DORA TLPT: threat-led penetration testing under TIBER-EU
Articles 24–27. TIBER-EU aligned. 5 phases, white-team operating model, RFI templates for Threat Intelligence + Red Team providers, scenario library, supervisory attestation pack.
What this solves
Threat-led penetration testing is the most misread requirement in DORA. It is not an annual pentest with a new name: it is a supervised exercise on live production systems, run against threat intelligence written for your institution, with a white team, an authority in the loop and an attestation at the end.
Entities designated for TLPT usually discover late that the hard part is not the red team. it is the scoping, the provider requirements and the evidence pack the supervisor expects.
What is inside
- 5 TLPT phases mapped to TIBER-EU
- White-team operating model and RACI
- RFI templates for TI + Red Team providers
- Rules of Engagement (RoE) template
- 8-archetype attack scenario library
- Closure mechanics (red / blue / purple)
- Supervisory attestation evidence pack
What it covers in the regulation
- Articles 24–27: digital operational resilience testing
- Article 26: advanced testing based on TLPT
- Article 27: requirements for testers
- TIBER-EU framework alignment
- RTS on threat-led penetration testing
Who uses it, and when
Institutions that have been told they are in scope for TLPT, and the security leads who must run the white-team side. Also used by entities that are not in scope but want their testing programme to hold up under Articles 24–25.
How to work through it
- Establish whether you are actually in scope, and document the reasoning either way.
- Stand up the white team and its operating model before talking to any provider.
- Use the RFI templates to select the threat intelligence and red team providers against Article 27.
- Pick scenarios from the library that map to your critical functions.
- Assemble the attestation pack as the exercise runs, not afterwards.