// REGULATION

DORA and TLPT: what the financial sector has to test

DORA brought the financial sector a new type of test: threat-led penetration testing (TLPT). It isn’t an ordinary pentest, and it doesn’t apply to every financial company. A company it does apply to has to get through it under precise rules and under the supervision of the Czech National Bank. Testing runs at least once every three years, and the scenario is built around a real threat, not around a generic brief.

Regulation

By Patrik Žák

// 01

What is DORA and who does it apply to?

The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) covers the digital operational resilience of the financial sector, and it has applied since January 17, 2025. Across the European Union it unifies the rules for managing IT risk, reporting incidents, and testing the resilience of financial entities.

It reaches a wide range of entities: banks, insurers, investment firms, providers of payment services and of services around crypto-assets, and others. The exact scope and its interpretation are maintained by the Czech National Bank (CNB) on its DORA pages (in Czech).

DORA is a different regulation from the NIS2 Directive (Directive (EU) 2022/2555) and from Act No. 264/2025 Coll., on Cybersecurity (the Czech Cybersecurity Act), even though the topics overlap. Who the Czech Cybersecurity Act reaches and to what extent is covered on a separate page. DORA, by contrast, aims at financial services alone and goes into testing in more detail.

// 02

What is threat-led penetration testing (TLPT)?

TLPT is a penetration test driven by a real threat: the scenario is built around the way an actual adversary would attack the institution in question, and the test measures whether the organization spots it and how fast it copes. So it isn’t about vulnerabilities alone, but about the detection and the response of the whole company.

The framework for such tests comes from TIBER-EU, the European Central Bank’s model for threat-led testing. Its Czech form is run by the CNB under the name TIBER-CZ. What separates TLPT from an ordinary pentest is that it runs covertly, with a narrow circle of insiders, and measures the defense, not the number of findings.

The scenario doesn’t rest on a general idea of an attacker but on threat intelligence about the threats relevant to that particular entity. That is why the test is called threat-led. The goal is to imitate as closely as possible what would actually hit the company.

// 03

How often, and which entities have to run TLPT?

Not every financial entity has to run TLPT. Under Article 26 of the Regulation, the supervisory authority, in the Czech Republic the CNB, designates which entities have to run it, and in practice these are mainly institutions systemically important for the financial market. Testing runs at least once every three years, and the authority may adjust the interval according to the risk profile.

The Regulation also sets requirements on who carries the test out. For significant credit institutions, only an external tester is allowed. Who may run TLPT is settled by Article 27 itself: it asks the vendor for accreditation in a member state or adherence to a formal code of ethics, independent assurance on the management of test risks, and professional indemnity insurance.

// 04

TLPT, an ordinary penetration test, and a red team side by side

TLPT stands closest in meaning to a red team, not to an ordinary pentest. An ordinary pentest has a defined scope, the defenders know about it, and the goal is to find as many vulnerabilities as possible. A red team and TLPT both run covertly and measure whether the defense notices the attack at all.

The difference between TLPT and a red team lies mostly in who oversees the test and under what rules. TLPT is a regulatory test under the supervision of the CNB, with formal requirements on the vendor. A scenario run as a real attack outside the regulation is an ordinary red team operation, that is, a covert operation that measures detection.

Where exactly the line between a red team and an ordinary pentest runs is something we wrote out in a comparison of the two services with a table. As a rough guide, TLPT is the most demanding and the most formalized of the three.

// 05

Who runs TLPT in the Czech Republic and who do you turn to?

In the Czech Republic, TLPT is overseen by the CNB, which joined the European TIBER-EU framework in September 2024 and runs the TIBER-CZ program under it for entities critical to the Czech financial system. Inside the CNB there is a team that enters the test through its test manager. That team can also invalidate a test, and such a test is then not recognized.

An entity that falls under TLPT verifies the conditions directly with the Czech National Bank (in Czech). With the vendor of the test, watch for exactly what Article 27 asks: accreditation or a code of ethics, independent assurance, and professional indemnity insurance. Without those, the test will not hold up for regulatory purposes.

// 06

Does DORA require penetration tests?

Yes, but not from everyone and not in the ordinary form. DORA introduces threat-led penetration testing, TLPT, as an advanced resilience test for the financial sector. The obligation doesn’t apply to all financial entities, only to those designated by the supervisory authority under Article 26 of the Regulation, in the Czech Republic the CNB.

// 07

What is TLPT and how does it differ from an ordinary penetration test?

TLPT is a penetration test driven by a real threat: the scenario is built around a specific adversary, and what gets measured is whether the organization spots it and how fast. An ordinary pentest has a defined scope, the defenders know about it, and the goal is to find the maximum number of vulnerabilities. TLPT runs covertly and tests the detection and the response of the whole company, not single vulnerabilities.

// 08

How often does TLPT have to be run?

At least once every three years, as Article 26 of DORA sets out. The supervisory authority, in the Czech Republic the CNB, may adjust the interval according to the institution’s risk profile and its operational circumstances. The frequency is therefore not the same for every entity, but three years is the statutory minimum for those that fall under TLPT.

// 09

Whom does DORA regulate?

DORA reaches financial entities across the European Union: banks, insurers, investment firms, providers of payment and crypto-asset services, and others. The TLPT obligation is narrower than the reach of DORA as a whole. It applies only to entities designated by the supervisory authority, in the Czech Republic mainly to systemically important institutions.

Updated .

// NEXT STEP

Want us to check the same thing in your environment?

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.