Showing posts with label DORA. Show all posts
Showing posts with label DORA. Show all posts

Tuesday, September 15, 2026

DORA TLPT Explained: Threat-Led Penetration Testing Deadline Is 2028, But Procurement Must Start in 2026


17 January 2028 sounds a long way off. For any EU financial entity designated for DORA TLPT (Threat-Led Penetration Testing), it isn't. Once you account for provider scarcity, regulatory scoping, and a testing cycle that runs 9 to 14 months on its own, the real deadline that matters is 2026 — because that is when procurement has to begin.

If your bank, insurer, investment firm, or payment institution has received a designation notice from your National Competent Authority (NCA), this article breaks down exactly what Threat-Led Penetration Testing under DORA Article 26 requires, why the timeline is tighter than it looks, and what to do about it right now.

What Is DORA TLPT, Exactly?

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has been in force across the EU since 17 January 2025. Among its five pillars — ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing — Article 26 and Article 27 introduce the most demanding obligation of all: Threat-Led Penetration Testing, modelled directly on the European Central Bank's TIBER-EU framework.

Unlike a standard vulnerability scan or annual penetration test, TLPT is an intelligence-led, covert red team exercise run against your live production environment. Your own security operations team is not told it is happening. A licensed threat intelligence provider first builds a Targeted Threat Intelligence (TTI) report profiling the real adversaries most likely to target your institution — nation-state actors, organised financial cybercrime groups, or insider-threat scenarios. An accredited red team then executes those exact attack scenarios against your critical or important functions, including outsourced and cloud infrastructure, for a minimum of 12 weeks.

AspectTraditional Penetration TestDORA TLPT / TIBER-EU
Driven byStandard checklistReal, targeted threat intelligence
AwarenessBlue team informedBlue team unaware ("blind" test)
EnvironmentTest/staging systemsLive production systems
Duration1–4 weeks9–14 months end to end
ProviderAny qualified testerTIBER-EU accredited providers only
OutcomeVulnerability listFormal supervisory attestation

TLPT is not optional and it is not self-selected. Your NCA designates you based on systemic importance, asset size, and criticality to the financial system. Once designated, the obligation repeats at least every three years, and no generic penetration test can substitute for it.

The 2028 Deadline — And Why It's Already Close

The first mandatory TLPT cycle under DORA must be completed by 17 January 2028. On paper, that is more than a year away from today. In practice, a full engagement — provider procurement, scope agreement with your competent authority, the threat intelligence phase, the red team campaign, purple teaming, remediation, and final attestation — typically takes between 9 and 14 months once everything is running smoothly.

The real bottleneck: provider capacity. There are only an estimated 30–40 TIBER-EU accredited red team and threat intelligence providers across the entire EU, and well over 8,000 financial entities may fall within TLPT scope. With hundreds of institutions needing a slot in the same 2026–2027 window, qualified providers are already booking capacity 12 to 18 months in advance.

Typical DORA TLPT Timeline

MilestoneRecommended Timing
Designation notification from your NCAOngoing — check supervisory correspondence
Begin threat intelligence & red team provider procurement12–18 months before target test date (i.e., 2026)
Scope agreement with competent authority8–10 months before the test
Threat intelligence phase6–10 weeks
Red team execution8–12 weeks (minimum 12 under TIBER-EU)
Purple teaming & closure3–10 weeks
Final report & supervisory attestation4–8 weeks
First mandatory deadline17 January 2028

Work backwards from January 2028 and the math is unforgiving: procurement should realistically start in 2026, not 2027. Entities that wait until designation pressure builds risk being left with whatever accredited provider capacity remains — often at a premium, and often without the specialist industry experience their scope actually needs.

What Happens If You Miss the Deadline?

Missing the 2028 deadline, running a poorly scoped test, or failing to remediate critical findings on the agreed timeline all expose an institution to enforcement action under DORA Article 50, including financial penalties tied to global annual turnover and operational restrictions imposed by supervisors. For designated entities, TLPT sits alongside the broader resilience testing programme required under Article 25 — but it carries a legal weight and reputational visibility that an annual vulnerability scan does not.

