ISO 27001 and IT-Grundschutz
ISO/IEC 27001 defines requirements for an information security management system. IT-Grundschutz adds a concrete methodology and building blocks. Begin with scope and the evidence you need.
TLPT is advanced testing for financial entities identified by the supervisor. Selection follows DORA and Commission Delegated Regulation (EU) 2025/1190.
DORA distinguishes regular resilience testing from threat-led penetration testing. Annual testing of ICT systems supporting critical or important functions does not mean an annual TLPT. For selected entities, Article 26 generally requires TLPT at least every three years. The authority may adjust frequency to the risk profile. Microenterprises and the entities listed in Article 16(1) are excluded from this TLPT requirement.
Size is not the only factor. Article 2 of Regulation 2025/1190 combines sector-specific criteria with significance, interconnectedness, substitutability and ICT risk. For banks it identifies, in particular, G-SIIs, O-SIIs and institutions belonging to them. Payment institutions, electronic money institutions, market infrastructures, certain trading venues and certain insurers are assessed under their respective criteria. The authority can decide against inclusion on the basis of its overall assessment. Institutions should therefore establish their position with the responsible TLPT authority and record the outcome.
A TLPT covers several or all critical or important functions and is performed on live production systems. Scope follows the ICT systems, processes and technologies supporting those functions. Relevant third parties belong in that assessment. The entity proposes the scope and the authority validates it. Joint or pooled testing requires the prescribed coordination. A provider’s existing test report alone is not evidence that the entity has completed its own TLPT.
A small control team manages the exercise within the institution. The authority’s test manager oversees the process. An external threat-intelligence provider develops the threat assessment and testers execute the agreed scenarios. The blue team provides operational defence. Agree communication, confidentiality, stopping authority and production safeguards in advance. The financial entity remains responsible.
| Role | Main task |
|---|---|
| Control team | Planning, risk, direction and agreed escalation |
| Threat intelligence | Threat assessment and realistic attack scenarios |
| Testers / red team | Controlled execution and a traceable report |
| Blue team | Detection and response within operations |
| TLPT authority | Validation, oversight and attestation |
The RTS require initiation information within three months of notification. Within six months, the entity submits a scope document approved by its management body; approval by the authority is a further step before testing. The active red-team phase lasts at least twelve weeks. Reports, replaying attacks and improvement exercises follow the test. Plan preparation, active testing and closure as distinct parts of the project.
Record root cause, remediation, priority, owner and expected completion for each relevant vulnerability. Document residual risks and dependencies. The authority’s attestation supports mutual recognition of the test. It is not a certificate of lasting immunity from attacks. Internal oversight should establish that actions were implemented and their effectiveness checked.
The requirement applies to entities identified by their supervisor under DORA and the RTS. Consider sector-specific criteria together with the authority’s overall assessment.
DORA Article 26(8) requires significant credit institutions under the SSM Regulation to use external testers. Other entities face additional conditions and supervisory approval when using internal testers.
The required outputs include red-team and blue-team reports, a test summary and a remediation plan. The RTS give them distinct submission steps and deadline triggers. The institution continues to track remediation owners and evidence.
ISO/IEC 27001 defines requirements for an information security management system. IT-Grundschutz adds a concrete methodology and building blocks. Begin with scope and the evidence you need.
T-NEX advises banks and insurers on software projects and GRC processes, with functional specifications, technical planning and an agreed implementation scope.
Explore serviceBring a concrete task. Together, we will define what the application needs to do.
Discuss your project