DORAPenetration testingComplianceTLPT

TLPT and DORA: mandatory advanced penetration testing for financial entities

DORA has applied since January 2025. For significant financial entities, Article 26 requires advanced penetration testing based on real-world threats. What this means in practice.

Hakim Djelili9 min read

Since 17 January 2025, DORA has applied throughout the European Union. Most financial institutions have focused their efforts on its most visible pillars: the register of ICT contracts, incident management and business continuity. But Article 26 introduces a requirement that goes further: TLPTs, or Threat-Led Penetration Tests.

This is not a conventional audit. It is not a standard penetration test. It is a targeted attack simulation conducted by external red teamers against your production systems, based on threat intelligence concerning the real-world threats targeting you.

Regulatory context

What Article 26 of DORA requires

Art. 26

Of DORA

Legal basis for TLPTs for financial entities

3 years

Minimum frequency

Between two full TLPTs, unless the supervisor requests otherwise

Jan. 2025

Application date

DORA has applied in full since 17 January 2025

Article 26 clearly distinguishes TLPTs from the routine security tests provided for in Article 25 (vulnerability scans and conventional penetration tests). TLPTs are advanced-level tests reserved for entities whose failure would have a systemic impact.

The main requirements are as follows: the test must cover several or all of the entity's critical functions, be conducted on live production systems by independent testers qualified under the RTS, and result in a summary of findings, a remediation plan and an attestation submitted to the supervisor.

Who is affected

Regulated entities and the cascading effect on providers

Competent authorities (the ACPR and AMF in France) select entities according to their size, risk profile, degree of interconnectedness, the criticality of their services and their history of ICT incidents. The more systemic an entity is, the more likely it is to be designated.

Entities directly affected include banks, insurance companies, asset management companies, investment firms, payment and electronic money institutions, trading venues and clearing houses.

How it works

The 4 phases of a TLPT under TIBER-FR

In March 2025, the Banque de France published the TIBER-FR guide, the framework for all TLPTs conducted under ACPR or AMF supervision.

  1. Phase 1

    Threat Intelligence

    A Threat Intelligence provider -- independent from the red team -- analyses the real-world threats targeting your sector: OSINT, active cybercriminal groups, tactics, techniques and procedures (TTPs). This intelligence informs the attack scenarios. It is what distinguishes a TLPT from a conventional penetration test.

  2. Phase 2

    Reconnaissance and initial access (RECON + IN)

    The red team begins with external reconnaissance: digital footprint, exposed services and compromised credentials on criminal marketplaces. It then attempts to gain initial access through targeted phishing, vulnerability exploitation, social engineering and, in some cases, physical intrusion, depending on the scope.

  3. Phase 3

    Lateral movement and escalation (THROUGH)

    Once it gains initial access, the red team moves laterally through the information system: escalating privileges, bypassing controls and pivoting towards adjacent systems. The blue team does not know that the test is under way -- this is a test of real-world detection.

  4. Phase 4

    Objectives, closure and purple teaming (OUT)

    The red team achieves the predefined objectives: exfiltrating target data or compromising a critical service. The closure stage follows: a debrief with the blue team, purple teaming to test variations, a full report and the supervisor attestation.

Test deliverables

Report, remediation plan and supervisor attestation

  • Full technical report: attack timeline, vectors used, systems compromised, accessible data and TTPs employed. Confidential -- circulated only among the entity, testers and supervisor.
  • Remediation plan: for each finding, a corrective action with an owner, deadline and priority level. Critical vulnerabilities must be addressed within strict timeframes monitored by the supervisor.
  • Compliance attestation: a formal document submitted to the ACPR or AMF and signed by the entity and testers, confirming that the TLPT was conducted in accordance with DORA requirements and the TIBER-FR guide.
  • Purple team debrief: a workshop involving the red and blue teams to replay scenarios, test variations and strengthen SOC detection rules based on the TTPs used.

Preparing for a TLPT

What to put in place before you begin

  • Establish the White Team: three to five internal staff who manage the TLPT without informing the SOC. This group coordinates with providers, approves the scope and manages unexpected situations.
  • Define the scope precisely with the supervisor: critical functions, systems and ICT providers included. A poorly defined scope causes disputes and delays.
  • Select qualified providers separately: Threat Intelligence and red team providers must be independent from each other. The DORA RTS define the qualification criteria.
  • Prepare contractual clauses with your subcontractors: if ICT providers fall within the scope, clauses permitting the test must be signed before it starts.
  • Anticipate crisis management: the White Team must have a clear escalation protocol if the red team triggers a real alert or a system becomes unstable.

What it costs

Indicative budgets

6 to 12 months

Total duration

From preparation to submission of the supervisor attestation

€150k to €500k

Typical cost

Threat Intelligence + red team + internal management, depending on entity size

3 years

Amortisation

Time between two TLPTs -- spreading the cost across the period

These ranges vary according to the entity's size, the number of systems within the scope and the duration of the red team phase. Smaller designated entities may remain at the lower end of the range, while cross-border groups will reach the upper end.

Cyber Expert supports financial entities and their ICT providers in preparing and conducting DORA-compliant TLPTs. Contact us for an initial discussion about your situation and compliance timetable.

Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call