Since 17 January 2025, DORA has applied throughout the European Union. Most financial institutions have focused their efforts on its most visible pillars: the register of ICT contracts, incident management and business continuity. But Article 26 introduces a requirement that goes further: TLPTs, or Threat-Led Penetration Tests.
This is not a conventional audit. It is not a standard penetration test. It is a targeted attack simulation conducted by external red teamers against your production systems, based on threat intelligence concerning the real-world threats targeting you.
Regulatory context
What Article 26 of DORA requires
Art. 26
Of DORA
Legal basis for TLPTs for financial entities
3 years
Minimum frequency
Between two full TLPTs, unless the supervisor requests otherwise
Jan. 2025
Application date
DORA has applied in full since 17 January 2025
Article 26 clearly distinguishes TLPTs from the routine security tests provided for in Article 25 (vulnerability scans and conventional penetration tests). TLPTs are advanced-level tests reserved for entities whose failure would have a systemic impact.
The main requirements are as follows: the test must cover several or all of the entity's critical functions, be conducted on live production systems by independent testers qualified under the RTS, and result in a summary of findings, a remediation plan and an attestation submitted to the supervisor.
Who is affected
Regulated entities and the cascading effect on providers
Competent authorities (the ACPR and AMF in France) select entities according to their size, risk profile, degree of interconnectedness, the criticality of their services and their history of ICT incidents. The more systemic an entity is, the more likely it is to be designated.
Entities directly affected include banks, insurance companies, asset management companies, investment firms, payment and electronic money institutions, trading venues and clearing houses.
How it works
The 4 phases of a TLPT under TIBER-FR
In March 2025, the Banque de France published the TIBER-FR guide, the framework for all TLPTs conducted under ACPR or AMF supervision.
Phase 1
Threat Intelligence
A Threat Intelligence provider -- independent from the red team -- analyses the real-world threats targeting your sector: OSINT, active cybercriminal groups, tactics, techniques and procedures (TTPs). This intelligence informs the attack scenarios. It is what distinguishes a TLPT from a conventional penetration test.
Phase 2
Reconnaissance and initial access (RECON + IN)
The red team begins with external reconnaissance: digital footprint, exposed services and compromised credentials on criminal marketplaces. It then attempts to gain initial access through targeted phishing, vulnerability exploitation, social engineering and, in some cases, physical intrusion, depending on the scope.
Phase 3
Lateral movement and escalation (THROUGH)
Once it gains initial access, the red team moves laterally through the information system: escalating privileges, bypassing controls and pivoting towards adjacent systems. The blue team does not know that the test is under way -- this is a test of real-world detection.
Phase 4
Objectives, closure and purple teaming (OUT)
The red team achieves the predefined objectives: exfiltrating target data or compromising a critical service. The closure stage follows: a debrief with the blue team, purple teaming to test variations, a full report and the supervisor attestation.
Test deliverables
Report, remediation plan and supervisor attestation
- Full technical report: attack timeline, vectors used, systems compromised, accessible data and TTPs employed. Confidential -- circulated only among the entity, testers and supervisor.
- Remediation plan: for each finding, a corrective action with an owner, deadline and priority level. Critical vulnerabilities must be addressed within strict timeframes monitored by the supervisor.
- Compliance attestation: a formal document submitted to the ACPR or AMF and signed by the entity and testers, confirming that the TLPT was conducted in accordance with DORA requirements and the TIBER-FR guide.
- Purple team debrief: a workshop involving the red and blue teams to replay scenarios, test variations and strengthen SOC detection rules based on the TTPs used.
Preparing for a TLPT
What to put in place before you begin
- Establish the White Team: three to five internal staff who manage the TLPT without informing the SOC. This group coordinates with providers, approves the scope and manages unexpected situations.
- Define the scope precisely with the supervisor: critical functions, systems and ICT providers included. A poorly defined scope causes disputes and delays.
- Select qualified providers separately: Threat Intelligence and red team providers must be independent from each other. The DORA RTS define the qualification criteria.
- Prepare contractual clauses with your subcontractors: if ICT providers fall within the scope, clauses permitting the test must be signed before it starts.
- Anticipate crisis management: the White Team must have a clear escalation protocol if the red team triggers a real alert or a system becomes unstable.
What it costs
Indicative budgets
6 to 12 months
Total duration
From preparation to submission of the supervisor attestation
€150k to €500k
Typical cost
Threat Intelligence + red team + internal management, depending on entity size
3 years
Amortisation
Time between two TLPTs -- spreading the cost across the period
These ranges vary according to the entity's size, the number of systems within the scope and the duration of the red team phase. Smaller designated entities may remain at the lower end of the range, while cross-border groups will reach the upper end.
Cyber Expert supports financial entities and their ICT providers in preparing and conducting DORA-compliant TLPTs. Contact us for an initial discussion about your situation and compliance timetable.
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call