Skip to content
    August 23, 2026| Top Floor Team| 11 min read

    Does DORA Require Threat-Led Penetration Testing?

    The number of financial entities that decide for themselves whether they owe a threat-led penetration test is zero. TLPT under DORA applies to a designated subset, and the designation is made by your competent authority rather than by you, your auditor or your consultant. The Central Bank of Ireland states it plainly: "Only a subset of FEs are required to perform advanced TLPT under DORA", and describes how the answer reaches you, which is that "an identification exercise is carried out annually and any additional firms identified will be engaged with on a timely basis", applying "only to firms that meet the specific DORA TLPT selection criteria." The contrarian consequence is one most vendors will not volunteer: if nobody has contacted you, the correct posture is not to buy a TLPT. It is to be ready to be designated, which is a much smaller and much cheaper project.

    What follows is who decides and on what basis, what a threat-led test actually is compared with the testing you already buy, the narrow internal-tester exception, what happens to you if you are the vendor rather than the entity, and the case for spending nothing on this today.

    Key takeaways

    • TLPT applies to a designated subset of financial entities, not to everyone in DORA scope, according to the Central Bank of Ireland.
    • Designation is a supervisory act. The MFSA describes the authority assessing a firm's impact, systemic characteristics and ICT risk profile under the TLPT regulatory technical standards.
    • The relevant technical standards are Commission Delegated Regulation (EU) 2025/1190, adopted under DORA Article 26(11).
    • The ECB's TIBER-EU framework is the operational handbook, and the ECB says a test run under it makes an entity DORA TLPT-compliant assuming the formal requirements set by competent authorities are met.
    • Internal testers are possible but narrow, and the ECB notes that significant credit institutions identified under DORA cannot use them at all.

    Who decides, and on what basis

    Two documents from two competent authorities answer this without ambiguity, and neither of them is a vendor.

    The MFSA's national implementation document is the clearer of the two on mechanics. It states that Article 26 of DORA identifies the financial entities within scope of a TLPT, and that the relevant regulatory technical standards, which it names as Regulatory Technical Standards (EU) 2025/1190 adopted under Article 26(11), further specify at Article 2(1) that the authority "shall assess whether a FE's impact, systemic characteristics, and ICT risk profile" determine whether the entity is required to test, and separately that the authority "shall require the FE listed in Article 2(2) of the RTS" to test. So there are two routes into scope: an assessment against criteria, and a list.

    The Central Bank of Ireland describes the same thing from the receiving end. It has "engaged directly with in-scope firms", runs the identification exercise annually, and notes that it applies only to firms meeting the specific selection criteria.

    Two things follow that are worth being blunt about. Your size alone does not settle it, because impact and systemic characteristics are not the same variable as headcount or balance sheet. And no consultancy can perform this determination on your behalf. A firm that tells you it has assessed you as in scope for TLPT has told you what it would like to sell, not what a supervisor has decided.

    For entities that are not designated, the general testing duties still apply, and they are a different regime with a different cadence. Our DORA service page sets out the Article 24 and Article 25 testing programme alongside the Article 26 TLPT cadence, and the honest distinction between the two is the whole point of this article.

    A threat-led test is not a bigger penetration test

    The vocabulary invites the wrong mental model. A TLPT is not a longer engagement with a larger scope statement; it is a different exercise with different participants and a different risk profile.

    The ECB's TIBER-EU framework document describes a standard for "implementing realistic intelligence-led red team tests on live production systems throughout (and beyond) the European Union". Production is the load-bearing word. The ECB's own framework document is candid that this creates real exposure, describing the risks associated with testing live production systems including the possibility of an unexpected system crash or damage to critical live production systems, which is why the framework wraps the exercise in a control team, written notifications and a formal risk-management posture rather than a scope document and a start date.

