DORA TLPT: Who Must Test, the 3-Year Cycle and Pooled Testing Explained
DORA requires financial entities singled out by their TLPT authority to carry out threat-led penetration testing at least every three years, on live production systems supporting critical or important functions. The detailed rules are in Commission Delegated Regulation (EU) 2025/1190, adopted on 13 February 2025 and published in the Official Journal on 18 June 2025. They name the firms that are in scope by default, from G-SIIs and O-SIIs to payment institutions above EUR 150 billion of payment transactions in each of the two preceding years. When an ICT supplier's other, non-financial customers could be harmed by its taking part, DORA permits pooled testing.
Scope note: why this concerns UK organisations
DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025 and is not UK law. TLPT obligations fall on EU financial entities, such as the EU-authorised bank, insurer or e-money institution of a UK group. UK firms are also involved as ICT suppliers whose clients test them, or as testers and threat-intelligence providers. Whether a test run under any UK scheme counts for DORA is not addressed in the sources of the DORA knowledge base; the mutual recognition in DORA Article 26(7) is described as being between competent authorities.
The cycle and the basics
- Every 3 years at least, under Article 26(1). The competent authority may require a shorter or longer interval depending on the firm's risk profile and operational circumstances.
- Live production systems, covering several or all critical or important functions, including those outsourced to ICT third-party providers (Article 26(2)). The authority validates the scope.
- Not for everyone: microenterprises and firms under the Article 16(1) simplified framework are excluded.
- Built on TIBER-EU: recital 1 of RTS 2025/1190 states that it mirrors TIBER-EU, and firms may apply TIBER-EU or a national implementation insofar as it is consistent with DORA and the RTS.
TLPT sits on top of the general testing programme: all financial entities other than microenterprises must test every ICT system and application supporting critical or important functions at least yearly (Article 24(6)).
Which firms are in scope by default
The TLPT authority assesses each firm's impact, systemic character and ICT risk profile (RTS Article 2(1)). Article 2(2) lists firms it must require to test unless that assessment shows TLPT is unjustified:
- credit institutions identified as G-SIIs or O-SIIs, or part of one;
- payment institutions above EUR 150 billion in total value of payment transactions in each of the two calendar years preceding the assessment;
- e-money institutions above EUR 150 billion of payment transactions or above EUR 40 billion of outstanding electronic money, in each of those two years;
- all central securities depositories and central counterparties;
- electronic trading venues with the highest national turnover share in certain instruments, or more than 5% of EU turnover, in each of the two preceding years;
- large insurers and reinsurers, filtered in two stages: GWP above EUR 1.5 billion and technical provisions above EUR 10 billion (and, for life or composite insurers, assets above 3.5% of the national market); then GWP above EUR 3 billion, technical provisions above EUR 30 billion, or assets above 10% of the national market.
Worked example (illustrative figures)
An EU e-money subsidiary of a UK fintech group had EUR 42 billion of outstanding e-money in the first preceding year and EUR 38 billion in the second, with payment volumes well below EUR 150 billion. Because EUR 38 billion is under EUR 40 billion, the e-money criterion is not met "in each" year, so the firm is not in the default list. The authority may still identify it under the general Article 2(1) factors.
Group structure matters. Where several group entities share ICT systems or the same intra-group ICT provider, authorities decide whether individual tests are relevant, and a joint TLPT is preferred where it reduces costs and resources (RTS Articles 2(3) and 16(2)). Testers employed by an ICT intra-group service provider count as internal testers (Article 15(4)).
Phases and deadlines
RTS 2025/1190 timetable
| Step | Timing |
|---|---|
| Initiation information to test managers | Within 3 months of the TLPT notification |
| Scope specification document (approved by the management body) | Within 6 months of the notification |
| Scenario selection | At least three; at most one non-threat-led |
| Active red team phase | Minimum 12 weeks; weekly progress reports |
| Red team report | Within 4 weeks of the end of active testing |
| Blue team report, replay and purple teaming | No later than 10 weeks after active testing ends |
| Summary report and remediation plan | Each within 8 weeks of the authority confirming the reports are complete |
Confidentiality runs through the whole process: access is need-to-know, parties use a code name where possible, and the control team must be told if staff at the firm or its ICT suppliers detect the test (RTS Article 4). The authority then issues an attestation (DORA Article 26(7)).
