tlpt

TLPT vs penetration testing: what is the difference?

Updated 5 min read

TLPT and penetration testing are often confused, but they answer different questions. Both matter – and TLPT sits on top of a solid pen-testing programme.

Two different questions

A penetration test asks whether a defined system contains exploitable weaknesses. A threat-led penetration test asks whether a realistic adversary, working from intelligence about who actually targets you, could reach something that matters – and whether anyone would notice in time. The first is a property of a system. The second is a property of an organisation. Routine tests may leave detection and response gaps that a TLPT exposes. TLPT is a learning exercise, not a pass-or-fail security verdict.

Under DORA they are separate obligations with separate legal bases. Penetration testing is one of the baseline test types listed in Article 25(1) of Regulation (EU) 2022/2554. TLPT is the advanced testing required by Article 26, detailed by Commission Delegated Regulation (EU) 2025/1190 and operationalised by the ECB’s TIBER-EU framework. For the mechanics of the latter, start with what TLPT is.

The differences, dimension by dimension

Every row below is a design decision someone made deliberately. The environment, the secrecy and the duration are not TLPT being a bigger pen test; they define the conditions under which a regulated TLPT evaluates resilience. Other exercises can also assess detection and response.

Penetration testing and TLPT compared
DimensionPenetration testTLPT
ScopeNamed systems in an agreed scopeSeveral or all critical or important functions of the entity (DORA Art 26(2))
EnvironmentOften staging, or a carved-out slice of productionLive production systems supporting those functions (Art 26(2))
DriverA methodology and a checklistBespoke threat intelligence – a targeted report with at least three end-to-end scenarios (TIBER-EU)
DefendersUsually informed in advanceThe blue team is “not aware of the TLPT” (Reg. 2025/1190 Art 1(3))
DurationDays to weeksActive red team phase of at least 12 weeks (Art 11(5))
Tester barCommercial selection by the clientSuitability, certification and indemnity insurance (DORA Art 27(1)); at least five references (Art 7(1)(d))
OversightThe clientA TLPT authority validates the scope and issues the attestation (Art 26(2), 26(7))
OutputA findings reportAttestation, summary of findings and a remediation plan, each on a statutory clock (Art 26(6)–(7))
Sources: Regulation (EU) 2022/2554 and Commission Delegated Regulation (EU) 2025/1190, EUR-Lex.

Who has to do which

Nearly everyone in scope of DORA owes the baseline. Article 24(1) requires a sound and comprehensive digital operational resilience testing programme for every financial entity other than microenterprises, Article 24(4) requires the tests to be undertaken by independent parties whether internal or external, and Article 24(6) requires appropriate tests at least yearly on all ICT systems and applications supporting critical or important functions.

TLPT is narrower. Article 26(1) requires it at least every three years from entities other than those referred to in Article 16(1), first subparagraph, and other than microenterprises – and only where the competent authority has identified them. Article 26(8), third subparagraph, puts that identification with the authorities, applying the Article 4(2) criteria plus impact-related factors, financial stability and systemic character, and the entity’s ICT risk profile and maturity. Mandatory DORA TLPT follows authority identification. Voluntary TIBER-EU tests are also possible. DORA has no general TLPT category called “significant entities”.

What a penetration test still does better

A TLPT is not a better pen test; it is a different instrument, and it is worse at several things a pen test does well.

  • Depth on one system. A pen test can spend its entire budget on a single application, API or network segment. A TLPT spends its budget reaching a flag, and will walk past a dozen findings on the way.
  • Frequency. A three-yearly TLPT cannot satisfy Article 24(6)’s yearly requirement across all systems supporting critical or important functions. Only a routine programme can.
  • Safety. Because it can run outside production, a pen test can attempt things that would be reckless against live systems carrying customer transactions.
  • Breadth of technique. Article 25(1) enumerates vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing. A TLPT covers a slice of that.
  • Turnaround. You can commission a pen test in weeks and retest after the fix. Nothing about a TLPT is that responsive.

