DORA · TIBER-EU
Threat-led penetration testing, explained
TLPT is the most advanced testing DORA requires — an intelligence-led red-team attack on your live systems, modelled on real adversaries. Understand who must do it, and how an engagement actually runs.
- Based on DORA & TIBER-EU
- Vendor-neutral
- Updated 2026
What is TLPT
A real attack, run safely and by the book
Threat-led penetration testing simulates how a real adversary would attack your organisation — against live systems, guided by genuine threat intelligence.
Threat-led penetration testing (TLPT) is an advanced form of security testing in which skilled testers emulate the tactics, techniques and procedures of real threat actors against an organisation’s live production systems. It measures not just whether a flaw exists, but whether the organisation can prevent, detect and respond to a realistic attack end to end.
Under the EU DORA regulation, significant financial entities must undergo TLPT at least every three years. DORA’s TLPT builds on TIBER-EU — the European framework for threat intelligence-based ethical red-teaming — which several EU central banks already operate.
It is deliberately demanding: real intelligence, live systems, strict rules of engagement, and testers who meet high independence and competence criteria. This site walks through what that means in practice.
What makes it different
Four things that set TLPT apart
TLPT is a different discipline from routine penetration testing.
- INTEL-LED
Intelligence-led
Scenarios are built from real threat intelligence about the adversaries actually targeting your sector — not a generic checklist.
- LIVE
Live production
Testing runs against real, live systems for maximum realism, under strict, agreed rules of engagement to keep it safe.
- END-TO-END
Prevent, detect, respond
It measures the full chain: can attackers get in, and just as importantly, do your defenders notice and react in time?
- GOVERNED
Strictly governed
Defined roles, authority oversight and testers who meet strict independence and competence criteria under DORA and TIBER-EU.
Who's in scope
When TLPT is required
TLPT is not for everyone — it targets the most significant entities, but for them it is mandatory.
- Required
Significant entities
Financial entities identified by competent authorities as significant must undergo TLPT — it is not optional for them.
Note: Identified by authorities on size, risk and systemic importance.
- Cadence
At least every 3 years
In-scope entities must complete a TLPT at least once every three years, though authorities may adjust the frequency.
Note: Minimum once per three-year cycle.
- Basis
Built on TIBER-EU
DORA’s TLPT follows the TIBER-EU framework, which several EU jurisdictions already run as TIBER-XX.
Note: Harmonised across the EU on a common framework.
- Testers
Strict tester criteria
Threat-intelligence and red-team providers must meet strict independence, competence and reputation requirements.
Note: Not any pen-test provider qualifies for TLPT.
The engagement
How a TLPT engagement runs
A TLPT unfolds over months in defined phases. Scrub through to see what happens at each stage — and which team leads it.
- 1
- 2
- 3
- 4
- 5
- 6
Preparation & scoping
The entity’s Control Team, with the authority, defines the critical functions in scope, agrees the rules of engagement, and procures the threat-intelligence and red-team providers.
Only a small, trusted "White Team" knows the test is happening.
Threat intelligence
A threat-intelligence provider produces a targeted report on the adversaries most likely to attack the entity, which is turned into realistic attack scenarios.
Red teaming
Over several weeks, the red team attempts to achieve the scenario objectives against live production systems — safely, within the agreed rules of engagement.
Detection & response
The organisation’s defenders — who do not know a test is underway — detect and respond as they would to a real attack. Their performance is measured.
Purple teaming
Red and blue teams walk through the engagement together, comparing what the attackers did with what the defenders saw, and identifying the gaps.
Closure & remediation
Findings are reported, a remediation plan is agreed, and — depending on the jurisdiction — an attestation confirms the test met the framework’s requirements.
The point is improvement, not a pass/fail score.
Simplified from the TIBER-EU process. Exact phases, durations and roles vary by jurisdiction and by the entity’s authority.
The facts
TLPT at a glance
An advanced, harmonised testing regime — in force now for the entities that matter most.
Each figure links to its primary source. Details vary by jurisdiction; confirm your obligations with your authority or a qualified adviser.
For significant entities
Preparing for a test that touches live systems
TLPT is high-stakes: real attacks on production, strict governance, and a defending team that must not be tipped off. Preparation is everything.
DORA requires significant financial entities to carry out threat-led penetration testing at least every three years, following the TIBER-EU framework, using testers that meet strict independence and competence requirements.
-
Get the baseline right first
TLPT sits on top of a mature testing programme. Fix the known issues from routine testing before staging a full red-team engagement.
-
Build a trusted White Team
A small, discreet control group runs the engagement while keeping the defenders genuinely unaware — essential for a realistic detection test.
-
Choose qualified providers
Threat-intelligence and red-team providers must meet strict criteria. Vet them early; not every pen-test firm qualifies.
-
Plan for remediation
The value is in acting on findings. Line up the capacity to remediate and retest, not just to run the exercise.
Guides
Go deeper
Plain-English guides to TLPT: what it is, how it differs from standard testing, and how to prepare.
-
What is TLPT? Threat-led penetration testing explained
TLPT is an intelligence-led red-team attack on your live systems, mandated by DORA for significant entities. Here is what it involves.
Read guide -
TLPT vs penetration testing: what is the difference?
A standard pen test checks a system for flaws. TLPT tests the whole organisation against a realistic, intelligence-led attack. Here is how they compare.
Read guide -
How to prepare for a TLPT engagement
TLPT touches live systems and a defending team that must stay unaware. Good preparation is what makes it safe and valuable.
Read guide
Frequently asked questions
Short, clear answers
What is threat-led penetration testing (TLPT)?
TLPT is advanced, intelligence-led testing where skilled testers emulate real threat actors against an organisation’s live production systems, measuring whether it can prevent, detect and respond to a realistic attack. Read the full explainer →
Who has to do TLPT under DORA?
Financial entities identified by their competent authorities as significant. Other entities run DORA’s baseline testing programme but are not required to perform full TLPT.
How often is TLPT required?
At least once every three years for in-scope significant entities, though authorities can adjust the frequency based on risk.
How is TLPT different from a normal penetration test?
A standard pen test checks specific systems for flaws. TLPT tests the whole organisation — people, process and technology — against a realistic, intelligence-led attack on live systems, and measures detection and response too. See the comparison →
What is TIBER-EU?
TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) is the European framework, published by the ECB in 2018, on which DORA’s TLPT is based. Several EU jurisdictions run national versions (TIBER-XX).
Is TLPT safe to run on live systems?
Yes, when governed properly. Strict, agreed rules of engagement, a trusted control team and experienced testers keep the exercise controlled while preserving realism. How to prepare →
Who can carry out TLPT?
Threat-intelligence and red-team providers that meet strict independence, competence and reputation criteria set out in the framework — not every penetration-testing provider qualifies.