Rules for testers and threat-intelligence providers
DORA Article 27(1) requires testers to be of the highest suitability and reputability, to have specific expertise, to be certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks, to provide independent assurance or an audit report, and to hold professional indemnity cover. A UK red-team firm should therefore check which of those two routes it can evidence.
RTS Article 7 then sets minimum staffing and track record. External red teams need a manager with at least 5 years' experience and at least two testers with at least 2 years each, a combined participation in at least five prior assignments, and at least five references. Threat-intelligence teams need a manager with 5 years' experience, a second member with 2 years', and at least three references. Firms may depart from these points only in exceptional circumstances, with documented mitigating measures.
Pooled testing: the option for ICT suppliers
Contracts for ICT services supporting critical or important functions must oblige the supplier to participate and fully cooperate in the client's TLPT (DORA Article 30(3)(d)). For a supplier with many financial and non-financial customers on shared infrastructure, repeated one-off tests can be a real risk.
Article 26(4) addresses this. Where the supplier's participation is reasonably expected to harm the quality or security of services for customers outside DORA's scope, or the confidentiality of their data, the firm and the supplier may agree in writing that the supplier itself contracts an external tester for a pooled TLPT, under the direction of one designated financial entity, involving several of its financial clients. The pooled test counts as TLPT for each participant, and the number of participants is calibrated to the complexity and types of services. Under RTS Article 10(4), at least one scenario must include the supplier's underlying systems supporting the clients' critical or important functions.
Preparation checklist
- Check each EU entity against the Article 2(2) criteria, using two full calendar years of data.
- Map critical or important functions and the suppliers behind them.
- Confirm the TLPT cooperation clause is in every relevant supplier contract.
- Identify suppliers who may request pooled testing, and agree the approach in writing.
- Shortlist testers and threat-intelligence providers against Article 27 DORA and Article 7 of the RTS.
- Budget for a 6-month scoping window and a 12-week minimum active phase.
For a quick, sourced answer on any of these points, query the DORA knowledge base, for instance: "Above what total value of payment transactions must a payment institution be required by its TLPT authority to perform threat-led penetration testing?"
Check TLPT rules against the source
The DORA base indexes DORA Articles 24 to 27 and the full text of RTS 2025/1190, with citations on every answer.
This guide is not legal advice. Official sources: RTS 2025/1190 on EUR-Lex and DORA on EUR-Lex.
Frequently asked questions
What is the TLPT frequency under DORA?
At least every three years (DORA Article 26(1)), with the competent authority able to shorten or lengthen the interval according to the firm's risk profile and operational circumstances.
Does DORA TLPT apply to UK firms?
DORA is EU law and not part of UK law. TLPT duties fall on EU financial entities identified by their TLPT authority, including EU subsidiaries of UK groups; UK suppliers can be brought into scope through their contracts.
When can an ICT supplier ask for pooled testing?
When its participation is reasonably expected to adversely affect the quality, security or data confidentiality of services to customers outside DORA's scope. The firm and supplier must agree in writing (Article 26(4)).
What experience must external red teamers have?
Under RTS 2025/1190 Article 7, a manager with at least 5 years' experience and at least two testers with at least 2 years each, at least five prior assignments combined, and at least five references.
How long does a DORA TLPT take?
Up to 6 months for scoping after notification, at least 12 weeks of active red teaming, then reports within 4 and 10 weeks and summary and remediation documents within 8 weeks of the authority's confirmation.
Get the Kopik newsletter
New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.
By subscribing you agree to receive our newsletter. We never share your address.