The Digital Operational Resilience Act (DORA) is planned to go into effect on the 17th of January 2025. One part of DORA is Threat Led Penetration Testing (TLPT). But what entities are in scope for TLPT? We will go into that in this article.
To avoid confusion it is good to state that there are two different requirements for testing by entities under DORA. First there is article 24 that applies to all entities in scope for DORA except microenterprises. It requires these entities to implement a digital operational resilience testing programme as part of their risk-management framework. These tests have to performed annually at minimum.
Besides this article there is a specific Regulatory Technical Standard (RTS) that goes into Threat Led Penetration Testing (TLPT). Entities in scope for TLPT need to perform a TLPT every three years (unless otherwise defined by the competent authority).
We will first look at Operational resilience testing of article 24 and afterwards discuss TLPT.
If your entity is in scope for DORA TLPT and you want assistance with testing under DORA please contact me.
Digital Operational Resilience testing
According to article 24 of DORA entities (except microenterprises) have to do risk based testing, independent assessments and tests for all IT systems and applications that support critical functions. Procedures must be in place to address any weaknesses or gaps that are identified during these test. These testing activities should be documented in the ICT risk-management framework.
For the purpose of assessing preparedness for handling ICT-related incidents, of identifying weaknesses, deficiencies and gaps in digital operational resilience, and of promptly implementing corrective measures, financial entities, other than microenterprises, shall, taking into account the criteria set out in Article 4(2), establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk-management framework referred to in Article 6.
TLPT testing under DORA
Financial entities that meet certain criteria under DORA have to perform Threat Led Penetration Testing (TLPT). TLPT under DORA is in accordance to the TIBER-EU framework. In a previous blog I have described the differences between TIBER-EU and DORA TLPT.
DORA TLPT takes a two layered approach for identification of entities in scope. First entities that play a systematic role in the financial services sector are included by the criteria listed in the quoted box below.
DORA also gives authorities the option to include or exclude entities based on:
- Impact and systemic character of the entity like size and interconnectedness
- ICT risk related factors of the entity like the risk profile, threat landscape and maturity of detection and response.
Entities in scope for DORA TLPT by default are:
(a) Credit institutions identified as global systemically important institutions (G-SIIs) in accordance with Article 131 of Directive 2013/36/EU of the European Parliament and of the Council 15 or as other systemically important institutions (O-SIIs) or that are part of a G-SIIs or O-SIIs.
(b) Payment institutions, exceeding in each of the previous two financial years EUR 150 billion
of total value of payment transactions as defined in point (5) of Article 4 of Directive (EU) 2015/2366 of the European Parliament and of the Council16.
(c) Electronic money institutions, exceeding in each of the previous two financial years EUR 150 billion of total value of payment transactions as defined in point (5) of Article 4 of Directive(EU) 2015/2366 or EUR 40 billion of total value of the amount of outstanding electronic money.
(d) Central securities depositories;
(e) Central counterparties;
(f) Trading venues with an electronic trading system that meet at least one of the following criteria:(i) the trading venue with the highest market share in terms of turnover at national level
in each of the preceding two financial years in one or more of the following:
- transferable securities as defined in point (44)(a) of Article 4(1) of Directive 2014/65/EU of the European Parliament and of the Council;
- transferable securities as defined in point (44)(b) of Article 4(1) of Directive 2014/65/EU;
- derivatives as defined in Article 2(1)(29) of Regulation (EU) No 600/2014 of the European Parliament and of the Council;
- structured finance products as defined in Article 2(1)(28) of Regulation (EU) No 600/2014 ;
- emission allowances as defined in point (11) of Section C of Annex I to Directive 2014/65/EU;
(ii) the trading venue whose market share in terms of turnover at Union level exceeds 5% in each of the preceding two financial years in one or more of the following:
- transferable securities as defined in point (44)(a) of Article 4(1) of Directive 2014/65/EU
- transferable securities as defined in point (44)(b) of Article 4(1) of directive Directive 2014/65/EU
- derivatives as defined in Article 2(1)(29) of Regulation (EU) No 600/2014
- structured finance products as defined in Article 2(1)(28) of Regulation (EU) No 600/2014
- emission allowances as defined in point (11) of Section C of Annex I to Directive 2014/65/EU;
For the purposes of point (ii) of this point (f), where the trading venue is part of a group
using common ICT systems or the same ICT intra-group service provider, the turnover
of the securities and derivatives contracts on all trading venues pertaining to the same
group and established in the Union shall be considered.(g) Insurance and reinsurance undertakings that meet all the following criteria:
- gross written premium (GWP) exceeding EUR 1 500 000 000;
- technical provisions exceeding EUR 10 000 000 000;
- in case of life insurance undertakings, as referred to in Article 13, point (1), of Directive 2009/138/EC of the European Parliament and of the Council, and of insurance undertakings pursuing both life and non-life activities, total assets exceeding 3.5% of the sum of the total assets valuated according to Article 75 of Directive 2009/138/EC of the insurance and reinsurance undertakings established in the Member State.
TLPT authorities shall create a subset of all insurance and reinsurance undertakings by applying the criteria listed in the first subparagraph. Insurance and reinsurance undertakings included in this subset shall be required to perform TLPT where they also meet one or more of the following criteria:
- gross written premium (GWP) exceeding EUR 3 000 000 000;
- technical provisions exceeding EUR 30 000 000 000;
- total assets exceeding 10% of the sum of the total assets valuated according to Article 75 of Directive 2009/138/EC of the insurance and reinsurance undertakings established in the Member State.

3 thoughts on “What entities are in scope for Threat Led Penetration Testing under DORA?”
We are considering whether my organisation – Trading212 – is required to do a TLPT under DORA for our EU Operations centre that supports two EU entities ? I don’t believe that we meet the main criteria in Article 2(1) of the RTS but possibly we may fit within Article 2 (4).
Hi Adrian, if you are willing to send me some information about your entity and considerations surrounding TLPT I would be more than happy to have a look.
You can contact me via the contact form.