DORA TLPT Red Team Provider

Threat-led penetration testing under DORA is not a bigger pentest. It is an intelligence-led red team exercise against your live production systems, run to the TIBER-EU framework, supervised by your competent authority, and mandatory at least every three years for designated financial entities.

RedSecLabs delivers TLPT as an external red team provider. We have completed threat-led penetration testing engagements under the TIBER-EU framework for financial entities, working to the DORA TLPT regulatory technical standard (Commission Delegated Regulation (EU) 2025/1190). We are CREST-accredited, run intelligence-led red team operations against live production environments, and maintain threat intelligence capability in-house.

TLPT engagements are confidential, so we do not name clients or supervisory authorities publicly. We are happy to discuss our experience directly, under NDA, with entities evaluating providers.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Confidential Enquiry

TLPT provider selection is sensitive. Tell us the essentials and a senior consultant will respond directly — we can execute an NDA before any detail is shared.

Handled by a senior consultant, not a sales queue. NDA available before scoping.

TLPT engagements delivered · TIBER-EU methodology · CREST-accredited · In-house threat intelligence · Live production, controlled delivery
Who this is for

This service fits if you’re..

1
Designated entities
Banks, insurers and payment institutions notified by their competent authority that they fall in scope for DORA TLPT.
2
G-SIIs and large firms
Globally systemically important institutions automatically in scope, and large entities expecting designation.
3
Prior TIBER participants
Entities with an earlier TIBER-EU test seeking a provider for their next three-year cycle under DORA.

DORA TLPT, Quick Facts

Last reviewed: 2026-07-21
Governing standard
DORA Articles 26–27, with the TLPT regulatory technical standard, Commission Delegated Regulation (EU) 2025/1190, applicable from 8 July 2025
Methodology
The TIBER-EU framework (European Central Bank), updated in February 2025 to align with the DORA RTS
Frequency
At least every three years for designated entities; the cycle can carry over from a qualifying earlier TIBER-EU test
Scope
Live production systems supporting critical or important functions. Staging or test environments do not qualify
Red team phase
A minimum active red-teaming period of 12 weeks under the RTS
Two-provider rule
The threat intelligence and red team functions must be independent on a test; we provide the red team, and hold in-house threat intelligence where we lead that role on a separate engagement
TIBER-EU
Framework we deliver to
12 weeks
Minimum active red team phase
3 years
Maximum interval between tests
9-14 mo
Typical full cycle, plan early
Scope check

Do you actually need TLPT?

TLPT applies only to designated entities. Most DORA-covered firms meet their testing obligation through Articles 24–25 instead. Getting this wrong is expensive in both directions.

TLPT likely applies
Articles 26–27
  • You are a globally systemically important institution (G-SII)
  • Your regulator has formally notified you of TLPT designation
  • You completed a TIBER-EU test and the three-year cycle is approaching
  • You are a large bank, insurer, payment institution or CSD expecting designation
Discuss provider selection
Articles 24–25 is your route
Regular testing obligation
  • You are a smaller entity with no designation notification
  • Your obligation is DORA Articles 24–25 regular testing only
  • You need vulnerability assessments and standard penetration testing
  • You are unsure — most covered entities never perform TLPT
See financial services testing

Designation is determined by your competent authority. If you are unsure, we will help you establish which obligation applies before you commit budget.

How a TLPT engagement actually runs

TLPT follows the TIBER-EU phases, and the structure is deliberately different from a scoped penetration test. In the preparation phase, the entity forms a control team and engages its competent authority’s TIBER Cyber Team; scope is set around critical or important functions, and providers are contracted. The threat intelligence phase produces a targeted threat profile and attack scenarios grounded in the real adversaries facing your institution. The active red team phase, at least twelve weeks under the RTS, executes those scenarios against live production, testing not just technical controls but your detection and response, your blue team, in real conditions. Closure brings the red team and defenders together to replay the engagement, agree findings, and produce the reporting your authority requires, including a certificate of completion.

As your red team provider, we operate the intelligence-led attack under strict rules of engagement agreed with your control team and your regulator. Because we maintain threat intelligence capability in-house, our scenarios are built on current adversary behaviour rather than generic attack playbooks, and where we are engaged as the threat intelligence provider on a separate test, the red team function is kept independent as the framework requires.

What we deliver as your red team provider:
Intelligence-led attack scenarios based on the real threats to your institution
A minimum twelve-week active red team phase against live production, per the RTS
Testing of detection and response, not just preventive controls
Delivery to the updated TIBER-EU red team guide and the DORA RTS deliverables
Rules of engagement and risk management agreed with your control team and regulator
Closure-phase replay, findings and the reporting your authority requires

The output is not a vulnerability list; it is an evidenced account of how a realistic adversary fares against your live defences, in the form your competent authority expects to receive.

Why TLPT is different from a penetration test

Institutions that approach TLPT as a larger penetration test get it wrong in expensive ways. A pentest enumerates known weaknesses in defined systems; TLPT asks whether a realistic, funded adversary can compromise the functions your business depends on, while your defenders are live and unaware. It runs on production, not staging, because the point is to test the real environment and the real people responding to it. And it is supervised: your competent authority is involved throughout, and the deliverables are prescribed.

