Threat-led penetration testing for financial services

DORA TLPT: Threat-Led Penetration Testing.

Test your critical financial services against realistic threats. Document the findings and the DORA testing process.

DORA TLPT helps designated financial entities assess how well they prevent, detect and respond to attacks on live systems. We support the control team, authority-validated scope, targeted threat intelligence, at least twelve weeks of active red teaming, and the reports required for regulatory review. Fixed price for your scope, agreed before work begins.

  • Scope validated by your competent authority before testing begins
  • Twelve weeks minimum of active red teaming, not a two-week scan
  • Full evidence pack and summary report ready for submission
DORA TLPT: red team conducting threat-led penetration testing for a financial institution

A red team that has done this under DORA before, and a control team that documents every step your authority will ask about.

See a sample pentest report ↗
Cover of the illustrative penetration test report

SEE THE DELIVERABLE

See what a useful
penetration test report looks like.

Review a combined engagement covering web, REST and GraphQL APIs, gRPC, SaaS tenant isolation, Android and iOS, networks, cloud, identity and CI/CD. Includes technical evidence, remediation and retest criteria.

62 pages. 24 findings. 14 charts, diagrams and matrices.
Illustrative penetration test. The organisation, systems and findings are fictional. This conventional pentest sample illustrates technical reporting; a formal TLPT requires additional threat-intelligence, exercise and regulatory deliverables.

Get the sample report

A free PDF. Available immediately after submitting your details.

We’ll email you a thank-you and an invitation to discuss your penetration test needs. Privacy policy.

DEFINE YOUR SCOPE

Turn your testing requirements into a clear RFP.

Build one request for your applications, APIs, networks, and cloud. Review the scope, download your document, and send a copy to your inbox and our team.

Only questions relevant to your scope. Estimates and “not sure” are welcome.

200+Security Assessments
14Countries
12Weeks Active Red Team, Minimum
FixedPrice Before Anything Starts
The five phases of a DORA threat-led penetration test: preparation, threat intelligence, a twelve week red team phase, closure, and attestation
Alexander Sverdlov, founder of Atlant Security
Alexander SverdlovFounder, Atlant SecurityCISSP, CEH, CHFI, Mandiant

Sits on the control team himself and writes the summary report your authority reads.

Connect on LinkedIn

01 / THE DETAIL

DORA TLPT Requirements: Testing and Regulatory Evidence

The request that lands in your inbox looks like one question. It is two, and they are graded separately. Most TLPT engagements answer the first one well and the second one not at all.

The technical outcome

Identified vulnerabilities, the full attack paths that chained them together, and remediation recommendations an engineer can act on. This is the part most providers deliver.

Proof the process itself met DORA

A dedicated control team, a scope your competent authority validated, a threat intelligence report, at least twelve weeks of active red teaming, and a summary report submitted to your authority. This is the part that fails audits.

The documents in a DORA TLPT evidence pack: scope specification, threat intelligence report, test plan, red team report, blue team report, summary report and remediation plan

02 / THE DETAIL

Who Must Perform DORA TLPT, and How Often?

Competent authorities identify which financial entities must perform DORA TLPT, using the criteria in DORA Article 26 and Commission Delegated Regulation (EU) 2025/1190. Selected entities test at least every three years, unless their authority adjusts the frequency. Each test covers several or all critical or important functions and the live production systems supporting them. DORA applicability alone does not mean an entity is required to conduct TLPT.

Table of DORA TLPT obligations: who must test, how often, what is in scope, and who validates it

03 / THE DETAIL

The DORA TLPT Process: From Scoping to Attestation

These five delivery stages cover preparation, threat intelligence, active red teaming, closure and the authority’s attestation. The technical reports and process records must support each other.

1

Preparation

The control team is named and kept small. Scope is drafted against your critical or important functions, written up as a scope specification, and submitted to your competent authority for validation. Testers are procured against the Article 27 criteria. Risk controls, escalation paths and a stop condition are agreed in writing before anything is touched.

2

Threat intelligence

A targeted threat intelligence report establishes which threat actors realistically go after an entity like yours, what they want, and how they operate. That report is not background reading. It is the source the red team scenarios are built from, and an auditor will check that the scenarios trace back to it.

3

Active red team testing

At least twelve weeks of active testing against live production systems, running the agreed scenarios end to end. Your blue team is deliberately not told, because the point is to measure real detection and response, not rehearsed detection and response.

4

Closure

The red team and blue team produce their reports. They then replay the attack timeline and carry out purple teaming to improve detection and response. Closure includes lessons learned, a test summary and a remediation plan with owners and deadlines.