How to Prepare Now

  • Confirm designation status with your NCA and don't assume you're out of scope simply because you haven't been formally notified yet.
  • Start provider procurement in 2026 — evaluate TIBER-EU accredited threat intelligence and red team providers before capacity dries up.
  • Map critical and important functions, including third-party and cloud dependencies, ahead of scoping discussions.
  • Run standing red team and continuous penetration testing programmes so TLPT becomes a checkpoint rather than a scramble.
  • Align TLPT with your wider DORA programme — ICT risk management, incident reporting, and third-party risk registers all feed into a credible scope document.

This is exactly where experienced penetration testing services earn their keep well before the formal TLPT clock starts. A mature, continuous testing programme built on CREST-approved methodology gives your institution a defensible baseline while you queue for accredited TLPT capacity. VistaInfoSec's broader guidance on common DORA compliance challenges is a useful starting point if you're still building out your resilience testing roadmap.

It's also worth understanding how TLPT fits alongside your other frameworks. If your institution already holds ISO 27001 or SOC 2, this DORA, ISO 27001 and SOC 2 mapping guide shows exactly where DORA's testing requirements go beyond what those certifications already cover. And if NIS2 obligations apply to any part of your group alongside DORA, this NIS2 vs DORA compliance guide untangles where the two regulations overlap and where they diverge.

The Bottom Line

DORA TLPT isn't a 2028 problem — it's a 2026 decision. The financial entities that treat threat-led penetration testing as a checkpoint within an already-mature security testing programme will move through designation, scoping, and attestation calmly. Those that wait will be negotiating with whatever accredited provider has a slot left, on someone else's timeline. For EU financial institutions serious about operational resilience, the smartest move this year is simple: start the conversation with accredited providers now, not in Q4 2027.

Wednesday, June 17, 2026

DORA's First Threat-Led Penetration Tests Are Here: What Financial Entities Must Prove in 2026



For the first time since the Digital Operational Resilience Act (DORA) came into force, European financial entities are receiving official notifications to undergo Threat-Led Penetration Testing (TLPT). This is not a routine compliance exercise. It is a live, regulator-mandated simulation of a real cyberattack against your organisation's most critical systems, and the results will determine how supervisors view your operational resilience for years to come.


If your organisation is a bank, insurer, asset manager, payment provider, or an ICT service provider supporting any of these, 2026 is the year DORA stops being a compliance document and starts being an operational reality. Here is exactly what is happening, what is required of you, and how to prepare.


From Guidance to Enforcement: Where DORA Stands in 2026

DORA has been fully enforceable since January 17, 2025, following a two-year transition period. Unlike NIS2, which required each EU member state to transpose it into national law, DORA is a regulation, meaning it applies directly and uniformly across all member states without national variation. This is the regulatory backbone for ICT risk management across the EU financial sector.


What makes 2026 distinct is that European Supervisory Authorities, the EBA, EIOPA, and ESMA, have now finalised the detailed Regulatory and Implementing Technical Standards that specify exactly how compliance must be demonstrated. Supervisors are no longer issuing guidance. They are conducting audits, scrutinising ICT third-party contracts, and issuing the first formal TLPT notifications to in-scope entities.


What Is Threat-Led Penetration Testing (TLPT) Under DORA?

TLPT is DORA's most advanced testing requirement. It mandates that designated financial entities undergo a controlled, intelligence-led simulated cyberattack against their live production systems, replicating the tactics of real threat actors rather than running a standard vulnerability scan.


Entities that receive a TLPT notification have a defined timeline to respond: three months to submit initiation documents, followed by six additional months to deliver a detailed scope specification before testing begins. This is a significant undertaking that touches threat intelligence, red-team execution, and senior management sign-off, not something that can be arranged in the final weeks before a deadline.


The first wave of TLPT notifications is being issued in late 2026, with subsequent waves continuing into 2027. Entities should not assume they are out of scope simply because they have not yet been notified. Designation criteria consider systemic importance, and the list of in-scope entities is expected to expand.


The Register of Information: Your Most Urgent 2026 Deadline

While TLPT is the headline-grabbing requirement, the Register of Information (RoI) under Article 28 of DORA is the obligation affecting every single financial entity in scope, right now. The RoI is a comprehensive register documenting all contractual arrangements with ICT third-party service providers, covering everything from your cloud infrastructure provider to your data analytics vendor.


National competent authorities must consolidate and forward these registers to the European Supervisory Authorities by March 31, 2026, using a reference date of December 31, 2025. Individual countries have set their own internal submission windows ahead of this backstop date. For example, German entities submit to BaFin between March 9 and 30, Dutch entities submit to DNB or AFM by March 20, and Irish entities submit to the Central Bank of Ireland between March 2 and 31.


