DORA threat-led penetration testing (TLPT)
DORA · Every 3 years · At least every 3 years
Under DORA Art. 26, financial entities that their competent authority has identified must carry out threat-led penetration testing (TLPT) at least every 3 years. The authority can ask a firm to test more or less often, based on its risk profile.
Who has to do it
Only firms their competent authority identifies, based on their impact on the financial sector, financial stability concerns, and their ICT risk profile and maturity (Art. 26(8)). Microenterprises and firms under the simplified ICT risk management framework (Art. 16) are out of scope.
What a test covers
Several or all of your critical or important functions, tested on the live production systems that support them, including services outsourced to ICT third-party providers. You assess which functions to cover, and your authority validates the scope (Art. 26(2)). The approach follows the TIBER-EU framework.
Testers
Testers must meet the requirements in Art. 27. If you use internal testers, every third test must use external testers. Significant credit institutions must always use external testers (Art. 26(8)).
After the test
Once reports and remediation plans are agreed, you give your authority a summary of the findings, the remediation plans and documentation showing the test met the requirements. The authority then issues an attestation (Art. 26(6) and (7)).
Get reminded before it's due
Regmindr tracks this alongside the rest of your compliance calendar, and emails your team before each deadline.
Sources
This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.