Home › DORA › TLPT Explained

DORA Compliance

Threat-Led Penetration Testing (TLPT) Explained

Key takeaway

TLPT is the advanced testing tier under DORA Articles 26–27: an intelligence-led red-team exercise against live production systems, required only for financial entities identified by their competent authority. It is far more demanding than a standard penetration test, and firms identified for it should plan promptly after notification.

TLPT is the part of DORA that most often causes confusion — and it is where the stakes are highest. This page explains what it is, who has to do it, how it works, and how to prepare.

What TLPT is

TLPT is an intelligence-led red-team exercise conducted against live production systems, guided by real threat intelligence. The blue team — the personnel responsible for security detection and response — is not told in advance, while a small control team knows about the exercise and manages its safety, secrecy and coordination. That covertness is the point: TLPT measures genuine resilience, not a rehearsed response.

Who is identified for TLPT

Only financial entities identified for TLPT by their competent authority must perform it. Identification follows the criteria in DORA and the TLPT technical standard, including the entity’s regulatory category, systemic importance, ICT risk profile and potential impact on financial stability. Only a subset of financial entities is identified. In Ireland, the Central Bank engages directly with identified firms and repeats the identification exercise annually.

Identification should never be assumed from size alone. See Who needs to do TLPT?.

How TLPT is structured

Flow diagram of the five TLPT phases: preparation, threat intelligence, red teaming, closure, remediation
The five phases of a TLPT engagement, aligned with TIBER-EU.

The delegated regulation frames TLPT around a preparation phase, a testing phase and a closure phase, followed by a remediation plan. In practice a programme runs through these workstreams:

  1. Preparation and scoping — define critical functions and systems in scope, engage the competent authority, procure providers.

  2. Threat intelligence — an external threat-intelligence provider produces a targeted report profiling likely attackers and their techniques, which shapes the attack scenarios.

  3. Red teaming (active testing) — the red team executes the scenarios against live systems. This active phase must last at least 12 weeks.

  4. Closure — the red team reveals its activity and works with the blue team (purple teaming) to analyse detection and response gaps.

  5. Remediation — findings are documented and a remediation plan is agreed, with the process closing on a supervisory attestation.

The roles involved

Diagram of TLPT roles: TLPT authority, control team, external threat-intelligence provider, red team, and the unaware blue team
The roles in a TLPT — and why the blue team is kept in the dark.
  • Control team — a small internal group that manages the exercise and is aware it is happening.

  • Threat-intelligence provider — always external and independent; produces the targeted threat intelligence.

  • Red team — executes the attack scenarios.

  • Blue team — the firm’s defenders, not told in advance.

Internal vs external testers

DORA permits internal red teams for up to two of every three cycles, but the threat-intelligence provider must always be external, and at least every third test must use an external red team. The competent authority is involved throughout.

Frequency and timing

Entities identified for TLPT must perform it at least once every three years, unless their competent authority adjusts the frequency based on risk. There is no single fixed EU-wide deadline: the timing of a first test is set by the authority through a formal notification process.

Why to plan early

A TLPT is a lengthy exercise. The active red-team testing phase alone must last at least 12 weeks, with preparation, reporting, replay, purple teaming and remediation work on either side. Firms identified for TLPT should therefore begin planning promptly after notification.

Frequently asked questions

Who has to do TLPT?

Only financial entities identified for TLPT by their competent authority, based on the criteria in DORA and the TLPT technical standard. Only a subset of entities is identified; in Ireland the Central Bank engages directly with identified firms and repeats the exercise annually.

How is TLPT different from a penetration test?

A standard pentest scopes a defined system, runs for a week or two, and the security team knows about it. TLPT is covert, intelligence-led, runs on live production systems, and ends with supervisory attestation. See Pentest vs TLPT.

Can we use internal testers?

Partly. Internal red teams are allowed for up to two of every three cycles, but the threat-intelligence provider must always be external, and at least every third test must use an external red team.

Next step

Unsure whether your firm is identified for TLPT, or what a test would involve? See our DORA testing services.