    The other structural difference is who inside your organisation knows. A TIBER-style exercise deliberately keeps the defending team unaware, which is why the framework spends as much text on the control team and its lead as it does on the testers. That is an organisational design problem, not a procurement one, and it is the part firms consistently underestimate.

    The ECB also sets expectations on frequency in a way worth quoting exactly, because it is a framework norm rather than a legal cadence: its framework document warns against conducting a TIBER-EU test too frequently, "with 3 years intervals being the norm."

    We are not publishing a price for any of this, and the general engagement economics are on our penetration testing cost breakdown rather than restated here. The relevant point for budgeting is that a threat-led exercise is not a line item you can benchmark against a web application test, because the threat intelligence phase, the control team overhead and the remediation cycle are all additional.

    TIBER-EU is the how, and it is doing double duty

    The ECB describes TIBER-EU as "a European framework for threat intelligence-based ethical red-teaming", and its framework document states directly that "the TLPT-related requirements under DORA are included in the detailed TIBER-EU testing process, so that financial entities completing a test under a national or European-level implementation of the TIBER-EU framework will be DORA TLPT-compliant, assuming they fulfil the formal TLPT-related requirements set by the competent authorities."

    Read that qualifier. Running a TIBER-shaped exercise privately does not produce compliance. The framework works because a TLPT authority is inside the process: the ECB describes the test manager signing an attestation at the end of each test, and that attestation is what provides the grounds for mutual recognition between jurisdictions. An attestation is issued by an authority, not purchased from a supplier.

    That also explains why "we can run you a TIBER-style test" is an incomplete offer. The testing is procurable. The designation, the authority involvement and the attestation are not.

    Worth knowing for group structures: the MFSA notes that its national document does not apply to credit institutions classified as significant entities by the Single Supervisory Mechanism, where the European Central Bank is the competent TLPT authority. If your group contains a significant institution, the authority you are dealing with may not be your usual national one.

    The internal-tester question, which is narrower than it sounds

    Firms with a capable internal red team ask this immediately, and the answer is a qualified yes with conditions that most internal teams will not meet.

    The Central Bank of Ireland sets out that DORA Chapter IV establishes the conditions for using internal testers, and lists among them that such use "has been approved by the relevant competent authority or by the single public authority designated in accordance with Article 26(9) and (10)", and that the competent authority "has verified that the financial entity has sufficient dedicated resources and ensured that conflicts of interest are avoided throughout the design and execution phases of the test."

    The ECB adds a hard exclusion in its framework document: significant credit institutions as identified under DORA cannot use internal testers at all.

    Where internal testers are permitted, the ECB is unenthusiastic in a useful way. Its framework observes that internal testers have an advantage in knowing the internal environment and processes, that handling that internal knowledge is complicated, and recommends that rather than using only internal testers, an experienced external red team test manager join them to bring a fresh perspective. That is a design recommendation you can act on today whether or not you are ever designated, because it is also true of ordinary offensive testing.

    If you are the vendor rather than the entity

    Most readers of this article are not designated financial entities. They are the technology companies those entities buy from, and the question that actually reaches them is a contractual one.

    The obligation arrives through your customer's agreements. The contractual set an EU financial entity must impose on ICT third-party providers is covered in DORA contract requirements for vendors, and participation in the entity's threat-led penetration testing is one of the terms that shows up in it. The Central Bank of Ireland's guidance to firms on contracts names the same thing, advising that agreements include the inclusion of the third-party provider in the financial entity's digital operational resilience testing and advanced TLPT "where relevant".

    So the vendor question is not "are we in scope for TLPT", because you are not a financial entity. It is "can we support a customer's test without a crisis": who at your company would receive the notification, whether your contract already commits you to participate, whether your support and change-management processes can operate while an exercise is running against a shared platform, and whether you can distinguish a test from a real incident. For non-EU vendors, whether DORA applies to you at all is the prior question and the answer is usually contractual rather than regulatory.

    When to spend nothing

    This is the section our own commercial interest argues against, so here it is first rather than last.

