Implementation

DORA TLPT: threat-led penetration testing under TIBER-EU

Articles 24–27. TIBER-EU aligned. 5 phases, white-team operating model, RFI templates for Threat Intelligence + Red Team providers, scenario library, supervisory attestation pack.

€69 excl. VAT
PDF · 20 pages · one-time · instant download
Buy & download →

What this solves

Threat-led penetration testing is the most misread requirement in DORA. It is not an annual pentest with a new name: it is a supervised exercise on live production systems, run against threat intelligence written for your institution, with a white team, an authority in the loop and an attestation at the end.

Entities designated for TLPT usually discover late that the hard part is not the red team — it is the scoping, the provider requirements and the evidence pack the supervisor expects.

What is inside

  • 5 TLPT phases mapped to TIBER-EU
  • White-team operating model and RACI
  • RFI templates for TI + Red Team providers
  • Rules of Engagement (RoE) template
  • 8-archetype attack scenario library
  • Closure mechanics (red / blue / purple)
  • Supervisory attestation evidence pack

What it covers in the regulation

  • Articles 24–27 — digital operational resilience testing
  • Article 26 — advanced testing based on TLPT
  • Article 27 — requirements for testers
  • TIBER-EU framework alignment
  • RTS on threat-led penetration testing

Who uses it, and when

Institutions that have been told they are in scope for TLPT, and the security leads who must run the white-team side. Also used by entities that are not in scope but want their testing programme to hold up under Articles 24–25.

How to work through it

  1. Establish whether you are actually in scope, and document the reasoning either way.
  2. Stand up the white team and its operating model before talking to any provider.
  3. Use the RFI templates to select the threat intelligence and red team providers against Article 27.
  4. Pick scenarios from the library that map to your critical functions.
  5. Assemble the attestation pack as the exercise runs, not afterwards.

Questions

Is TLPT mandatory for us?

Only for entities identified by the competent authority. Articles 24–25 testing applies far more widely — the guide separates the two.

Is this TIBER-EU?

It is aligned to TIBER-EU, which is the framework most national authorities build their TLPT process on.

Does it include provider selection material?

Yes — RFI templates for both the threat intelligence and the red team provider, framed against the Article 27 tester requirements.

What format?

A PDF, delivered by personal download link after checkout.

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join Free Monthly Webinar