5

Attestation

The financial entity submits the required summary, remediation plan and supporting documentation. The TLPT authority reviews the exercise and issues the attestation under DORA. A provider prepares and supports the submission; the authority decides whether the regulatory requirements have been met.

04 / THE DETAIL

How Long Does DORA TLPT Take?

Twelve weeks is the minimum length of the active red team testing phase. It is not padding, and it is not negotiable down because the quarter got busy. A real intrusion is slow: reconnaissance, an initial foothold, patient movement, and a long quiet period before anything visible happens. Compress that into two weeks and you are no longer testing whether your defences hold against the threat actor in the intelligence report. You are testing whether they hold against a fast, loud, budget-constrained imitation of one.

The twelve weeks also produce the thing your blue team actually needs: dwell time data. Not whether an alert fired, but how many days it took anyone to connect three alerts into one incident. That number is uncomfortable the first time. It is also the single most useful output of the entire exercise.

05 / THE DETAIL

The Four Parties, and Who Is Kept in the Dark

A TLPT has a deliberate information asymmetry built into it. Getting the roles wrong is the most common way a technically sound test becomes procedurally unusable.

The four parties in a DORA TLPT: control team, threat intelligence provider, red team provider and competent authority

Keep the blue team unaware during active testing

The control team manages confidentiality so the exercise measures normal detection and response. The blue team is normally informed after active testing and participates in closure and purple teaming. In exceptional circumstances, the TLPT authority can validate limited purple teaming during the active phase to allow testing to continue safely.

06 / THE DETAIL

DORA TLPT vs Standard Penetration Testing

If you already buy penetration testing, the temptation is to treat TLPT as the same purchase with a bigger number on it. The two differ on scope authority, duration, environment, disclosure and deliverable. All five matter to an auditor.

Comparison between a standard penetration test and a DORA threat-led penetration test

07 / THE DETAIL

Four Ways TLPT Evidence Fails an Audit

None of these are technical failures. Every one of them is a process failure that no amount of good red teaming compensates for.

Treating the pentest report as the deliverable

A red team report with good findings and no scope validation, no threat intelligence report and no summary submission is technically interesting and procedurally worthless. The auditor is assessing both halves.

Letting the blue team in on it

Once defenders know a test is running, the detection and response measurements stop meaning anything. Keeping the circle to the control team is a design requirement, not a preference.

Compressing the red team phase

An active red team phase shorter than twelve weeks does not meet the requirement, however thorough the testing was. Timeline evidence is one of the easiest things for an auditor to check.

Scoping around the awkward systems

Scope has to cover critical or important functions and it is validated by your competent authority, not by you. A scope that quietly excludes the systems that matter tends to come back.

08 / THE DETAIL

DORA TLPT Provider Requirements Under Article 27

Article 27 sets the bar for testers, and it is a real gate rather than a formality. Before you sign with any TLPT provider, including us, ask them to evidence each of these in writing. A provider that cannot is a provider whose test may not count.

  • Suitability and reputation of the highest standard
  • Demonstrable technical and organisational capability
  • Specific expertise in threat intelligence, penetration testing and red team testing
  • Certification by an accreditation body in an EU member state, or adherence to formal codes of conduct or ethical frameworks
  • Independent assurance, or an audit report, covering sound management of the risk the testing itself creates
  • Professional indemnity insurance, including against misconduct and negligence

On internal testers

Internal testers need competent-authority approval, dedicated resources and controls for conflicts of interest. The threat intelligence provider must be external, and external testers must be contracted every three tests. Significant credit institutions must use external testers.

If you have a capable internal red team, the useful question is not whether to use them instead of an external provider. It is which test in the cycle they run, and whether your authority has approved that arrangement in advance.

09 / THE DETAIL

DORA TLPT and TIBER-EU

DORA and its TLPT regulatory technical standards set the legal requirements. The ECB updated TIBER-EU in 2025 to align its operational framework with those requirements, including the control team, test deliverables and mandatory purple teaming.

TIBER-EU provides a practical framework for organising and running the exercise. Agree the applicable national implementation and supervisory arrangements with your TLPT authority before procurement and scoping.

What the attestation confirms

The authority’s attestation supports mutual recognition of the test between relevant authorities. It confirms compliance with the TLPT requirements; it is not a certification that the organisation has no security weaknesses. Findings still need an agreed remediation plan.

10 / THE DETAIL

Find Out Whether Your Last Test Would Survive the Audit

One scoping call. Bring whatever you have: a designation letter, a previous red team report, or just the auditor's request. You will leave the call knowing whether you are in scope, what is missing from your evidence, and what the next test has to look like. Then a fixed price for the work.

