The DORA Threat-led Penetration Testing RTS has been published

Threat-led Penetration Testing

Today on 18 June 2025, the European Commission officially published the long-awaited Regulatory Technical Standards (RTS) for Threat-Led Penetration Testing (TLPT) under the Digital Operational Resilience Act (DORA). This RTS supplements Article 26 of DORA and will expand the scope of Threat-led Penetration Testing to more entities in the financial sector.

After the publication in the EU journal the DORA TLPT RTS is active after 20 days. This means that on the 8th of July 2025 DORA TLPT will go into effect. At that point regulators will start sending official notification letters to entities that are in scope of DORA TLPT.

Are you looking for support with Threat-Led Penetration Testing (TLPT) — whether from the perspective of an entity, a TIBER Cyber Team (TCT), or as Red Team Testers (RTT)? Let’s plan a call!

For who is this important?

The DORA TLPT RTS affects different organisations that are dealing with TLPT:

  • Financial Entities in Scope: Banks, insurance providers, CCPs, payment/e-money institutions, trading venues, and CSDs meeting criticality thresholds
  • TLPT Authorities & TCTs: National and Union-level authorities responsible for overseeing TLPT execution
  • Red Team Testers (RTTs): Internal or external testers procured to simulate realistic threat actor scenarios
  • Threat Intelligence Providers (TIPs): External providers responsible for producing these threat scenarios

Key Takeaways about DORA TLPT

TLPT is now mandatory
Where TIBER-EU was voluntary in most cases TLPT is mandatory, but only entities meeting specific impact, risk, and systemic relevance criteria will be subject to TLPT.

Entities will receive an official notification
Entities do not self-initiate a TLPT. Instead, they receive a notification letter from their TLPT authority, which triggers a formal timeline:

  • 3 months to submit the initiation documents (a high-level project plan, Control Team Lead details, communication details, etc.)
  • 6 months to submit a detailed Scope Specification Document (detailing the CIFs, underlying systems and the flags)

The TLPT structure mirrors TIBER-EU
As I described in earlier blogs the new publication of TIBER-EU has been aligned to DORA TLPT. This means that in practice TIBER-EU can be used to perform DORA TLPT tests.

New obligations for Red Teams and TIPs
All external providers must:

  • Submit CVs, certifications, and references
  • Demonstrate a minimum of 3–5 prior red team/pentesting engagements
  • Maintain independence and separation (especially from Blue Team or TI roles)

Not only learning and improving is the goal anymore, but also receiving the Attestation
Because of the voluntary nature of TIBER-EU learning and improving based on the test was the primary goal. Since TLPT has become a supervisory tool the supervisory authority may issue a formal attestation if the TLPT was performed according to the TLPT/TIBER-EU requirements. This is up to the Test Managers from the TLPT authority to decide.

What should you do now?

For Financial Entities

  • Anticipate a notification letter if you meet the criteria
  • Ensure you understand the full TIBER/TLPT process
  • You can start to prepare your internal control team structure*
  • You can also already start identifying critical or important functions (CIFs)*
  • Budget and schedule resources for TIP and RTT engagement*

* Ensure that by preparing a control team, your CIFs and budget you do not notify people on the Blue Team of these preparations. As otherwise they will know that a test is in preparation.

For RTTs and TIPs

  • Validate that your experience and team composition meet the new minimum criteria
  • Prepare structured onboarding materials (CVs, certifications, prior references)
  • Review and align your methodology with DORA and TIBER-EU expectations
  • Establish robust documentation and data-handling processes

For TLPT Authorities and TCTs

  • If you do not already have a TIBER-EU implementation I would recommend to implement TIBER-EU in your jurisdiction to align to the DORA TLPT requirements and ensure mutual recognition
  • Prepare a TCT for the role as test managers, including training them properly

Need guidance or training?

Whether you’re preparing as an entity, supervising as a TCT, or delivering services as a TIP or RTT — I can help. The DORA TLPT requirements are detailed and demanding, but with the right preparation, they provide an excellent framework to strengthen the cyber resilience of the financial (and other) sectors.

I can help you with TLPT based on 10 years of experience with TIBER testing. Feel free to plan a call!

2 thoughts on “The DORA Threat-led Penetration Testing RTS has been published

Leave a Reply

Your email address will not be published. Required fields are marked *