DORA · TIBER-EU
Threat-led penetration testing, explained
TLPT is the most advanced testing DORA requires – an intelligence-led red-team attack on your live systems, modelled on real adversaries. Understand who must do it, and how an engagement actually runs.
- Based on DORA & TIBER-EU
- Primary sources linked
- Updated 2026
What is TLPT
A real attack, run safely and by the book
Threat-led penetration testing simulates how a real adversary would attack your organisation – against live systems, guided by genuine threat intelligence.
Threat-led penetration testing (TLPT) is an advanced form of security testing in which skilled testers emulate the tactics, techniques and procedures of real threat actors against an organisation’s live production systems. It measures not just whether a flaw exists, but whether the organisation can prevent, detect and respond to a realistic attack end to end.
Under the EU DORA regulation, financial entities identified by their competent authority must undergo TLPT at least every three years. DORA’s TLPT builds on TIBER-EU – the European framework for threat intelligence-based ethical red-teaming – which several EU central banks already operate.
It is deliberately demanding: real intelligence, live systems, strict rules of engagement, and testers who meet high independence and competence criteria. This site walks through what that means in practice.
What makes it different
Four things that set TLPT apart
TLPT is a different discipline from routine penetration testing.
- INTEL-LED
Intelligence-led
Scenarios are built from real threat intelligence about the adversaries actually targeting your sector – not a generic checklist.
- LIVE
Live production
Testing runs against real, live systems for maximum realism, under strict, agreed rules of engagement to keep it safe.
- END-TO-END
Prevent, detect, respond
It measures the full chain: can attackers get in, and just as importantly, do your defenders notice and react in time?
- GOVERNED
Strictly governed
Defined roles, authority oversight and testers who meet strict independence and competence criteria under DORA and TIBER-EU.
Who's in scope
When TLPT is required
TLPT is not for everyone – competent authorities identify which financial entities must perform it, but for those they name it is mandatory.
- Required
Entities authorities identify
Under Article 26(8), competent authorities identify the financial entities required to perform TLPT. "Significant entities" is common shorthand for them, not a DORA category.
Note: Identified by authorities on size, risk and systemic importance.
- Cadence
At least every 3 years
In-scope entities must complete a TLPT at least once every three years, though authorities may adjust the frequency.
Note: Minimum once per three-year cycle.
- Basis
Built on TIBER-EU
DORA’s TLPT follows the TIBER-EU framework, which several EU jurisdictions already run as TIBER-XX.
Note: Harmonised across the EU on a common framework.
- Testers
Strict tester criteria
Threat-intelligence and red-team providers must meet strict independence, competence and reputation requirements.
Note: Not any pen-test provider qualifies for TLPT.
The engagement
How a TLPT engagement runs
A TLPT unfolds over months in defined phases. Scrub through to see what happens at each stage – and which team leads it.
Interactive mode is not available. You can read the full reference content below. No answers are assessed and no result is calculated.
Preparation & scoping
Control Team
The entity’s Control Team, with the authority, defines the critical functions in scope, agrees the rules of engagement, and procures the threat-intelligence and red-team providers.
A small, trusted Control Team manages the test; the Blue Team remains unaware.
Threat intelligence
TI Provider
A threat-intelligence provider produces a targeted report on the adversaries most likely to attack the entity, which is turned into realistic attack scenarios.
Red teaming
Red Team
During an active phase of at least twelve weeks under the TLPT RTS, the red team attempts to achieve the scenario objectives against live production systems – safely, within the agreed rules of engagement.
Detection & response
Blue Team (unaware)
During the active red-team phase, the organisation’s defenders – who do not know a test is underway – detect and respond as they would to a real attack. Their performance is measured.
Purple teaming
Red + Blue
Red and blue teams walk through the engagement together, comparing what the attackers did with what the defenders saw, and identifying the gaps.
Closure & remediation
Control Team
Findings are reported, a remediation plan is agreed, and – depending on the jurisdiction – an attestation confirms the test met the framework’s requirements.
The point is improvement, not a pass/fail score.
- 1
- 2
- 3
- 4
- 5
- 6
Preparation & scoping
The entity’s Control Team, with the authority, defines the critical functions in scope, agrees the rules of engagement, and procures the threat-intelligence and red-team providers.
