DORA TLPT: Threat-Led Penetration Testing Explained (2026 Guide)
Pentestas Team
Security Analyst

💫 DORA TLPT — the short version
- TLPT (DORA Art. 26-27) is an intelligence-led red-team test on live production critical functions — a tier above ordinary pentesting.
- It applies to significant financial entities designated by their competent authority, at least every 3 years, and follows the TIBER-EU method.
- Three phases — preparation, active red-teaming, and closure (remediation + purple teaming) — with threat intelligence and testers that meet DORA's independence bar.
- Continuous, AI-driven pentesting between cycles is how you walk into a TLPT with fewer easy wins for the red team to find.
If your firm has been told it is in scope for TLPT under DORA, you are not being asked for a normal penetration test. Threat-Led Penetration Testing is a full, intelligence-led red-team exercise run against your live production systems, modelled on real adversaries, while most of your own defenders stay blind to it. It is the most demanding testing obligation in the regulation — and the one firms most often underestimate.
This guide explains what DORA TLPT actually requires, who has to do it, how an engagement runs from threat intelligence to closure, and how continuous testing in between keeps the 3-yearly exercise from turning up a pile of avoidable findings.
The mandate
What DORA TLPT requires
DORA (Regulation (EU) 2022/2554, in force since 17 January 2025) splits testing into two tiers. Articles 24-25 require every in-scope entity to run a broad testing programme — vulnerability assessments and penetration testing on the ICT systems behind critical or important functions, with the critical ones tested at least yearly. Articles 26-27 add Threat-Led Penetration Testing: a live-production, intelligence-driven red-team exercise carried out at least once every three years by designated entities. The detail is set by the regulatory technical standards (RTS) on TLPT and follows the European TIBER-EU framework.
The distinction that trips people up: an ordinary pentest proves a system is exploitable; a TLPT proves whether your people, processes and detection catch a realistic attack in progress, on the systems that actually run your business, without a safety net.
A TLPT engagement, end to end
Who and how often
Who is designated for TLPT
TLPT is not for everyone bound by DORA. National competent authorities designate the financial entities that must perform it — the systemically important ones, judged on size, risk profile, and the impact their disruption would have on the financial system. Banks, major payment institutions, key market infrastructures and large insurers are typical candidates. The baseline cadence is at least every three years, and an authority can move it up or down.
Even if you are not designated, the Art. 24-25 programme still binds you, and your board still has to show a coherent testing story. Many mid-size fintechs and their critical ICT providers prepare as if TLPT is coming, because for a growing firm it often is.
The engagement
How a TLPT runs, phase by phase
Preparation. Scope is agreed with the authority's TLPT team, a control group is set up inside the firm, and providers are engaged. Threat intelligence then builds realistic attack scenarios from the actual threat actors targeting your sector.
Testing. An independent red team runs those scenarios against live production, attempting to reach defined ‘flags’ on critical functions while the wider blue team stays unaware — a genuine test of detection and response. Closure. Red and blue teams reconcile in a purple-team review, findings are remediated, and a report goes to the authority. DORA sets a high bar for tester independence and competence; threat-intelligence and red-team providers must meet it, and internal testers are only allowed under specific conditions.
Between cycles
Where continuous AI testing fits
A TLPT every three years is a milestone, not a control you can lean on day to day. The systems it tests change every week. The firms that come through a TLPT well are the ones whose critical functions were already being tested continuously, so the red team has to work for its flags instead of walking through last quarter's unpatched API.
Between formal TLPT cycles, Pentestas keeps you test-ready as a pentesting as a service platform. It runs as an AI penetration testing system that exercises your critical functions after every deploy — penetration testing with AI orchestrated by frontier models, using penetration testing with Claude for deep exploit reasoning and cost-controlled penetration testing with DeepSeek for high-volume passes — and, for the fintechs and vendors in scope, a B2B SaaS pentest that maps each finding to the DORA control it supports.
Cost of staying in-scope
FAQ
DORA TLPT, quick answers
Is TLPT the same as a penetration test?
No. A penetration test proves systems are exploitable; TLPT is an intelligence-led red-team exercise on live production that also tests whether your detection and response catch a real attack. TLPT sits on top of the ordinary testing programme, it does not replace it.
How often is DORA TLPT required?
At least once every three years for designated significant entities, and your competent authority can adjust that frequency based on your risk profile.
Does every DORA entity have to do TLPT?
No. Competent authorities designate which entities must perform TLPT — typically the systemically important ones. Everyone else still owes the Art. 24-25 testing programme, including regular penetration testing of critical systems.
Can an AI platform perform our TLPT?
Not the formal exercise — TLPT requires qualified red-teamers and independent threat intelligence. But continuous AI-driven pentesting between cycles closes the easy findings first, so the human red team spends its time on the hard, high-value scenarios.
A straight answer on manual vs. AI
A DORA TLPT must be run by qualified red-teamers — that is the regulation, and it is the right call: creative human adversaries chaining business-logic flaws are exactly what the exercise is meant to simulate, and no tool replaces them. What an AI platform does is change what the red team finds. Run continuous, AI-driven pentesting between cycles to close the obvious, programmatically-findable holes after every deploy; reserve the human TLPT for the deep, adversarial, high-assurance test the regulator wants. The strongest programmes do both — and the AI keeps you defensible every day in between.
Bottom line: DORA TLPT is a live-fire, intelligence-led red-team test on the systems that run your business — and it rewards firms that were already testing continuously. An AI penetration testing system will not sign your TLPT report, but it is how you arrive at one with far less to fix.
Walk into your next TLPT with fewer easy wins to give away
Continuous internal + external penetration testing of your critical functions, mapped to DORA, from $79/month.
See plans & pricing
Alexander Sverdlov
Founder of Pentestas. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.
