DEV Community

Cover image for DORA TLPT Explained: Threat-Led Penetration Testing Deadline Is 2028, But Procurement Must Start in 2026
Narendrasahoo
Narendrasahoo

Posted on

DORA TLPT Explained: Threat-Led Penetration Testing Deadline Is 2028, But Procurement Must Start in 2026

17 January 2028 sounds a long way off. For any EU financial entity designated for DORA TLPT (Threat-Led Penetration Testing), it isn't. Once you account for provider scarcity, regulatory scoping, and a testing cycle that runs 9 to 14 months on its own, the real deadline that matters is 2026 because that is when procurement has to begin.

If your bank, insurer, investment firm, or payment institution has received a designation notice from your National Competent Authority (NCA), this article breaks down exactly what Threat-Led Penetration Testing under DORA Article 26 requires, why the timeline is tighter than it looks, and what to do about it right now.

What Is DORA TLPT, Exactly?

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has been in force across the EU since 17 January 2025. Among its five pillars ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing Article 26 and Article 27 introduce the most demanding obligation of all: Threat-Led Penetration Testing, modelled directly on the European Central Bank's TIBER-EU framework.

Unlike a standard vulnerability scan or annual penetration test, TLPT is an intelligence-led, covert red team exercise run against your live production environment. Your own security operations team is not told it is happening. A licensed threat intelligence provider first builds a Targeted Threat Intelligence (TTI) report profiling the real adversaries most likely to target your institution nation-state actors, organised financial cybercrime groups, or insider-threat scenarios. An accredited red team then executes those exact attack scenarios against your critical or important functions, including outsourced and cloud infrastructure, for a minimum of 12 weeks.

Aspect Traditional Penetration Test DORA TLPT / TIBER-EU
Driven by Standard checklist Real, targeted threat intelligence
Awareness Blue team informed Blue team unaware ("blind" test)
Environment Test/staging systems Live production systems
Duration 1–4 weeks 9–14 months end to end
Provider Any qualified tester TIBER-EU accredited providers only
Outcome Vulnerability list Formal supervisory attestation

TLPT is not optional and it is not self-selected. Your NCA designates you based on systemic importance, asset size, and criticality to the financial system. Once designated, the obligation repeats at least every three years, and no generic penetration test can substitute for it.

The 2028 Deadline — And Why It's Already Close

The first mandatory TLPT cycle under DORA must be completed by 17 January 2028. On paper, that is more than a year away from today. In practice, a full engagement — provider procurement, scope agreement with your competent authority, the threat intelligence phase, the red team campaign, purple teaming, remediation, and final attestation — typically takes between 9 and 14 months once everything is running smoothly.

The real bottleneck: provider capacity. There are only an estimated 30–40 TIBER-EU accredited red team and threat intelligence providers across the entire EU, and well over 8,000 financial entities may fall within TLPT scope. With hundreds of institutions needing a slot in the same 2026–2027 window, qualified providers are already booking capacity 12 to 18 months in advance.

Typical DORA TLPT Timeline

Milestone Recommended Timing
Designation notification from your NCA Ongoing — check supervisory correspondence
Begin threat intelligence & red team provider procurement 12–18 months before target test date (i.e., 2026)
Scope agreement with competent authority 8–10 months before the test
Threat intelligence phase 6–10 weeks
Red team execution 8–12 weeks (minimum 12 under TIBER-EU)
Purple teaming & closure 3–10 weeks
Final report & supervisory attestation 4–8 weeks
First mandatory deadline 17 January 2028

Work backwards from January 2028 and the math is unforgiving: procurement should realistically start in 2026, not 2027. Entities that wait until designation pressure builds risk being left with whatever accredited provider capacity remains often at a premium, and often without the specialist industry experience their scope actually needs.

What Happens If You Miss the Deadline?

Missing the 2028 deadline, running a poorly scoped test, or failing to remediate critical findings on the agreed timeline all expose an institution to enforcement action under DORA Article 50, including financial penalties tied to global annual turnover and operational restrictions imposed by supervisors. For designated entities, TLPT sits alongside the broader resilience testing programme required under Article 25 — but it carries a legal weight and reputational visibility that an annual vulnerability scan does not.

How to Prepare Now

  • Confirm designation status with your NCA and don't assume you're out of scope simply because you haven't been formally notified yet.
  • Start provider procurement in 2026 — evaluate TIBER-EU accredited threat intelligence and red team providers before capacity dries up.
  • Map critical and important functions, including third-party and cloud dependencies, ahead of scoping discussions.
  • Run standing red team and continuous penetration testing programmes so TLPT becomes a checkpoint rather than a scramble.
  • Align TLPT with your wider DORA programme — ICT risk management, incident reporting, and third-party risk registers all feed into a credible scope document.

This is exactly where experienced penetration testing services earn their keep well before the formal TLPT clock starts. A mature, continuous testing programme built on CREST-approved methodology gives your institution a defensible baseline while you queue for accredited TLPT capacity. VistaInfoSec's broader guidance on common DORA compliance challenges is a useful starting point if you're still building out your resilience testing roadmap.

It's also worth understanding how TLPT fits alongside your other frameworks. If your institution already holds ISO 27001 or SOC 2, this DORA, ISO 27001 and SOC 2 mapping guide shows exactly where DORA's testing requirements go beyond what those certifications already cover. And if NIS2 obligations apply to any part of your group alongside DORA, this NIS2 vs DORA compliance guide untangles where the two regulations overlap and where they diverge.

The Bottom Line

DORA TLPT isn't a 2028 problem — it's a 2026 decision. The financial entities that treat threat-led penetration testing as a checkpoint within an already-mature security testing programme will move through designation, scoping, and attestation calmly. Those that wait will be negotiating with whatever accredited provider has a slot left, on someone else's timeline. For EU financial institutions serious about operational resilience, the smartest move this year is simple: start the conversation with accredited providers now, not in Q4 2027.

Top comments (0)