DORA TLPT: who must run threat-led penetration tests and how
Threat-led penetration testing (TLPT) is the advanced testing DORA requires from certain financial entities, based on the experience of the TIBER-EU framework. Delegated Regulation (EU) 2025/1190 sets who is in scope, how tests run and what testers must prove.
Ask your question
Free account requiredAnswers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.
Entities required to perform TLPT
TLPT authorities require it from, among others, credit institutions identified as G-SIIs or O-SIIs or part of one, central securities depositories, central counterparties and certain trading venues.
Payment institutions are in scope if they exceeded EUR 150 billion of total value of payment transactions in each of the 2 calendar years before the assessment. For electronic money institutions, the test is the same EUR 150 billion, or EUR 40 billion of outstanding electronic money.
Identified entities carry out TLPT at least every 3 years; the competent authority may reduce or increase this frequency.
From red team to purple teaming
The active red team testing phase lasts at least 12 weeks, with testers reporting at least weekly. Within 4 weeks of its end, testers submit the red team test report. No later than 10 weeks after the end, the blue team submits its report and both teams replay the attack, followed by a purple teaming exercise.
Frequently asked questions
What experience must the testing team have?
External testers need a team with at least a manager with 5 years of experience in penetration and red team testing and two additional testers with at least 2 years each. They must provide at least five references from previous assignments.
Can the threat intelligence provider be internal?
No. Testers may be internal or external, but threat intelligence providers are always external. The provider must give at least three references from previous assignments.
Can a TLPT be paused if it becomes risky?
Yes. In exceptional circumstances the control team lead may suspend it, or, as a last resort and with validation by the TLPT authority, continue with a limited purple teaming exercise that counts towards the 12 weeks.
Embed / API / MCP
Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs β¬0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.
MCP for your agents
This base's MCP server URL (tools ask_base and search_base):
https://kopik.io/api/mcp?base=eu-dora-ict-resilienceClaude Code, Cursor and other clients
claude mcp add --transport http kopik-eu-dora-ict-resilience "https://kopik.io/api/mcp?base=eu-dora-ict-resilience" --header "Authorization: Bearer kpk_β¦"{
"mcpServers": {
"kopik-eu-dora-ict-resilience": {
"url": "https://kopik.io/api/mcp?base=eu-dora-ict-resilience",
"headers": {
"Authorization": "Bearer kpk_β¦"
}
}
}
}REST API for your apps
mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.
curl -X POST https://kopik.io/api/v1/bases/eu-dora-ict-resilience/query \
-H "Authorization: Bearer kpk_β¦" \
-H "Content-Type: application/json" \
-d '{"question": "Your question here", "mode": "answer"}'Getting started
- Create a key in your dashboard and top up your credit.
- Replace
kpk_β¦with your key. - Full details (responses, errors, JS and Python examples): developer docs.