Threat-led penetration testing for financial services
DORA TLPT: Threat-Led Penetration Testing.
Test your critical financial services against realistic threats. Document the findings and the DORA testing process.
DORA TLPT helps designated financial entities assess how well they prevent, detect and respond to attacks on live systems. We support the control team, authority-validated scope, targeted threat intelligence, at least twelve weeks of active red teaming, and the reports required for regulatory review. Fixed price for your scope, agreed before work begins.
- Scope validated by your competent authority before testing begins
- Twelve weeks minimum of active red teaming, not a two-week scan
- Full evidence pack and summary report ready for submission

A red team that has done this under DORA before, and a control team that documents every step your authority will ask about.

SEE THE DELIVERABLE
See what a useful
penetration test report looks like.
Review a combined engagement covering web, REST and GraphQL APIs, gRPC, SaaS tenant isolation, Android and iOS, networks, cloud, identity and CI/CD. Includes technical evidence, remediation and retest criteria.
62 pages. 24 findings. 14 charts, diagrams and matrices.
Illustrative penetration test. The organisation, systems and findings are fictional. This conventional pentest sample illustrates technical reporting; a formal TLPT requires additional threat-intelligence, exercise and regulatory deliverables.
Get the sample report
A free PDF. Available immediately after submitting your details.
DEFINE YOUR SCOPE
Turn your testing requirements into a clear RFP.
Build one request for your applications, APIs, networks, and cloud. Review the scope, download your document, and send a copy to your inbox and our team.
REQUEST RECEIVED
Your RFP is submitted.
Reference: . Email copies are being sent to and Alexander at Atlant Security. Check your spam folder if needed.
You can also book a call to discuss the scope.