This is widely regarded as the most data-intensive obligation under DORA. During the European Supervisory Authorities' 2024 dry-run exercise, only a small fraction of nearly 1,000 participating firms successfully passed all data quality checks on their first attempt, underscoring just how easy it is to get this wrong. Submissions must follow a strict xBRL-CSV format, and errors trigger a resubmission cycle that can quickly eat into your remaining time.


Why ICT Third-Party Providers Should Pay Close Attention Too

DORA's reach extends well beyond banks and insurers. If your organisation provides software, cloud hosting, cybersecurity services, or any technology service to a financial entity operating in the EU, you are part of the ecosystem DORA regulates, even if you are not directly supervised.


The European Supervisory Authorities have already published an official list of Critical ICT Third-Party Providers, including major hyperscale cloud providers and global technology and telecom firms. These designated providers face direct oversight from Joint Examination Teams. Financial entities relying on any of these providers must document the dependency in their Register of Information and assess concentration risk accordingly. In practice, this means your financial sector clients will increasingly demand proof of your own security posture, incident response capability, and resilience testing before renewing contracts.


DORA vs NIS2: Understanding the Overlap

Many organisations operating in regulated sectors are now navigating both DORA and NIS2 simultaneously, and the relationship between the two matters. DORA acts as lex specialis to NIS2 for the financial sector, meaning that where the two frameworks overlap, DORA's more specific and stringent requirements take precedence for in-scope financial entities.


If your organisation has already built NIS2 compliance processes around incident reporting, risk management, and supply chain oversight, you have a meaningful head start. However, DORA introduces requirements that go further, particularly around the Register of Information and Threat-Led Penetration Testing, which have no direct equivalent under NIS2. Equally, a strong ISO 27001 information security management system provides a solid foundation, since a large proportion of ISO 27001 controls map directly onto DORA's ICT risk management pillar.


Your DORA 2026 Compliance Checklist

  • Confirm your in-scope status: Determine whether your organisation, or your role as an ICT provider to financial entities, falls within DORA's regulatory perimeter.
  • Build and validate your Register of Information: Document every ICT third-party contractual arrangement at entity, sub-consolidated, and consolidated level, formatted correctly for xBRL-CSV submission.
  • Map your national submission window: Confirm your country's specific RoI deadline ahead of the March 31, 2026 ESA backstop date.
  • Run internal data quality checks: Validate LEI and entity identifiers, check for duplicate records, and confirm consistency across all contracts before submission.
  • Prepare for TLPT readiness: Even without a notification yet, establish threat intelligence capability, red-team processes, and senior management sign-off procedures.
  • Review your ICT risk management framework: Ensure it is documented, board-approved, and reviewed on an ongoing basis as DORA requires.
  • Strengthen incident reporting workflows: DORA requires major incidents to be reported within hours, not days, so test your detection and escalation timelines.
  • Reassess critical ICT third-party dependencies: Identify any reliance on designated Critical ICT Third-Party Providers and document concentration risk.
  • Align with existing ISO 27001 or NIS2 programmes: Avoid duplicating effort by mapping shared controls across frameworks.

How Vista Infosec Can Help

DORA compliance is technically demanding and time-sensitive, but it does not have to be navigated alone. Vista Infosec is a CREST-accredited global cybersecurity and compliance consulting firm with over 20 years of experience helping financial entities and ICT providers across the US, UK, Singapore, India, and the Middle East meet rigorous regulatory standards.


Our team can help you:

  • Conduct a DORA gap assessment and build or validate your Register of Information ahead of national deadlines.
  • Design and execute penetration testing aligned withTLPT methodology and audit expectations.
  • Strengthen your ICT risk management framework and incident reporting processes.
  • Map DORA requirements against your existing ISO 27001, SOC 2, or NIS2 controls to streamline compliance and reduce audit fatigue.

 

Do not wait for a TLPT notification to discover gaps in your resilience. Get assessed now and walk into your next regulatory audit with confidence.

 

Book a free 30-minuteconsultation with Vista Infosec today.

DORA TLPT Explained: Threat-Led Penetration Testing Deadline Is 2028, But Procurement Must Start in 2026

17 January 2028 sounds a long way off. For any EU financial entity designated for DORA TLPT (Threat-Led Penetration Testing), it isn't...