TLPT under DORA
TLPT is advanced testing for financial entities identified by the supervisor. Selection follows DORA and Commission Delegated Regulation (EU) 2025/1190.
ISO/IEC 27001 defines requirements for an information security management system. IT-Grundschutz adds a concrete methodology and building blocks. Begin with scope and the evidence you need.
Both approaches support systematic information security management. The organisation assigns responsibility, assesses risks, implements measures and checks their effectiveness. Define the information domain: business processes, information, applications, technology, people and providers. A certificate covering a narrow area says little about a service operated outside that scope.
ISO/IEC 27001:2022 is an ISMS requirements standard. Its publicly documented edition includes a 2024 amendment. IT-Grundschutz provides a structured implementation approach through BSI standards and the compendium. The approaches can be combined: BSI offers ISO 27001 certification on the basis of IT-Grundschutz.
| Aspect | ISO/IEC 27001 | BSI IT-Grundschutz |
|---|---|---|
| Starting point | Management-system requirements | Methodology, modelling and building blocks |
| Choosing measures | Own risk assessment and treatment | Relevant modules, protection needs and additional risk analysis |
| Documentation | Scope, risks, reasons for measures and effectiveness | Information domain, module mapping, implementation and risks |
| Evidence | ISMS conformity within the certified scope | Implementation evidence or certification, depending on approach |
| Selection question | How will an appropriate risk process be run? | How does the information domain fit the methodology? |
BSI Standard 200-2 distinguishes basic, core and standard protection. Basic protection provides an entry point. Core protection initially concentrates on particularly important assets and processes. Standard protection develops a comprehensive security process for the selected information domain. Starting with basic protection is not equivalent to full ISO 27001 certification based on IT-Grundschutz.
Working example: a bank evaluates a document-processing service. Under either approach, define the relevant data, people, applications, infrastructure and external dependencies. Then assess risks, protection needs and measures that operate effectively. A small exercise using this same information domain can reveal which approach fits the existing organisation and evidence practices.
Check the standard version, named legal entity, scope, issuer and validity. For a provider, establish whether the purchased service and relevant operational components are included. A certificate does not establish that every control works in every customer deployment. Request additional evidence in relation to the actual service.
An ISMS can support the organisation of risks and controls. DORA adds specific obligations for entities in scope, including incident reporting, testing and ICT third parties. Map each DORA requirement to an existing process and evidence. A certificate does not establish that all DORA obligations are met. Revisit the mapping when standards or the Grundschutz methodology change.
That does not fully describe the relationship. ISO 27001 is an ISMS requirements standard. IT-Grundschutz is a methodology with implementation guidance and its own route to ISO 27001 certification.
It depends on the existing ISMS, scope, protection needs and required evidence. Use the same example to compare additional effort.
No. Check the scope and map the relevant DORA obligations individually.
TLPT is advanced testing for financial entities identified by the supervisor. Selection follows DORA and Commission Delegated Regulation (EU) 2025/1190.
T-NEX advises banks and insurers on software projects and GRC processes, with functional specifications, technical planning and an agreed implementation scope.
Explore serviceBring a concrete task. Together, we will define what the application needs to do.
Discuss your project