Sits on the control team himself and writes the summary report your authority reads.
Connect on LinkedIn01 / THE DETAIL
DORA TLPT Requirements: Testing and Regulatory Evidence
The request that lands in your inbox looks like one question. It is two, and they are graded separately. Most TLPT engagements answer the first one well and the second one not at all.
The technical outcome
Identified vulnerabilities, the full attack paths that chained them together, and remediation recommendations an engineer can act on. This is the part most providers deliver.
Proof the process itself met DORA
A dedicated control team, a scope your competent authority validated, a threat intelligence report, at least twelve weeks of active red teaming, and a summary report submitted to your authority. This is the part that fails audits.
02 / THE DETAIL
Who Must Perform DORA TLPT, and How Often?
Competent authorities identify which financial entities must perform DORA TLPT, using the criteria in DORA Article 26 and Commission Delegated Regulation (EU) 2025/1190. Selected entities test at least every three years, unless their authority adjusts the frequency. Each test covers several or all critical or important functions and the live production systems supporting them. DORA applicability alone does not mean an entity is required to conduct TLPT.
03 / THE DETAIL
The DORA TLPT Process: From Scoping to Attestation
These five delivery stages cover preparation, threat intelligence, active red teaming, closure and the authority’s attestation. The technical reports and process records must support each other.
Preparation
The control team is named and kept small. Scope is drafted against your critical or important functions, written up as a scope specification, and submitted to your competent authority for validation. Testers are procured against the Article 27 criteria. Risk controls, escalation paths and a stop condition are agreed in writing before anything is touched.
Threat intelligence
A targeted threat intelligence report establishes which threat actors realistically go after an entity like yours, what they want, and how they operate. That report is not background reading. It is the source the red team scenarios are built from, and an auditor will check that the scenarios trace back to it.
Active red team testing
At least twelve weeks of active testing against live production systems, running the agreed scenarios end to end. Your blue team is deliberately not told, because the point is to measure real detection and response, not rehearsed detection and response.
Closure
The red team and blue team produce their reports. They then replay the attack timeline and carry out purple teaming to improve detection and response. Closure includes lessons learned, a test summary and a remediation plan with owners and deadlines.
Attestation
The financial entity submits the required summary, remediation plan and supporting documentation. The TLPT authority reviews the exercise and issues the attestation under DORA. A provider prepares and supports the submission; the authority decides whether the regulatory requirements have been met.
04 / THE DETAIL
How Long Does DORA TLPT Take?
Twelve weeks is the minimum length of the active red team testing phase. It is not padding, and it is not negotiable down because the quarter got busy. A real intrusion is slow: reconnaissance, an initial foothold, patient movement, and a long quiet period before anything visible happens. Compress that into two weeks and you are no longer testing whether your defences hold against the threat actor in the intelligence report. You are testing whether they hold against a fast, loud, budget-constrained imitation of one.
The twelve weeks also produce the thing your blue team actually needs: dwell time data. Not whether an alert fired, but how many days it took anyone to connect three alerts into one incident. That number is uncomfortable the first time. It is also the single most useful output of the entire exercise.
05 / THE DETAIL
The Four Parties, and Who Is Kept in the Dark
A TLPT has a deliberate information asymmetry built into it. Getting the roles wrong is the most common way a technically sound test becomes procedurally unusable.
Keep the blue team unaware during active testing
The control team manages confidentiality so the exercise measures normal detection and response. The blue team is normally informed after active testing and participates in closure and purple teaming. In exceptional circumstances, the TLPT authority can validate limited purple teaming during the active phase to allow testing to continue safely.
06 / THE DETAIL
DORA TLPT vs Standard Penetration Testing
If you already buy penetration testing, the temptation is to treat TLPT as the same purchase with a bigger number on it. The two differ on scope authority, duration, environment, disclosure and deliverable. All five matter to an auditor.
07 / THE DETAIL
Four Ways TLPT Evidence Fails an Audit
None of these are technical failures. Every one of them is a process failure that no amount of good red teaming compensates for.
Treating the pentest report as the deliverable
A red team report with good findings and no scope validation, no threat intelligence report and no summary submission is technically interesting and procedurally worthless. The auditor is assessing both halves.
Letting the blue team in on it
Once defenders know a test is running, the detection and response measurements stop meaning anything. Keeping the circle to the control team is a design requirement, not a preference.
Compressing the red team phase
An active red team phase shorter than twelve weeks does not meet the requirement, however thorough the testing was. Timeline evidence is one of the easiest things for an auditor to check.
Scoping around the awkward systems
Scope has to cover critical or important functions and it is validated by your competent authority, not by you. A scope that quietly excludes the systems that matter tends to come back.
08 / THE DETAIL
DORA TLPT Provider Requirements Under Article 27
Article 27 sets the bar for testers, and it is a real gate rather than a formality. Before you sign with any TLPT provider, including us, ask them to evidence each of these in writing. A provider that cannot is a provider whose test may not count.
- Suitability and reputation of the highest standard
- Demonstrable technical and organisational capability
- Specific expertise in threat intelligence, penetration testing and red team testing
- Certification by an accreditation body in an EU member state, or adherence to formal codes of conduct or ethical frameworks
- Independent assurance, or an audit report, covering sound management of the risk the testing itself creates
- Professional indemnity insurance, including against misconduct and negligence
On internal testers
Internal testers need competent-authority approval, dedicated resources and controls for conflicts of interest. The threat intelligence provider must be external, and external testers must be contracted every three tests. Significant credit institutions must use external testers.
If you have a capable internal red team, the useful question is not whether to use them instead of an external provider. It is which test in the cycle they run, and whether your authority has approved that arrangement in advance.
09 / THE DETAIL
DORA TLPT and TIBER-EU
DORA and its TLPT regulatory technical standards set the legal requirements. The ECB updated TIBER-EU in 2025 to align its operational framework with those requirements, including the control team, test deliverables and mandatory purple teaming.
TIBER-EU provides a practical framework for organising and running the exercise. Agree the applicable national implementation and supervisory arrangements with your TLPT authority before procurement and scoping.
What the attestation confirms
The authority’s attestation supports mutual recognition of the test between relevant authorities. It confirms compliance with the TLPT requirements; it is not a certification that the organisation has no security weaknesses. Findings still need an agreed remediation plan.
10 / THE DETAIL
Find Out Whether Your Last Test Would Survive the Audit
One scoping call. Bring whatever you have: a designation letter, a previous red team report, or just the auditor's request. You will leave the call knowing whether you are in scope, what is missing from your evidence, and what the next test has to look like. Then a fixed price for the work.
Scope My TLPT11 / THE DETAIL
Book a DORA TLPT Scoping Call
Choose a time for your scoping call.
12 / FAQ
DORA TLPT: Frequently Asked Questions
What is DORA TLPT?
How does DORA TLPT differ from a penetration test?
How long does a DORA TLPT take?
Who needs DORA TLPT, and how often?
What is a control team in a TLPT?
What does the threat intelligence report have to contain?
What gets submitted to the competent authority?
Can we use internal testers for DORA TLPT?
What is the relationship between DORA TLPT and TIBER-EU?
How much does DORA TLPT cost?
Can ICT third-party providers be included in the scope?
We failed an audit on TLPT evidence. Can you fix it retrospectively?
13 / THE DETAIL
Related Services
DORA compliance and the ICT risk function - Penetration testing - Fintech virtual CISO - Incident response - Cybersecurity risk assessment