Does every DORA entity need a threat-led penetration test?
No. Every financial entity needs a proportionate digital operational resilience testing programme, while competent authorities identify which entities must perform advanced TLPT at least every three years.
Operating sequence
- 01
Map systems and services supporting critical or important functions.
- 02
Keep ordinary testing, scenario testing, vulnerability work, and TLPT requirements distinct.
- 03
For designated TLPT, govern scope, threat intelligence, red and blue teams, provider participation, remediation, and attestation.
Failure modes to avoid
- Calling a conventional penetration test “TLPT”.
- Excluding third-party systems that support the tested critical function without analysis.
- Treating the test report as completion before remediation and closure.
The source remains the authority.
DORA Articles 24–27 — EUR-Lex