DORA:
the testing digital operational resilience requires
A guide for banks, fintechs, insurers and their technology suppliers: what baseline testing covers, what TLPT means, and who has to run it.
DORA — Regulation (EU) 2022/2554 on digital operational resilience — has applied since 17 January 2025 and changes the question a financial supervisor asks. It is no longer "do you have security controls?" but "have you demonstrated the critical service survives a real attack?". That difference has direct consequences for how testing is planned.
Who it applies to — and why it matters beyond the EU
DORA covers essentially the whole European financial sector: credit institutions, payment and e-money institutions, investment firms, fund managers, insurers, crypto-asset service providers, market infrastructures. On top of that sits a second circle, often overlooked: third-party ICT service providers — hosting, cloud, banking software, processing, maintenance.
The baseline testing programme
DORA requires a digital resilience testing programme applied at least annually to all ICT systems supporting critical or important functions. The programme is not one test but a set: vulnerability assessments, open source scans, network security analyses, physical security reviews, questionnaires, source code reviews, compatibility testing, performance testing and penetration tests.
Two cross-cutting conditions change practice: testing must be performed by independent parties, internal or external, free of conflict of interest with the team that built the system; and findings must enter a tracked remediation process, prioritised by risk to critical functions.
TLPT: threat-led penetration testing
Above the baseline programme, DORA introduces advanced testing for entities designated by the competent authorities, based on risk and systemic importance criteria. TLPT is run at least once every three years, follows the European TIBER-EU framework, and differs from an ordinary pentest in three essential ways.
- It is built on real threat intelligence: an intelligence provider builds the scenarios from the groups that actually target your sector.
- It runs against production systems, not a test environment — hence the strict governance and a small control team inside the entity.
- It measures the defence, not just the attack: the blue team does not know the test is happening, and the result includes how fast it detected and responded.
A TLPT exercise usually spans several months and ends with a replay phase: attackers and defenders walk the timeline together, minute by minute, to see where a signal existed and went unnoticed. That phase usually produces more improvement than the vulnerability list does.
Baseline vs. TLPT — what, who, how often
| Aspect | Baseline programme | TLPT |
|---|---|---|
| Who is covered | All financial entities in DORA scope | Only entities designated by the authority |
| Frequency | At least annually | At least once every three years |
| Environment | Usually pre-production or production, by agreement | Live production systems |
| What is measured | Vulnerabilities and configurations | Detection, response and resilience of critical functions |
| Reference framework | Standard methodologies (OWASP, PTES, NIST) | TIBER-EU, with the authority involved in the process |
What to do before you reach TLPT
A threat-led exercise against untested infrastructure produces a predictable, expensive report: the attackers reach critical functions quickly by mundane paths, and the useful conclusion is lost. The healthy order is the reverse — first close the obvious paths with classic testing, then measure detection and response.
- An inventory of critical functions and the ICT systems supporting them — without it, TLPT scope cannot be defined.
- Classic external and internal testing, with remediation taken through to re-test.
- The ICT provider register and the contractual testing and audit clauses.
- Real detection capability: with no centralised monitoring, TLPT will measure its absence.
Frequently asked questions
What is DORA and since when does it apply?
DORA is Regulation (EU) 2022/2554 on the digital operational resilience of the financial sector, applicable since 17 January 2025. Being a regulation rather than a directive, it applies directly in the member states with no national transposition. It covers five areas: ICT risk management, incident reporting, digital resilience testing, third-party ICT risk and threat information sharing.
What is TLPT and how does it differ from an ordinary pentest?
TLPT means threat-led penetration testing — testing driven by real threat intelligence. It differs in three ways: scenarios are built from the groups actually attacking that sector, the test runs against live production systems, and the defending team is not informed, so detection and response capability is measured too. It follows the TIBER-EU framework, with the competent authority involved in the process.
Must every financial entity run TLPT?
No. The annual baseline testing programme applies to all entities in DORA scope. TLPT applies only to entities designated by the competent authorities, on risk, size and systemic importance criteria — mainly institutions whose unavailability would affect financial stability. For those designated, the minimum frequency is once every three years.
I am an IT supplier to an EU bank. Does DORA concern me?
Directly, only if you are designated a critical ICT service provider at European level. Indirectly, almost certainly yes: the financial entity must include security requirements, audit and access rights, resilience clauses and, for providers supporting critical functions, participation in resilience testing — including in the client’s TLPT exercises.
How long does a TLPT exercise take and what does it cost?
A full exercise usually takes three to six months, split into preparation, threat intelligence, the testing phase itself, and closure with a replay. Cost depends on the number of scenarios, the breadth of scope and the involvement of external providers, and sits significantly above a classic penetration test — one more reason it should not be the first test you run.
Related guides
- What a pentest costs — what drives the price, how effort is estimated, and what makes two quotes comparable.
- ISO 27001 & SOC 2 — which controls require technical testing and what evidence the auditor accepts.
- Moldova’s Law 48/2023 — the national cybersecurity framework: who is in scope and what obligations it brings.
- OWASP Top 10 — the ten web risk categories, explained with examples and what gets tested in each.
- PCI DSS 4.0 — requirements 11.3 and 11.4, segmentation testing, and what it means for payment processors.
- Pentest vs vulnerability scanning — what each one finds, what it misses, and what auditors accept as evidence.
- How to prepare for a pentest — scope, access, rules of engagement and everything settled before day one.
This material is informational and does not constitute legal or regulatory advice. DORA applicability and TLPT designation are determined by the competent authorities, case by case.
Building your DORA testing programme?
Book a free consultation: we map critical functions, scope and the sequence of tests up to the level required of you.