TLPT is not for everyone. Only financial entities identified for it by their competent authority must perform threat-led penetration testing. Identification follows the criteria in DORA and the TLPT technical standard — regulatory category, systemic importance, ICT risk profile and impact on financial stability — and should never be assumed from size alone.
One of the most common DORA mistakes is assuming that because you run penetration tests, you must do TLPT — or that any large firm automatically qualifies. This page explains how identification actually works.
The two-tier testing model
DORA sets two tiers of testing. Every non-micro entity must run a baseline resilience-testing programme (Articles 24–25). Only entities identified by their competent authority must additionally perform TLPT (Articles 26–27). The baseline tier applies far more widely than TLPT.
See DORA resilience testing for the baseline obligation.
How competent authorities identify firms
Identification is authority-led, not self-assessed. Authorities apply the criteria in DORA and the TLPT technical standard, weighing factors such as:
The entity’s regulatory category
Its systemic importance and interconnectedness
Its ICT risk profile
Its potential impact on financial stability
The identified set is broader than just the largest banks, and authorities can include entities across categories — but it remains a subset of all DORA entities. Authorities may also adjust the required frequency for an identified firm.
The Irish position
In Ireland, the Central Bank of Ireland is the competent authority for TLPT. It engages directly with financial entities identified for TLPT, carries out the identification exercise annually, and contacts any additional firms identified on a timely basis.
See DORA in Ireland: the Central Bank’s role.
A quiz or self-check can help you understand the criteria, but it cannot make you (or exempt you from being) identified. Only your competent authority determines identification, through formal notification.
Frequently asked questions
How do I know if we are identified for TLPT?
Your competent authority tells you through a formal identification and notification process. In Ireland, the Central Bank engages directly with identified firms. You should not infer identification from size alone.
We are a large firm — do we automatically need TLPT?
Not automatically. Size is one factor among several; identification depends on the authority’s assessment against the criteria in DORA and the TLPT technical standard.
Want help understanding your obligation and preparing if you are identified? Talk to CyberLabs.