    If you have not been contacted, do not buy a TLPT. The exercise exists to be run under an authority's supervision, with an attestation at the end. Bought privately, you have purchased an expensive red team engagement and called it something else, and you cannot present it as satisfying an obligation you have not been given.

    If you are a small entity, or an ICT provider, the general testing programme is the work. Ordinary vulnerability management and independent testing against your critical systems is where the money goes, and it is what a customer questionnaire will actually ask about.

    If you already run mature offensive testing, the gap is probably governance, not testing. The parts of TLPT that break unprepared organisations are the control team, the notification discipline and the ability to keep a defending team genuinely unaware. Those are cheap to design and expensive to improvise.

    And if you have been designated, your first call is your authority, not a vendor. The process is set by them, including who may test and what the deliverables are.

    Where Top Floor fits

    Our DORA practice does scoping support: whether your services touch a critical or important function, what the contractual set obliges, and what participation in a customer's exercise would actually require of your team. Offensive testing itself sits under penetration testing, and for firms carrying DORA alongside other frameworks, running one control set rather than several is what compliance as a service is for.

    What we do not do is designate anyone, issue attestations, or tell you that you are in scope for TLPT. Those belong to a competent authority, and a firm claiming otherwise is describing a role that does not exist.

    How to decide this week

    Establish, as a fact rather than an assumption, whether your entity has been contacted by its competent authority about TLPT. Ask the person who receives supervisory correspondence, not the security team.

    If the answer is no, stop the TLPT project and put the money into the general testing programme instead.

    If the answer is yes, identify who your control team lead would be, and confirm that person can keep an exercise confidential from their own colleagues. That single appointment determines more about how the test goes than the choice of tester.

    If you are a vendor, search your largest financial-sector contracts for testing participation clauses and find out what you have already committed to. Discovering that during a customer's exercise is the expensive version.

    Frequently asked questions

    Does every financial entity under DORA have to do threat-led penetration testing?

    No. The Central Bank of Ireland states that only a subset of financial entities are required to perform advanced TLPT under DORA, and that it engages directly with in-scope firms through an identification exercise carried out annually. Entities that are not designated still carry DORA's general digital operational resilience testing duties, which are a separate and lighter regime. Because designation is a supervisory act, no consultancy or auditor can place you in scope or out of it.

    Who decides whether we are in scope for TLPT?

    Your competent authority. The MFSA describes the assessment as running on the criteria in the regulatory technical standards adopted under DORA Article 26(11), Commission Delegated Regulation (EU) 2025/1190, whose Article 2(1) has the authority assess a financial entity's impact, systemic characteristics and ICT risk profile, with a further category of entities listed at Article 2(2) that the authority is to require to test. Where a group contains a credit institution classified as significant under the Single Supervisory Mechanism, the European Central Bank is the competent TLPT authority rather than the national one.

    Can we use our own internal red team?

    Sometimes, under conditions, and not at all for some entities. The Central Bank of Ireland notes that the conditions for internal testers include prior approval by the relevant competent authority or the designated single public authority, and verification by the authority that the entity has sufficient dedicated resources and that conflicts of interest are avoided throughout design and execution. The ECB's TIBER-EU framework states that significant credit institutions identified under DORA cannot use internal testers, and where internal testers are permitted the ECB recommends that an experienced external red team test manager join them rather than the test being run internally alone.

    We are a software vendor, not a bank. Does this reach us?

    Only through your customer's contract, which is usually enough. Financial entities are obliged to impose a specific contractual set on their ICT third-party providers, and participation in the entity's testing, including advanced threat-led penetration testing where relevant, is among the terms the Central Bank of Ireland advises firms to include. The practical preparation is knowing who at your company would receive a test notification, whether an exercise against a shared platform can run without breaking your change controls, and whether your on-call team could tell a sanctioned test from a genuine incident.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.