What Is Threat-Led Penetration Testing (TLPT) Under DORA?

7 min readAbleneo AI transformation team

Short answer. Threat-Led Penetration Testing (TLPT) is an intelligence-driven attack simulation on a financial entity’s live production systems, required under Articles 26 and 27 of DORA. Identified significant entities must run it at least once every 3 years, following the TIBER-EU methodology. The red team phase lasts at least 12 weeks, and the technical standard that governs it, Commission Delegated Regulation (EU) 2025/1190, became directly applicable across the EU on 8 July 2025.

1What This Means in Practice

TLPT replaces the tick-box penetration test with a controlled cyberattack that mimics real threat actors. A separate threat intelligence provider first builds a profile of who would attack the entity and how. A red team then executes that scenario against production systems while the entity’s own defenders, the blue team, do not know a test is running. The goal is to measure how the organization detects, responds to, and recovers from an attack that behaves like the real thing.

Three details make TLPT heavier than a normal assessment. It runs on live systems that support critical or important functions, not a staging copy. It covers the full attack chain, from reconnaissance to data exfiltration. And it pulls in the ICT third parties that sit inside those functions, so a bank cannot scope out its core-banking vendor or its cloud provider.

2Why This Matters for Regulated Industries

DORA became applicable on 17 January 2025, and TLPT is the most demanding testing obligation inside it. The regulatory technical standard, Commission Delegated Regulation (EU) 2025/1190, was published in the Official Journal on 18 June 2025 and became directly applicable on 8 July 2025. That standard sets the criteria for which entities are in scope, the competency rules for testers, the testing methodology, and the closure and remediation stages. It is not guidance. It is binding law across all 27 member states.

For banks and insurers in Central Europe, the supervisory context is concrete. The TIBER-EU framework that underpins TLPT has already been adopted in Slovakia, the Czech Republic, and Austria, so the national competent authorities and central banks running these tests are established, not hypothetical. An entity identified for TLPT that cannot show a completed cycle, a valid remediation plan, and evidence of third-party inclusion is exposed on the one obligation supervisors are watching most closely.

TLPT is mandatory for significant financial entities under DORA Articles 26 and 27, at least once every 3 years.

3Which Financial Entities Must Run TLPT?

Not every financial entity is in scope. TLPT targets entities that are significant in terms of their impact on the financial sector and that run mature ICT systems. Competent authorities identify these entities using the criteria in Regulation (EU) 2025/1190, weighing systemic importance, the nature of the services, and the maturity of the ICT estate. A small payment institution will usually fall outside the requirement, while a large bank, a systemic insurer, or a core market infrastructure will usually fall inside it.

Once identified, an entity must perform TLPT at least once every 3 years. The regulation also allows pooled or joint TLPTs, so entities that share the same ICT third-party provider can run a coordinated test rather than each one attacking the shared provider separately. That option matters in Central Europe, where a handful of core-banking and cloud vendors serve many of the region’s banks.

4How Is TLPT Different From a Standard Penetration Test?

A standard penetration test scopes a defined system, runs for a fixed window, and often uses generic attack patterns with the defenders aware. TLPT inverts most of that. It is scenario-led, built from real threat intelligence about who would target this specific entity. It runs against live production, so the risk and the realism are both higher. And the blue team is kept in the dark, which turns the exercise into a genuine test of detection and response rather than a test of a known checklist.

The separation of roles is also stricter. DORA requires an independent threat intelligence provider and a separate red team provider, both meeting defined competency requirements. This split prevents the same team that designs the scenario from also grading its own attack, which keeps the result credible to a supervisor.

5What Are the Three Phases of a TLPT Engagement?

A TLPT cycle runs in three phases. The preparation phase sets the project charter, agrees the scope of critical or important functions, and appoints the control team that manages the test from inside the entity. The testing phase has two parts: targeted threat intelligence that produces the attack scenarios, then the active red team engagement of at least 12 weeks against production systems.

The closure phase is where the value lands. After the red team finishes, a mandatory replay session, sometimes called purple teaming, brings the attackers and defenders together to reconstruct the attack step by step. The entity then produces a remediation plan and reports the results to its competent authority. A finished attack with no remediation plan does not satisfy the obligation.

6How Does TLPT Relate to the TIBER-EU Framework?

TLPT under DORA follows the TIBER-EU framework, the threat intelligence-based ethical red teaming model developed by the European Central Bank and the EU national central banks and first published in May 2018. In February 2025, the Eurosystem updated TIBER-EU to align it fully with the DORA regulatory technical standards, so the two now describe one coherent process rather than two competing ones. Entities in countries that already ran TIBER tests, including Slovakia, the Czech Republic, and Austria, can build on that experience instead of starting over.

7What Should a CEE Bank or Insurer Do First?

Start by confirming whether the competent authority has identified the entity as in scope, since the obligation only bites for significant entities with mature ICT. Then map the critical or important functions and the ICT third parties that sit inside them, because those third parties are part of the test and their contracts must permit it. Check whether prior TIBER-EU experience in Slovakia, the Czech Republic, or Austria can be reused, then plan the calendar: an independent threat intelligence provider, a separate red team, a red team phase of at least 12 weeks, and a remediation window after closure. Entities that treat the 3-year cycle as a standing program rather than a one-off audit spend less on each round and carry cleaner evidence into supervision.

8The Ableneo Perspective

DORA turns resilience testing into a governance problem, not only a security one. TLPT touches core systems, third-party contracts, incident response, and board-level reporting at the same time, which is exactly the seam where Ableneo works. Ableneo shipped 34 production AI projects in 2025 across regulated financial services and insurance clients in Slovakia, the Czech Republic, and Austria, with roughly 4 of 5 reaching production. That track record in regulated environments is the difference between a test that produces a compliance artifact and one that produces measurable resilience. Our view on building accountable, observable systems for FS&I is set out across the Ableneo AI Transformation FAQ.

Key takeaways

Sources

Planning AI in a regulated business? Ableneo takes systems from classification to governed production.

Talk to Ableneo