Article

DORA TLPT: who needs testing and how is it prepared?

TLPT is advanced testing for financial entities identified by the supervisor. Selection follows DORA and Commission Delegated Regulation (EU) 2025/1190.

T-NEX GmbHFirst version: Updated: Editorial policy
In daily work

Distinguish the testing programme from TLPT

DORA distinguishes regular resilience testing from threat-led penetration testing. Annual testing of ICT systems supporting critical or important functions does not mean an annual TLPT. For selected entities, Article 26 generally requires TLPT at least every three years. The authority may adjust frequency to the risk profile. Microenterprises and the entities listed in Article 16(1) are excluded from this TLPT requirement.

Overview

The supervisor identifies the entities

Size is not the only factor. Article 2 of Regulation 2025/1190 combines sector-specific criteria with significance, interconnectedness, substitutability and ICT risk. For banks it identifies, in particular, G-SIIs, O-SIIs and institutions belonging to them. Payment institutions, electronic money institutions, market infrastructures, certain trading venues and certain insurers are assessed under their respective criteria. The authority can decide against inclusion on the basis of its overall assessment. Institutions should therefore establish their position with the responsible TLPT authority and record the outcome.

Overview

Derive scope from critical functions

A TLPT covers several or all critical or important functions and is performed on live production systems. Scope follows the ICT systems, processes and technologies supporting those functions. Relevant third parties belong in that assessment. The entity proposes the scope and the authority validates it. Joint or pooled testing requires the prescribed coordination. A provider’s existing test report alone is not evidence that the entity has completed its own TLPT.

Overview

Agree roles and boundaries before testing

A small control team manages the exercise within the institution. The authority’s test manager oversees the process. An external threat-intelligence provider develops the threat assessment and testers execute the agreed scenarios. The blue team provides operational defence. Agree communication, confidentiality, stopping authority and production safeguards in advance. The financial entity remains responsible.

RoleMain task
Control teamPlanning, risk, direction and agreed escalation
Threat intelligenceThreat assessment and realistic attack scenarios
Testers / red teamControlled execution and a traceable report
Blue teamDetection and response within operations
TLPT authorityValidation, oversight and attestation
Overview

Allow enough time for each phase

The RTS require initiation information within three months of notification. Within six months, the entity submits a scope document approved by its management body; approval by the authority is a further step before testing. The active red-team phase lasts at least twelve weeks. Reports, replaying attacks and improvement exercises follow the test. Plan preparation, active testing and closure as distinct parts of the project.

Overview

Close with accountable remediation

Record root cause, remediation, priority, owner and expected completion for each relevant vulnerability. Document residual risks and dependencies. The authority’s attestation supports mutual recognition of the test. It is not a certificate of lasting immunity from attacks. Internal oversight should establish that actions were implemented and their effectiveness checked.

FAQ

Frequently asked questions

Does every bank have to carry out a TLPT?

The requirement applies to entities identified by their supervisor under DORA and the RTS. Consider sector-specific criteria together with the authority’s overall assessment.

Can a significant credit institution use internal testers?

DORA Article 26(8) requires significant credit institutions under the SSM Regulation to use external testers. Other entities face additional conditions and supervisory approval when using internal testers.

Which documents belong to closure?

The required outputs include red-team and blue-team reports, a test summary and a remediation plan. The RTS give them distinct submission steps and deadline triggers. The institution continues to track remediation owners and evidence.

Related options

You may also be interested in these.

Which task would you like to solve next?

Bring a concrete task. Together, we will define what the application needs to do.

Discuss your project