Skip to content
Knowledge Base

DORA and TLPT — What Threat-Led Penetration Tests Look Like for the Financial Sector

DORA raises the bar for testing in the financial sector: significant entities must carry out TLPT — tests targeted at real threats, on live systems, by independent testers. We explain the scope, the TIBER-EU framework, and how to prepare.

The DORA regulation (Digital Operational Resilience Act), which has been in full force since 17 January 2025, harmonized the requirements for digital operational resilience in the EU financial sector. One of its most demanding elements is the obligation of TLPT — threat-led penetration tests. This is far more than a standard pentest.

In this article we explain what TLPT is, who it applies to, and how to prepare for it.

What is TLPT?

TLPT (Threat-Led Penetration Testing) is an advanced form of testing in which attack scenarios are built on the basis of real threat intelligence for a given organization and sector. The test simulates the actions of a genuine, determined attacker on production systems. We organize the definition in the TLPT entry.

Key TLPT requirements under DORA

  • tests based on real threat scenarios,
  • conducted by independent, certified testers,
  • on critical or important functions in the production environment,
  • with a frequency of at least once every three years,
  • in accordance with the European TIBER-EU framework.

Who is subject to the TLPT obligation?

TLPT is a requirement for significant entities of the financial sector — not every institution must conduct it. Coverage is determined by the materiality criteria set out in the regulation and by supervisory authorities. Smaller entities fulfill the remaining DORA testing requirements, but not necessarily a full TLPT.

How does TLPT differ from an ordinary pentest?

  • Scope — critical business functions, not a single application.
  • Realism — scenarios from threat intelligence, on live systems.
  • Independence — a requirement for external, certified providers.
  • Basis — a regulatory obligation, not just good practice.

This is the difference between asking “does the application have vulnerabilities” and “will the organization withstand a real, targeted attack.”

How do you prepare for TLPT?

  1. Identify the critical functions and the systems that support them.
  2. Ensure the maturity of monitoring (SOC) so you can test safely in production.
  3. Plan the test with an independent provider in accordance with TIBER-EU.
  4. Turn the results into remediation actions and their validation.

A solid foundation before TLPT is a mature practice of penetration testing and continuous verification (PTaaS).

Check out our services

TLPT is the top tier of security testing — for the financial sector it is not an option but an obligation, one that must be prepared for diligently.

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Przemysław Widomski

Przemysław Widomski

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist