The Digital Operational Resilience Act (DORA) is currently in the consultation process. This Act aims to increase the digital operational resilience of the financial sector, amongst other things, by mandating threat led penetration testing (TLPT). But how does this make TLPT in DORA different from TIBER-EU? 1 And what do you, as a supervisor or authority, need to do in order to comply with DORA?
What is TIBER and what is DORA?
This article will sum up the big differences between TIBER and DORA related to Threat Led Penetration Testing (TLPT). Before we do that it is good to review what the TIBER-EU framework is and what DORA exactly entails.
TIBER-EU is a comprehensive framework that can be used voluntarily by any authority to improve the cyber resilience of their sector. As it is sector agnostic, free to use and can be customised using the optional elements it is ideal to use to conform to the Digital Operational Resilience Act (DORA). When TIBER is implemented in a country by the respective authority they make their own framework based on TIBER-EU referred to as TIBER-XX, XX being the ISO code for that country. For example TIBER-NL, TIBER-DE etc. TIBER-EU is the framework that describes how to implement TIBER in your sector. TIBER-XX will be the guide for your sector. It has mandatory and optional elements. The mandatory elements have to be used by any authority that implements TIBER in order for tests to be mutually recognised. Optional elements on the other hand can be implemented in a way the authority sees fit in order for its sector.
The Digital Operational Resilience Act (DORA) is an EU regulation that is currently out for consultation and will enter into force on January 17th 2025. It applies to 20 different kinds of financial entities and selected ICT service providers. DORA consists of multiple parts and one of those is mandatory Threat Led Penetration Testing (TLTP). In short, if you’re a financial entity and your lead authority has designated you to fall under the scope of DORA you must adhere to DORA and do TLPT that follows its requirements.
Since DORA TLPT should be ‘in accordance with the TIBER-EU framework’ according to text of the regulation there are not too many differences between the two approaches. There are currently only two significant differences from a testing perspective and some other points that are easier to incorporate. All of these will be updated in the TIBER-EU framework so that DORA and TIBER-EU are completely aligned.
The two significant differences between TIBER-EU and DORA, from a framework perspective, are the inclusion of internal testers and mandating Purple Teaming.
What are the differences between TIBER and DORA?
The use of internal Red team/penetration testers is allowed in the Digital Operational Resilience Act
TIBER-EU, at this moment, does not allow for internal testers. This means internal penetration testers or red teams of the entity that is being tested are not allowed to execute the role of the Red Team. In DORA this is allowed, but it has to be approved by the respective relevant authority.
The internal testers would need enough resources and there should be no conflict of interest. Even then, one in every three tests done under DORA by the entity has to be performed by external testers. This means a Red Team Provider has to be hired by the entity to perform one in three tests. The Threat Intelligence provider always has to be an external provider.
Purple Teaming is mandatory within the Digital Operational Resilience Act
During Purple Teaming the Red and Blue Team work together and form the Purple Team to directly learn from action of the red teaming phase or work together on attacks that couldn’t be performed in the red teaming phase. In TIBER-EU Purple Teaming is an optional element that can be done after the Red Team test is completed. DORA makes Purple Teaming mandatory because of the positive experience of Purple Teaming within TIBER.
Active Red team testing time
TIBER-EU states that the active red teaming phase, the time the red team provider is actively testing, should be 10-12 weeks. This does not mean that there is 10-12 weeks of constant red team activity, but the activity is scheduled within these weeks. This gives the red team provider time to wait for responses on phishing mails or pause when a detection has taken place. In DORA the active time of the TLPT has to be 12 weeks minimum.
Testing frequency
TIBER-EU does not mandate a certain frequency for testing, but some national implementations do. DORA TLPT on the other hand states that in general testing should be done every three years. This is in line of the general approach of TIBER authorities that require testing every 2-3 years. DORA allows the TLPT authority to either increase or decrease this frequency if desired.
Naming convention
Although not a significant change, certain terms and names of teams could be confusing in the TLPT under DORA. Foremost where TIBER-EU speaks about ‘threat intelligence based red teaming’ DORA instead refers to Threat Led Penetration Testing’ (TLPT). Although a whole discussion can be had on the difference between red teaming and penetration testing both concepts mean the same in the context of DORA TLPT.
Due to the mandatory nature the role of the authority responsible for the framework in a certain jurisdiction also had to be renamed. The authority responsible for the test is called the ‘TLPT authority’ under DORA. The team from the TLPT authority that delivers the test managers is in DORA referred to as the TLPT Cyber Team still shortened to TCT.
Besides this also the ‘White Team’, the people in control of the test and the only ones within the entity that know that the test is ongoing, has been renamed to the ‘Control Team.
Threat Intelligence scenarios
Within TIBER-EU it is important that the test is Threat Intelligence based in order to test the most relevant attack scenarios. This concept has to been taken over in DORA TLPT, but with a weird twist in the current proposal.
TIBER states that the TI provider has to deliver threat intelligence scenarios based on the scope of the critical functions and highlight what scenarios would be most relevant and impactful for the entity.
Within TLPT under DORA the TI provider must cover each and every critical function in these threat scenarios. This seems illogical and goes against the threat intelligence approach. There are not always relevant threat actors to map to all critical functions. Some functions might have multiple criminal and state actors that are interested in it and other functions might not be covered at all. By forcing the TI provider to cover the entire scoping document you water down the value of the scenarios.
Timelines
Lastly in the current proposal DORA introduced maximum timelines for certain documentation to be delivered in the closure phase of the test. Within TIBER-EU only the red team test report had to be delivered within 2 weeks after testing had completed. This has become 4 weeks in the current proposal, but in addition the DORA added timelines for the blue team report, the taking place of the replay session and the delivery of the test summary.
What actions do you have to take in order to comply with DORA?
So what does this mean for you as a supervisor or authority wanting to comply with the Digital Operational Resilience Act? Because of the limited differences you can use TIBER-EU to adhere to the Digital Operational Resilience Act and as we stated TIBER-EU will be updated to reflect the changes in DORA to be completely compatible. But below we will describe the two most likely scenarios for your current situation. If you still have questions feel free to contact us.
- You already have TIBER-EU implemented
In this case you only have the ensure that the scope of entities you test using TIBER includes the entities that fall under DORA TLPT. Next to that your tests have ensure that you incorporate the differences stated above until these are incorporated in TIBER-EU. The main two being allowing for internal testers (except for every third test) and including Purple Teaming as a mandatory element. - You do not have TIBER-EU implemented
You can use the TIBER-EU framework to quickly adhere to DORA and ensure that your tests are compatible with all the other countries that already do TIBER testing.
Of course you do not have to use TIBER-EU, but since it is already used widely in Europe and saves you a lot of time developing your own documentation we would recommend to base your DORA tests on TIBER-EU.
If you need assistance to comply with DORA using TIBER-EU feel free to contact us for advice.
- TIBER stands for Threat Intelligence Based Ethical Red-teaming ↩︎

9 thoughts on “What are the differences between DORA and TIBER-EU?”
Can i get the pdf for Blue team practices? The way you have documented for other teams like Red, Purple and White.
Thank you for your question! Unfortunately there is currently no blue team guidance from TIBER-EU. Since the blue team should be unaware of the test until the active red team phase is finished this team would also have less need for guidance during the test. However there could be a benefit for Blue team guidance to show the blue team how the handle the replay and purple teaming. I will put this on my todo list to write something about this.
Hi Maarten, +1 for the BT guidance – that would be great addition to the documentation already existing.
Hi Niki, Igor, with the updated release of TIBER-EU there is now a blue team report guidance. Please see https://tiber.info/documentation