16(1) from this advanced-testing obligation. Apply these categories carefully; an organisation’s commercial description is not a legal classification.
How often is TLPT required?
The baseline is at least once every three years for entities subject to Article 26. The competent authority may adjust the frequency based on the risk profile and operational circumstances.
DORA’s application date of 17 January 2025 is not a universal first-test appointment. Your authority’s notification and process determine the practical testing schedule. Do not infer an automatic 17 January 2028 deadline for every financial organisation.
If your entity has not been selected
The general digital operational resilience testing requirements can still apply. Conventional penetration testing, vulnerability assessments and other testing methods may form part of that programme, according to DORA and the entity’s risk profile.
A voluntary threat-led exercise can have value, but its status and possible recognition need to be clear. Do not label an ordinary penetration test “DORA TLPT” simply because it tests a financial institution.
What to check internally
- The legal entity and competent authority responsible for it.
- Any selection notification, supervisory communication or planned testing window.
- The critical or important functions likely to be covered.
- Previous TIBER or TLPT exercises and relevant recognition documentation.
- Who will lead the control team and regulatory coordination.
Use the readiness checklist to organise the information, then discuss your TLPT scope.
Primary sources
General information, not legal advice. Confirm the applicable requirements and test arrangements with your relevant authority.
