DORA TLPT: threat-led penetration testing under TIBER-EU
Articles 24–27. TIBER-EU aligned. 5 phases, white-team operating model, RFI templates for Threat Intelligence + Red Team providers, scenario library, supervisory attestation pack.
What this solves
Threat-led penetration testing is the most misread requirement in DORA. It is not an annual pentest with a new name: it is a supervised exercise on live production systems, run against threat intelligence written for your institution, with a white team, an authority in the loop and an attestation at the end.
Entities designated for TLPT usually discover late that the hard part is not the red team — it is the scoping, the provider requirements and the evidence pack the supervisor expects.
What is inside
- 5 TLPT phases mapped to TIBER-EU
- White-team operating model and RACI
- RFI templates for TI + Red Team providers
- Rules of Engagement (RoE) template
- 8-archetype attack scenario library
- Closure mechanics (red / blue / purple)
- Supervisory attestation evidence pack
What it covers in the regulation
- Articles 24–27 — digital operational resilience testing
- Article 26 — advanced testing based on TLPT
- Article 27 — requirements for testers
- TIBER-EU framework alignment
- RTS on threat-led penetration testing
Who uses it, and when
Institutions that have been told they are in scope for TLPT, and the security leads who must run the white-team side. Also used by entities that are not in scope but want their testing programme to hold up under Articles 24–25.
How to work through it
- Establish whether you are actually in scope, and document the reasoning either way.
- Stand up the white team and its operating model before talking to any provider.
- Use the RFI templates to select the threat intelligence and red team providers against Article 27.
- Pick scenarios from the library that map to your critical functions.
- Assemble the attestation pack as the exercise runs, not afterwards.