Six categories (governance, documentation, technical security, monitoring, training, testing) each contain questions answered Yes = 1, Partially = 0.5, No = 0. Each category score is expressed as a percentage of its maximum; the overall figure is the average across categories.
Reading the result
- A category below 50% is flagged as a priority gap.
- TLPT applies to entities designated by their authority; the methodology mirrors the RTS on TLPT and TIBER-EU.
Basis: DORA Art. 26-27; RTS on threat-led penetration testing; TIBER-EU framework.