Home › DORA › Who Needs TLPT

DORA Compliance

Who Needs to Do TLPT Under DORA?

Key takeaway

TLPT is not for everyone. Only financial entities identified for it by their competent authority must perform threat-led penetration testing. Identification follows the criteria in DORA and the TLPT technical standard — regulatory category, systemic importance, ICT risk profile and impact on financial stability — and should never be assumed from size alone.

One of the most common DORA mistakes is assuming that because you run penetration tests, you must do TLPT — or that any large firm automatically qualifies. This page explains how identification actually works.

The two-tier testing model

DORA sets two tiers of testing. Every non-micro entity must run a baseline resilience-testing programme (Articles 24–25). Only entities identified by their competent authority must additionally perform TLPT (Articles 26–27). The baseline tier applies far more widely than TLPT.

See DORA resilience testing for the baseline obligation.

How competent authorities identify firms

Identification is authority-led, not self-assessed. Authorities apply the criteria in DORA and the TLPT technical standard, weighing factors such as:

  • The entity’s regulatory category

  • Its systemic importance and interconnectedness

  • Its ICT risk profile

  • Its potential impact on financial stability

The identified set is broader than just the largest banks, and authorities can include entities across categories — but it remains a subset of all DORA entities. Authorities may also adjust the required frequency for an identified firm.

The Irish position

In Ireland, the Central Bank of Ireland is the competent authority for TLPT. It engages directly with financial entities identified for TLPT, carries out the identification exercise annually, and contacts any additional firms identified on a timely basis.

See DORA in Ireland: the Central Bank’s role.

Do not assume

A quiz or self-check can help you understand the criteria, but it cannot make you (or exempt you from being) identified. Only your competent authority determines identification, through formal notification.

Frequently asked questions

How do I know if we are identified for TLPT?

Your competent authority tells you through a formal identification and notification process. In Ireland, the Central Bank engages directly with identified firms. You should not infer identification from size alone.

We are a large firm — do we automatically need TLPT?

Not automatically. Size is one factor among several; identification depends on the authority’s assessment against the criteria in DORA and the TLPT technical standard.

Next step

Want help understanding your obligation and preparing if you are identified? Talk to CyberLabs.