Scope My TLPT

11 / THE DETAIL

Book a DORA TLPT Scoping Call

Choose a time for your scoping call.

Or visit our contact page ↗

12 / FAQ

DORA TLPT: Frequently Asked Questions

What is DORA TLPT?
DORA TLPT means threat-led penetration testing under Articles 26 and 27 of the Digital Operational Resilience Act. It is an intelligence-led exercise against live production systems supporting critical or important financial functions. It tests prevention, detection and response, with scope validation, controlled execution and reporting to the TLPT authority. The detailed process is set out in Commission Delegated Regulation (EU) 2025/1190.
How does DORA TLPT differ from a penetration test?
A normal penetration test has a scope you choose, usually runs for days or a couple of weeks, often targets staging, and your team generally knows it is happening. A DORA TLPT has a scope your competent authority validates, runs at least twelve weeks of active red teaming against live production, keeps the blue team deliberately uninformed, and produces procedural evidence alongside the findings. A penetration test report will not satisfy a DORA supervisor asking for TLPT evidence.
How long does a DORA TLPT take?
The active red team testing phase must run for at least twelve weeks. That is the active testing window and it does not include preparation, the threat intelligence phase, or the closure and reporting work that follows. In practice a full TLPT from initiation to attestation runs considerably longer than the twelve weeks of testing alone.
Who needs DORA TLPT, and how often?
Financial entities identified by their competent authority must conduct TLPT at least every three years, unless the authority adjusts the frequency. Selection depends on the applicable criteria, including systemic importance and ICT risk. Other entities may still have testing obligations under Articles 24 and 25, including appropriate annual testing of systems and applications supporting critical or important functions.
What is a control team in a TLPT?
The control team is the small, named internal group that runs the test in confidence. It owns the scope, the risk controls, the escalation path and the stop condition, and it is normally the only group inside the entity that knows the test is live. Its existence and its records are part of what an auditor checks, so the control team needs to be constituted and documented from the start, not reconstructed afterwards.
What does the threat intelligence report have to contain?
It has to be targeted rather than generic: which threat actors realistically target an entity of your type, size, market and technology profile, what those actors are after, and the tradecraft they use. The red team scenarios are then built from it. An auditor will look for a traceable line from the intelligence report to the scenarios that were actually executed.
What gets submitted to the competent authority?
On completion, once the reports and the remediation plan are agreed, DORA Article 26 requires the entity to provide its competent authority with a summary of the relevant findings, the remediation plans, and documentation demonstrating that the TLPT was conducted in accordance with the requirements. The authority then issues an attestation confirming the test was performed in line with those requirements, which is what allows mutual recognition of the test by supervisors in other member states.
Can we use internal testers for DORA TLPT?
Internal testers require competent-authority approval, dedicated resources and controls for conflicts of interest. The threat intelligence provider must be external. External testers must be contracted every three tests, and significant credit institutions must use external testers. Agree the arrangement with your authority before appointing the testing team.
What is the relationship between DORA TLPT and TIBER-EU?
DORA and Commission Delegated Regulation (EU) 2025/1190 define the legal requirements. TIBER-EU provides operational guidance for conducting the exercise. The ECB updated TIBER-EU in 2025 to align it with DORA, including the terminology, deliverables and purple teaming requirements. Your TLPT authority determines the applicable supervisory arrangements.
How much does DORA TLPT cost?
Scope decides it. A test covering two critical functions at a single entity is a different piece of work from one spanning several functions and a shared ICT third-party provider. We give you a fixed price for your scope before anything starts, and you approve it first. Under DORA the financial entity bears the cost of the test and of the remediation that follows.
Can ICT third-party providers be included in the scope?
Yes, and often they have to be, because critical or important functions frequently run on them. DORA anticipates this and requires appropriate safeguards, along with contractual arrangements that oblige the provider to participate. Where a provider's participation in individual tests would adversely affect the quality of service to customers outside the scope, DORA provides for pooled testing arrangements.
We failed an audit on TLPT evidence. Can you fix it retrospectively?
Partly. Findings, attack paths and remediation plans can be reworked and presented properly. Process evidence mostly cannot be manufactured after the fact: if there was no validated scope, no targeted threat intelligence report, or the active testing ran for six weeks rather than twelve, no amount of documentation closes that. In those cases the honest answer is to plan the next test correctly, and we will tell you that on the first call rather than sell you a rewrite.

13 / THE DETAIL

Related Services

DORA compliance and the ICT risk function - Penetration testing - Fintech virtual CISO - Incident response - Cybersecurity risk assessment