tlpt

DORA · TIBER-EU

Threat-led penetration testing, explained

TLPT is the most advanced testing DORA requires — an intelligence-led red-team attack on your live systems, modelled on real adversaries. Understand who must do it, and how an engagement actually runs.

  • Based on DORA & TIBER-EU
  • Vendor-neutral
  • Updated 2026

What is TLPT

A real attack, run safely and by the book

Threat-led penetration testing simulates how a real adversary would attack your organisation — against live systems, guided by genuine threat intelligence.

Threat-led penetration testing (TLPT) is an advanced form of security testing in which skilled testers emulate the tactics, techniques and procedures of real threat actors against an organisation’s live production systems. It measures not just whether a flaw exists, but whether the organisation can prevent, detect and respond to a realistic attack end to end.

Under the EU DORA regulation, significant financial entities must undergo TLPT at least every three years. DORA’s TLPT builds on TIBER-EU — the European framework for threat intelligence-based ethical red-teaming — which several EU central banks already operate.

It is deliberately demanding: real intelligence, live systems, strict rules of engagement, and testers who meet high independence and competence criteria. This site walks through what that means in practice.

What makes it different

Four things that set TLPT apart

TLPT is a different discipline from routine penetration testing.

  1. INTEL-LED

    Intelligence-led

    Scenarios are built from real threat intelligence about the adversaries actually targeting your sector — not a generic checklist.

  2. LIVE

    Live production

    Testing runs against real, live systems for maximum realism, under strict, agreed rules of engagement to keep it safe.

  3. END-TO-END

    Prevent, detect, respond

    It measures the full chain: can attackers get in, and just as importantly, do your defenders notice and react in time?

  4. GOVERNED

    Strictly governed

    Defined roles, authority oversight and testers who meet strict independence and competence criteria under DORA and TIBER-EU.

Who's in scope

When TLPT is required

TLPT is not for everyone — it targets the most significant entities, but for them it is mandatory.

  • Required

    Significant entities

    Financial entities identified by competent authorities as significant must undergo TLPT — it is not optional for them.

    Note: Identified by authorities on size, risk and systemic importance.

  • Cadence

    At least every 3 years

    In-scope entities must complete a TLPT at least once every three years, though authorities may adjust the frequency.

    Note: Minimum once per three-year cycle.

  • Basis

    Built on TIBER-EU

    DORA’s TLPT follows the TIBER-EU framework, which several EU jurisdictions already run as TIBER-XX.

    Note: Harmonised across the EU on a common framework.

  • Testers

    Strict tester criteria

    Threat-intelligence and red-team providers must meet strict independence, competence and reputation requirements.

    Note: Not any pen-test provider qualifies for TLPT.

The engagement

How a TLPT engagement runs

A TLPT unfolds over months in defined phases. Scrub through to see what happens at each stage — and which team leads it.

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
Phase 1 / 6 Control Team

Preparation & scoping

The entity’s Control Team, with the authority, defines the critical functions in scope, agrees the rules of engagement, and procures the threat-intelligence and red-team providers.

Only a small, trusted "White Team" knows the test is happening.

Simplified from the TIBER-EU process. Exact phases, durations and roles vary by jurisdiction and by the entity’s authority.

The facts

TLPT at a glance

An advanced, harmonised testing regime — in force now for the entities that matter most.

2018
the year the ECB published TIBER-EU, the framework DORA’s TLPT is built on.
Source: ECB · TIBER-EU, 2018
Every 3 yrs
the minimum TLPT frequency for significant entities under DORA.
Source: DORA Art. 26 · EUR-Lex, 2022
Jan 2025
DORA — including its TLPT obligations — has applied across the EU since this date.
Source: EUR-Lex · DORA, 2025
Live
TLPT is run against live production systems, not a copy — for maximum realism.
Source: DORA · EUR-Lex, 2022

Each figure links to its primary source. Details vary by jurisdiction; confirm your obligations with your authority or a qualified adviser.

For significant entities

Preparing for a test that touches live systems

TLPT is high-stakes: real attacks on production, strict governance, and a defending team that must not be tipped off. Preparation is everything.

DORA requires significant financial entities to carry out threat-led penetration testing at least every three years, following the TIBER-EU framework, using testers that meet strict independence and competence requirements.
DORA Art. 26-27 · EUR-Lex
  • Get the baseline right first

    TLPT sits on top of a mature testing programme. Fix the known issues from routine testing before staging a full red-team engagement.

  • Build a trusted White Team

    A small, discreet control group runs the engagement while keeping the defenders genuinely unaware — essential for a realistic detection test.

  • Choose qualified providers

    Threat-intelligence and red-team providers must meet strict criteria. Vet them early; not every pen-test firm qualifies.

  • Plan for remediation

    The value is in acting on findings. Line up the capacity to remediate and retest, not just to run the exercise.

Frequently asked questions

Short, clear answers

What is threat-led penetration testing (TLPT)?

TLPT is advanced, intelligence-led testing where skilled testers emulate real threat actors against an organisation’s live production systems, measuring whether it can prevent, detect and respond to a realistic attack. Read the full explainer →

Who has to do TLPT under DORA?

Financial entities identified by their competent authorities as significant. Other entities run DORA’s baseline testing programme but are not required to perform full TLPT.

How often is TLPT required?

At least once every three years for in-scope significant entities, though authorities can adjust the frequency based on risk.

How is TLPT different from a normal penetration test?

A standard pen test checks specific systems for flaws. TLPT tests the whole organisation — people, process and technology — against a realistic, intelligence-led attack on live systems, and measures detection and response too. See the comparison →

What is TIBER-EU?

TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) is the European framework, published by the ECB in 2018, on which DORA’s TLPT is based. Several EU jurisdictions run national versions (TIBER-XX).

Is TLPT safe to run on live systems?

Yes, when governed properly. Strict, agreed rules of engagement, a trusted control team and experienced testers keep the exercise controlled while preserving realism. How to prepare →

Who can carry out TLPT?

Threat-intelligence and red-team providers that meet strict independence, competence and reputation criteria set out in the framework — not every penetration-testing provider qualifies.