DORA Article 26 · TIBER-EU Framework

Threat-Led Penetration Testing
for EU Financial Entities

DORA Article 26 mandates Threat-Led Penetration Testing (TLPT) for significant financial entities operating in the EU. Requirements differ materially by entity type — select your sector below for a tailored compliance guide.

TLPT is intelligence-led, live-environment adversary simulation conducted by accredited external providers. It goes far beyond standard penetration testing — testing your real production systems against nation-state-level attack scenarios derived from current threat intelligence.

What Makes TLPT Different?

Intelligence-Led

Attack scenarios are derived from real threat intelligence specific to your sector and geography — not generic test scripts.

Live Production

Testing targets live systems without advance warning to the blue team, accurately measuring real-world detection and response capability.

Supervisory Reporting

Results must be formally reported to your national competent authority with documented remediation commitments.