DFIR Tech Blog – an AI playground

Deutsch English
Foto von Jinsoo Choi auf Unsplash.com

TLPT Under DORA: When Purple Teaming Becomes a Legal Duty

19.09.2026 doratlptpurple-teamingtiber-eu

Threat-Led Penetration Testing (TLPT) used to be a line item in the DORA text that most European banks quietly pushed to 2027 or beyond. That’s no longer possible. On 17 January 2025, DORA stopped being a future concern and became reality, and with the European Central Bank’s TIBER-EU SSM Implementation Guide published in November 2025, significant institutions no longer have room to “wait and see” on threat-led penetration testing. This isn’t a recommendation — it’s a binding implementation mandate for a test format that hits IR and SOC teams directly, because TLPT doesn’t probe vulnerabilities, it probes detection and response under real pressure.

What Sets TLPT Apart From a Standard Pentest

The guide spells it out clearly: under Articles 26 and 27 DORA, identified financial entities must carry out advanced operational resilience testing by means of Threat-Led Penetration Testing at least every three years. The critical difference from conventional pentesting lies in orientation: TLPT is driven by real threat intelligence specific to the institution and its most likely adversaries, and tests are conducted on live production systems rather than isolated environments, making findings operationally real. The test isn’t whether a vulnerability exists — it’s whether the SOC actually notices a realistic, covert attack, correctly triages it, and contains it effectively.

TLPT is an intelligence-driven simulation of real-world cyberattacks conducted in secrecy, with the organization’s defense team unaware that a test is taking place. That covertness is the real maturity test: a SOC that only performs well during announced exercises hasn’t demonstrated resilient detection capability in practice. The framework has also been tightened methodologically: on 11 February 2025 the TIBER-EU framework was updated to align with DORA’s RTS for TLPT, with the latest changes including mandatory purple teaming and terminology updates. A once-optional debrief has become a fixed, mandated element of the test cycle — red and blue teams must jointly work through findings, not just hand a report to management.

Who’s Affected — and What It Means for IR Practice

The target population is deliberately narrow: only entities identified as “significant” by their supervisor are subject to the mandatory TLPT every three years — roughly 120 significant banks under ECB supervision (SSM); for others, TLPT remains highly recommended as best practice, but not legally mandatory. For those in scope, the effort is substantial: it’s an intelligence-led red team exercise run against live production systems supporting critical functions, following TIBER-EU methodology, where a single test runs roughly three to six months across preparation, threat intelligence, and active red teaming lasting about 10 to 12 weeks.

For IR leaders, three practical consequences follow. First, the formal attestation requirement shifts focus from the playbook on paper to demonstrated operational effectiveness under supervisory scrutiny. TLPT is the “advanced level” test of an organisation’s cyber resilience — DORA essentially forces critical financial entities to prove their cyber resilience in a real-world scenario, not just on paper. Second, the vendor landscape shifts: DORA allows internal TLPT but requires independent threat intelligence, mandates outsourcing every third test, and forces external testers for significant institutions. Third — and this is the real maturity payoff — TLPT is becoming the cadence-setter for continuous exercise practice rather than point-in-time compliance: the readiness move is continuous adversary emulation between mandated cycles, with firms running standing red team and PTaaS programs treating the formal TLPT as a checkpoint, not a scramble.

For European SOC and IR teams, the takeaway is blunt: whoever still treats tabletop exercises as an annual formality will, within three years, be measured against a covert, months-long live attack — with a regulator watching.

← Back to overview