Banking & financeVerified by Kopik: Official sources reviewed and answers tested by Kopik

DORA TLPT: who must run threat-led penetration tests and how

Threat-led penetration testing (TLPT) is the advanced testing DORA requires from certain financial entities, based on the experience of the TIBER-EU framework. Delegated Regulation (EU) 2025/1190 sets who is in scope, how tests run and what testers must prove.

Ask your question

Free account required

Each question stands alone Β· 1 free a month, then with a subscription.

Answers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.

Entities required to perform TLPT

TLPT authorities require it from, among others, credit institutions identified as G-SIIs or O-SIIs or part of one, central securities depositories, central counterparties and certain trading venues.

Payment institutions are in scope if they exceeded EUR 150 billion of total value of payment transactions in each of the 2 calendar years before the assessment. For electronic money institutions, the test is the same EUR 150 billion, or EUR 40 billion of outstanding electronic money.

Identified entities carry out TLPT at least every 3 years; the competent authority may reduce or increase this frequency.

From red team to purple teaming

The active red team testing phase lasts at least 12 weeks, with testers reporting at least weekly. Within 4 weeks of its end, testers submit the red team test report. No later than 10 weeks after the end, the blue team submits its report and both teams replay the attack, followed by a purple teaming exercise.

Frequently asked questions

What experience must the testing team have?

External testers need a team with at least a manager with 5 years of experience in penetration and red team testing and two additional testers with at least 2 years each. They must provide at least five references from previous assignments.

Can the threat intelligence provider be internal?

No. Testers may be internal or external, but threat intelligence providers are always external. The provider must give at least three references from previous assignments.

Can a TLPT be paused if it becomes risky?

Yes. In exceptional circumstances the control team lead may suspend it, or, as a last resort and with validation by the TLPT authority, continue with a limited purple teaming exercise that counts towards the 12 weeks.

For developers and agents

Embed / API / MCP

Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.

MCP for your agents

This base's MCP server URL (tools ask_base and search_base):

MCP URL
https://kopik.io/api/mcp?base=eu-dora-ict-resilience
Claude Code, Cursor and other clients
Claude Code
claude mcp add --transport http kopik-eu-dora-ict-resilience "https://kopik.io/api/mcp?base=eu-dora-ict-resilience" --header "Authorization: Bearer kpk_…"
JSON config (mcpServers)
{
  "mcpServers": {
    "kopik-eu-dora-ict-resilience": {
      "url": "https://kopik.io/api/mcp?base=eu-dora-ict-resilience",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

REST API for your apps

mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-dora-ict-resilience/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Your question here", "mode": "answer"}'

Getting started

  1. Create a key in your dashboard and top up your credit.
  2. Replace kpk_… with your key.
  3. Full details (responses, errors, JS and Python examples): developer docs.