Regulation (EU) 2022/2554

Threat-led penetration testing under DORA

Separate ordinary resilience testing from the advanced TLPT duty for designated financial entities.

Written and reviewed by Fredrik Surtell ·

Does every DORA entity need a threat-led penetration test?

No. Every financial entity needs a proportionate digital operational resilience testing programme, while competent authorities identify which entities must perform advanced TLPT at least every three years.

Operating sequence

  1. 01

    Map systems and services supporting critical or important functions.

  2. 02

    Keep ordinary testing, scenario testing, vulnerability work, and TLPT requirements distinct.

  3. 03

    For designated TLPT, govern scope, threat intelligence, red and blue teams, provider participation, remediation, and attestation.

Failure modes to avoid

  • Calling a conventional penetration test “TLPT”.
  • Excluding third-party systems that support the tested critical function without analysis.
  • Treating the test report as completion before remediation and closure.

The source remains the authority.

DORA Articles 24–27 — EUR-Lex