The other frequent mistake is timing. A full cycle, from provider procurement to attestation, takes nine to fourteen months, and provider capacity across the EU is scarce. Entities that have received a designation notification and not begun planning are already behind. Starting early is not caution; it is the only way to secure a qualified provider and meet the deadline.

Common misunderstandings that derail TLPT:
Treating TLPT as a bigger pentest rather than an intelligence-led red team
Assuming staging is acceptable, the RTS requires live production
Underestimating the nine-to-fourteen-month cycle and provider scarcity
Missing the two-provider independence rule between threat intel and red team
Overlooking that detection and response, not just prevention, are under test
Confusing TLPT with DORA’s separate annual testing obligation (Articles 24–25)

TLPT is a governed, intelligence-led exercise with a regulator in the room. We run it as one, which is why the readiness work below matters before the test itself begins.

Need this scoped fast? Send your target list and we’ll return a fixed price within one working day.
Get a Fixed Quote
Engagement lifecycle

The TIBER-EU phases we operate in

The phases of a DORA TLPT engagement under the updated TIBER-EU framework, and where we sit as your red team provider.

1
Preparation 4–8 weeks
Your control team engages your regulator’s TIBER Cyber Team, scope is set around critical or important functions, and providers are formally contracted. We support scoping and rules-of-engagement drafting from the start.
2
Threat intelligence 4–6 weeks
A targeted threat profile and attack scenarios are produced, grounded in the adversaries realistically facing your institution. This is delivered by the independent threat intelligence provider; we bring in-house TI capability where we lead this role on a separate engagement.
3
Active red teaming 12+ weeks
At least twelve weeks executing the scenarios against live production under strict rules of engagement, testing preventive controls and your blue team’s detection and response in real conditions.
4
Closure and replay 4–6 weeks
Red team and defenders replay the engagement together, agree findings and remediation, and produce the reporting and certificate of completion your regulator requires.
5
Remediation and re-test Post-test
We support remediation planning and validation of the fixes, so improvements are evidenced ahead of your next three-year cycle.

Indicative durations. A full cycle typically runs 9–14 months from provider procurement to attestation.

Plan Your DORA TLPT Early

Whether you are newly designated or approaching your next cycle, talk to us about scoping, readiness and red team delivery, with a scoped proposal within one working day.

Frequently Asked Questions

DORA Article 26 takes a two-tier approach. Globally systemically important institutions (G-SIIs) are automatically in scope. Other financial entities are designated by their competent authority based on risk, size and systemic importance. If you have received a designation notification, you are in scope and on the clock; if you are a large or systemically important entity, you should plan on the assumption you will be designated.

No, and conflating them is a common and costly error. DORA Articles 24–25 require all covered entities to perform regular vulnerability assessments and penetration testing. TLPT (Articles 26–27) is a separate, higher obligation for designated entities only: an intelligence-led red team on live production, following TIBER-EU, supervised by your authority, at least every three years. We deliver both, scoped correctly and kept distinct.

The DORA TLPT regulatory technical standard, Commission Delegated Regulation (EU) 2025/1190, applicable since 8 July 2025, and the TIBER-EU framework published by the European Central Bank, which was updated in February 2025 to align with that RTS. Our engagements follow the updated TIBER-EU guides and produce the deliverables your competent authority expects.

On a single test the two functions must be independent, which is a core requirement of the framework. RedSecLabs delivers the red team, and we maintain in-house threat intelligence capability that we bring where we are engaged to lead the threat intelligence role on a separate engagement. On your test we make the separation explicit and coordinate with the other provider and your control team.

Typically nine to fourteen months from provider procurement to the final attestation, including a minimum twelve-week active red team phase. Because qualified provider capacity across the EU is limited, entities targeting a specific completion date should begin procurement many months ahead. If you have been designated and have not started, you are most likely already behind schedule.

It can. A TIBER-EU test conducted under the framework’s requirements, and after the relevant DORA application date under an authority that has adopted the aligned framework, can count towards your three-year cycle, provided it met the scope and requirements of the RTS. We can review a prior test and advise whether it qualifies or where a gap needs closing.

Your national competent authority, the financial regulator that supervises you, oversees the test. Examples include De Nederlandsche Bank, BaFin and the Bundesbank, the ACPR and Banque de France, the CSSF, the Central Bank of Ireland, and the ECB for directly supervised banks. Their TIBER Cyber Team engages with your control team on scope, provider selection and the required deliverables. As your red team provider we operate inside that governed process, to the rules of engagement agreed between you and your regulator.

Yes. We have completed threat-led penetration testing engagements under the TIBER-EU framework for financial entities. Because TLPT is confidential by nature, covering an entity’s critical functions and its detection and response capability, we do not publish client names or supervisory details. We are glad to discuss our experience, methodology and references directly under NDA as part of your provider selection.

Many entities are not, and starting the formal test before you are ready wastes the engagement. We offer TLPT readiness: a pre-test intelligence-led red team dry run, control-gap review, and support with scoping, provider coordination and authority liaison, so that when the supervised test runs, it measures a mature environment rather than exposing basic gaps.
📞 Call us Book a call