Regmindr
Compliance deadlines

DORA threat-led penetration testing (TLPT)

DORA · Every 3 years · At least every 3 years

Under DORA Art. 26, financial entities that their competent authority has identified must carry out threat-led penetration testing (TLPT) at least every 3 years. The authority can ask a firm to test more or less often, based on its risk profile.

Who has to do it

Only firms their competent authority identifies, based on their impact on the financial sector, financial stability concerns, and their ICT risk profile and maturity (Art. 26(8)). Microenterprises and firms under the simplified ICT risk management framework (Art. 16) are out of scope.

What a test covers

Several or all of your critical or important functions, tested on the live production systems that support them, including services outsourced to ICT third-party providers. You assess which functions to cover, and your authority validates the scope (Art. 26(2)). The approach follows the TIBER-EU framework.

Testers

Testers must meet the requirements in Art. 27. If you use internal testers, every third test must use external testers. Significant credit institutions must always use external testers (Art. 26(8)).

After the test

Once reports and remediation plans are agreed, you give your authority a summary of the findings, the remediation plans and documentation showing the test met the requirements. The authority then issues an attestation (Art. 26(6) and (7)).

Get reminded before it's due

Regmindr tracks this alongside the rest of your compliance calendar, and emails your team before each deadline.

Sources

This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.

Related