A small, trusted Control Team manages the test; the Blue Team remains unaware.
Threat intelligence
A threat-intelligence provider produces a targeted report on the adversaries most likely to attack the entity, which is turned into realistic attack scenarios.
Red teaming
During an active phase of at least twelve weeks under the TLPT RTS, the red team attempts to achieve the scenario objectives against live production systems – safely, within the agreed rules of engagement.
Detection & response
During the active red-team phase, the organisation’s defenders – who do not know a test is underway – detect and respond as they would to a real attack. Their performance is measured.
Purple teaming
Red and blue teams walk through the engagement together, comparing what the attackers did with what the defenders saw, and identifying the gaps.
Closure & remediation
Findings are reported, a remediation plan is agreed, and – depending on the jurisdiction – an attestation confirms the test met the framework’s requirements.
The point is improvement, not a pass/fail score.
Simplified from the TIBER-EU process. Activities overlap: detection and response occur during active red teaming. Follow the applicable TLPT RTS and your authority’s instructions for required timings and deliverables.
The facts
TLPT at a glance
An advanced, harmonised testing regime – in force now for the entities that matter most.
Each figure links to its primary source. Details vary by jurisdiction; confirm your obligations with your authority or a qualified adviser.
For entities in TLPT scope
Preparing for a test that touches live systems
TLPT is high-stakes: real attacks on production, strict governance, and a defending team that must not be tipped off. Preparation is everything.
DORA requires the financial entities that competent authorities identify under Article 26(8) to carry out threat-led penetration testing at least every three years, under the applicable TLPT technical standards, with TIBER-EU providing an aligned process, and using testers that meet strict independence and competence requirements.
-
Get the baseline right first
TLPT sits on top of a mature testing programme. Fix the known issues from routine testing before staging a full red-team engagement.
-
Build a trusted Control Team
A small, discreet control group runs the engagement while keeping the defenders genuinely unaware – essential for a realistic detection test.
-
Choose qualified providers
Threat-intelligence and red-team providers must meet strict criteria. Vet them early; not every pen-test firm qualifies.
-
Plan for remediation
The value is in acting on findings. Line up the capacity to remediate and retest, not just to run the exercise.
Guides
Go deeper
Plain-English guides to TLPT: what it is, how it differs from standard testing, and how to prepare.
-
What is TLPT? Threat-led penetration testing explained
TLPT is an intelligence-led red-team attack on your live systems, mandated by DORA for the financial entities authorities identify. Here is what it involves.
Read guide -
TLPT vs penetration testing: what is the difference?
A standard pen test checks a system for flaws. TLPT tests agreed critical or important functions against realistic, intelligence-led scenarios. Here is how they compare.
Read guide -
How to prepare for a TLPT engagement
TLPT touches live systems and a defending team that must stay unaware. Preparation sets the risk controls and conditions needed for a useful test.
Read guide
Frequently asked questions
Short, clear answers
What is threat-led penetration testing (TLPT)?
TLPT is advanced, intelligence-led testing where skilled testers emulate real threat actors against an organisation’s live production systems, measuring whether it can prevent, detect and respond to a realistic attack.
Who has to do TLPT under DORA?
The financial entities that competent authorities identify under Article 26(8) – widely called "significant entities", though DORA itself does not use that label. Other entities run DORA’s baseline testing programme but are not required to perform full TLPT.
How often is TLPT required?
At least once every three years for the entities authorities identify, though they can adjust the frequency based on risk.
How is TLPT different from a normal penetration test?
A standard pen test checks specific systems for flaws. TLPT tests in-scope people, processes and technology – against a realistic, intelligence-led attack on live systems, and measures detection and response too.
What is TIBER-EU?
TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) is the European framework, published by the ECB in 2018, on which DORA’s TLPT is based. Several EU jurisdictions run national versions (TIBER-XX).
Is TLPT safe to run on live systems?
Live-system testing carries operational risk. Agreed rules, stop conditions, a trusted control team and experienced testers reduce that risk while preserving realism – most of which is settled before the engagement starts.
Who can carry out TLPT?
Threat-intelligence and red-team providers that meet strict independence, competence and reputation criteria set out in the framework – not every penetration-testing provider qualifies.