TIBER-EU is the European Central Bank’s framework for intelligence-led red-team testing, developed before DORA. DORA’s TLPT requirements were designed to align with it, so a TIBER-EU test may be used to meet the obligation insofar as it is consistent with DORA and the TLPT technical standard. Ireland’s implementation is TIBER-IE.
If you have heard TIBER-EU and TLPT used interchangeably, this page explains how they actually relate.
What TIBER-EU is
TIBER-EU (Threat Intelligence-Based Ethical Red-teaming for the EU) is the ECB’s framework for intelligence-led red-team testing of financial institutions. It has been used since 2018–19 as a voluntary programme, and defines a standard methodology and provider requirements.
How it maps to DORA
DORA’s TLPT requirements were designed to align with TIBER-EU. In February 2025, TIBER-EU was updated to align with DORA’s TLPT technical standards. As a result, a TIBER-EU test conducted under the updated guidance may be used to meet the DORA TLPT obligation insofar as it is consistent with DORA and the RTS — it does not ‘automatically’ satisfy DORA in every case.
The five workstreams in TIBER terms
TIBER-EU frames testing around preparation, threat intelligence, red teaming and closure, with remediation following — mirroring the phases in the DORA delegated regulation. See TLPT explained.
TIBER-IE in Ireland
Ireland’s implementation is TIBER-IE, with the Central Bank of Ireland designated for TLPT matters. See DORA in Ireland.
Recognition of prior tests
Entities that have already conducted TIBER-EU or equivalent tests may be able to have them recognised toward the DORA obligation, subject to competent-authority approval and the conditions in the RTS. Engage your authority early.
Wondering how TIBER-IE applies to you? Talk to CyberLabs.