The governance is the part people underestimate

Secrecy is where a TLPT stops resembling procurement. Article 4(2) of Delegated Regulation (EU) 2025/1190 puts knowledge of a planned or ongoing test on a need-to-know footing, keeps the blue team outside it, and – where possible – has everyone refer to the test by code name only; the full list of who may know, and what the control team owes the test managers, is in how to prepare for a TLPT engagement. Your normal pen-test kick-off call would breach all of it.

Oversight is external too. The entity assesses which critical or important functions to cover, but under Article 26(2) that scope “shall be validated by the competent authorities”, and Article 26(7) has the authority issue an attestation “in order to allow for mutual recognition of threat led penetration tests between competent authorities”. Article 26(7) also makes clear the entity “shall remain at all times fully responsible for the impact of the tests”.

Cost, clock and cadence

The timelines are not comparable. From the authority’s notification onwards, Delegated Regulation (EU) 2025/1190 runs the whole engagement on statutory deadlines – three months to the initiation information, six months to a scope specification document approved by the management body, at least 12 weeks of active red teaming (Article 11(5)), then fixed windows for the two reports, the replay and the remediation plan. The milestone table in how to prepare gives each deadline with its article. An ordinary pen test can have a shorter schedule, depending on scope and availability.

What the threat data says about both

Verizon’s 2026 Data Breach Investigations Report found exploitation of vulnerabilities in 31% of breaches as an initial access vector – the most common route in, up from 20% – while only 26% of the CISA KEV vulnerabilities found in organisations’ environments were fully remediated, at a median of 43 days. That is a vulnerability-management and pen-testing problem, and no red team engagement will fix it for you. The same report puts the human element in 62% of breaches and third-party involvement at 48%, which supports including relevant people, processes and third-party dependencies in risk-based scoping. Both penetration tests and TLPT can examine those areas when appropriately scoped.

Which do you need

Start by checking your applicable obligations and the maturity of the baseline testing programme. Mandatory TLPT follows authority identification under Article 26(8); voluntary intelligence-led testing may also help answer specific resilience questions. Continue urgent remediation while planning the test, and agree how known weaknesses affect scope and risk controls with the test managers.

Sources

  1. Regulation (EU) 2022/2554 (Digital Operational Resilience Act) EUR-Lex · 2022 Article 24–25 baseline testing, Article 26 TLPT obligation and identification, Article 27 tester requirements.
  2. Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing EUR-Lex · 2025 Blue team definition, secrecy requirements, provider references and the phase deadlines.
  3. TIBER-EU Framework: How to implement the European framework for Threat Intelligence-Based Ethical Red teaming European Central Bank · 2025 The at-least-three end-to-end threat scenarios and the phase timings.
  4. What is TIBER-EU? European Central Bank The five teams and the framework’s learning-focused, non-pass/fail outcome.
  5. 2026 Data Breach Investigations Report Verizon · 2026 Vulnerability exploitation, CISA KEV remediation rates, the human element and third-party involvement.

FAQ

Related questions

Is TLPT just a bigger penetration test?

No. It runs against live production systems supporting critical or important functions (DORA Article 26(2)), is driven by bespoke threat intelligence, keeps the blue team unaware, and is overseen by a TLPT authority that validates the scope and issues an attestation.

Do I need TLPT if I already do penetration testing?

Only if your competent authority has identified you under DORA Article 26(8). Identification is the authority’s decision, not a self-assessment. Financial entities in DORA scope other than microenterprises still owe the Article 24(6) baseline: appropriate tests at least yearly on all ICT systems supporting critical or important functions.

Can the same provider do both?

Often yes, but TLPT testers must meet DORA Article 27(1): suitability and reputability, demonstrated expertise in threat intelligence and red teaming, certification or adherence to a formal code of conduct, an independent assurance report, and professional indemnity insurance. Delegated Regulation (EU) 2025/1190 Article 7(1)(d) adds at least five references.

Does a TLPT replace the yearly testing programme?

No. Article 26 advanced testing sits on top of the Articles 24 and 25 programme; the yearly obligation on systems supporting critical or important functions continues for entities other than microenterprises.