The DORA regulation (Digital Operational Resilience Act), which has been in full force since 17 January 2025, harmonized the requirements for digital operational resilience in the EU financial sector. One of its most demanding elements is the obligation of TLPT — threat-led penetration tests. This is far more than a standard pentest.
In this article we explain what TLPT is, who it applies to, and how to prepare for it.
What is TLPT?
TLPT (Threat-Led Penetration Testing) is an advanced form of testing in which attack scenarios are built on the basis of real threat intelligence for a given organization and sector. The test simulates the actions of a genuine, determined attacker on production systems. We organize the definition in the TLPT entry.
Key TLPT requirements under DORA
- tests based on real threat scenarios,
- conducted by independent, certified testers,
- on critical or important functions in the production environment,
- with a frequency of at least once every three years,
- in accordance with the European TIBER-EU framework.
Who is subject to the TLPT obligation?
TLPT is a requirement for significant entities of the financial sector — not every institution must conduct it. Coverage is determined by the materiality criteria set out in the regulation and by supervisory authorities. Smaller entities fulfill the remaining DORA testing requirements, but not necessarily a full TLPT.
How does TLPT differ from an ordinary pentest?
- Scope — critical business functions, not a single application.
- Realism — scenarios from threat intelligence, on live systems.
- Independence — a requirement for external, certified providers.
- Basis — a regulatory obligation, not just good practice.
This is the difference between asking “does the application have vulnerabilities” and “will the organization withstand a real, targeted attack.”
How do you prepare for TLPT?
- Identify the critical functions and the systems that support them.
- Ensure the maturity of monitoring (SOC) so you can test safely in production.
- Plan the test with an independent provider in accordance with TIBER-EU.
- Turn the results into remediation actions and their validation.
A solid foundation before TLPT is a mature practice of penetration testing and continuous verification (PTaaS).
Related concepts
Check out our services
- Penetration tests — including threat-led scenarios
- DORA readiness audit — preparation for the regulation’s requirements
- SOC 24/7 — critical monitoring during production testing
TLPT is the top tier of security testing — for the financial sector it is not an option but an obligation, one that must be prepared for diligently.
