TLPT applies only to designated entities. Most DORA-covered firms meet their testing obligation through Articles 24–25 instead. Getting this wrong is expensive in both directions.
Designation is determined by your competent authority. If you are unsure, we will help you establish which obligation applies before you commit budget.
TLPT follows the TIBER-EU phases, and the structure is deliberately different from a scoped penetration test. In the preparation phase, the entity forms a control team and engages its competent authority’s TIBER Cyber Team; scope is set around critical or important functions, and providers are contracted. The threat intelligence phase produces a targeted threat profile and attack scenarios grounded in the real adversaries facing your institution. The active red team phase, at least twelve weeks under the RTS, executes those scenarios against live production, testing not just technical controls but your detection and response, your blue team, in real conditions. Closure brings the red team and defenders together to replay the engagement, agree findings, and produce the reporting your authority requires, including a certificate of completion.
As your red team provider, we operate the intelligence-led attack under strict rules of engagement agreed with your control team and your regulator. Because we maintain threat intelligence capability in-house, our scenarios are built on current adversary behaviour rather than generic attack playbooks, and where we are engaged as the threat intelligence provider on a separate test, the red team function is kept independent as the framework requires.
The output is not a vulnerability list; it is an evidenced account of how a realistic adversary fares against your live defences, in the form your competent authority expects to receive.
Institutions that approach TLPT as a larger penetration test get it wrong in expensive ways. A pentest enumerates known weaknesses in defined systems; TLPT asks whether a realistic, funded adversary can compromise the functions your business depends on, while your defenders are live and unaware. It runs on production, not staging, because the point is to test the real environment and the real people responding to it. And it is supervised: your competent authority is involved throughout, and the deliverables are prescribed.
The other frequent mistake is timing. A full cycle, from provider procurement to attestation, takes nine to fourteen months, and provider capacity across the EU is scarce. Entities that have received a designation notification and not begun planning are already behind. Starting early is not caution; it is the only way to secure a qualified provider and meet the deadline.
TLPT is a governed, intelligence-led exercise with a regulator in the room. We run it as one, which is why the readiness work below matters before the test itself begins.
The phases of a DORA TLPT engagement under the updated TIBER-EU framework, and where we sit as your red team provider.
Indicative durations. A full cycle typically runs 9–14 months from provider procurement to attestation.
Whether you are newly designated or approaching your next cycle, talk to us about scoping, readiness and red team delivery, with a scoped proposal within one working day.