Feature Regulatory Compliance
DORA Article 26 TLPT: Who Gets Designated for Threat-Led Penetration Testing in 2026 and How to Prepare Before Your NCA Calls
DORA's advanced testing obligation under Article 26 is different from the ICT third-party risk requirements you've been building for. 2026 is the year national competent authorities begin issuing TLPT designations. Here's who is in scope, what a TLPT engagement actually covers, and what to have ready before you receive the call.
Table of Contents
TL;DR:
- DORA Article 26 TLPT is a separate, more demanding obligation than the Article 25 standard testing program — reserved for systemically important entities designated by their national competent authority.
- G-SIIs are automatically in scope; NCAs are issuing additional designations in 2026 as DORA enters active supervisory phase.
- TLPT targets live production systems (not test environments), uses real threat intelligence, and must cover critical or important functions including outsourced ones — meaning your cloud vendors and critical third parties can be in scope.
- A TIBER-EU test that meets the RTS scope and methodology standards can satisfy the DORA TLPT obligation.
- Preparation matters before designation: the entities that fare best are those who treated TIBER-EU or DORA TLPT preparedness as a capability to build, not a reactive compliance task.
For most of 2025, the DORA conversation was about the Register of Information, the 19 Critical ICT Third-Party Providers, and getting Article 30 contract clauses in place before supervisory reviews started. That work isn’t done — NCAs are actively cross-referencing Register submissions and finding gaps.
But there’s a parallel obligation that has received significantly less attention: the advanced testing requirement under Article 26. That’s starting to change. 2026 is when national competent authorities are moving from awareness to active designation. If your institution is systemically important enough to be on the TLPT list, you may not know it yet.
TLPT vs. Standard ICT Testing: Why Article 26 Is Different
DORA’s ICT testing framework has two tiers.
Article 25 — Standard testing: All financial entities must maintain an ICT testing program proportionate to their size and risk profile. This includes vulnerability assessments, penetration tests, and scenario-based exercises. Most financial entities operate here. The standard penetration test you do annually is an Article 25 requirement.
Article 26 — Advanced testing (TLPT): Designated entities must conduct Threat-Led Penetration Testing (TLPT) — a materially different type of engagement:
| Dimension | Standard Pentest (Article 25) | TLPT (Article 26) |
|---|---|---|
| Target environment | Can use test/staging environments | Must be conducted on live production systems |
| Threat model | Generic vulnerability scanning | Based on current threat intelligence about real adversaries |
| Scope | Defined by institution | Must cover critical or important functions including outsourced ones |
| Testers | Internal or external | Must involve independent external testers; internal testers allowed in hybrid arrangements |
| Frequency | Annual (best practice) | At least every 3 years |
| NCA involvement | None required | NCA notified; NCA may observe or coordinate |
| Third-party scope | Optional | Outsourced critical/important functions can be in scope; pooled testing available |
The production systems requirement is what makes TLPT operationally distinct. You can’t run a simulated red-team exercise on a staging environment and satisfy Article 26. The test is meant to assess how your actual operating environment would respond to a real, targeted threat actor using real attack techniques.
Who Is Designated for TLPT
Automatic designation: G-SIIs
Financial entities classified as globally systemically important institutions (G-SIIs) under CRR/CRD (or updated CRR III/CRD VI) are automatically subject to TLPT under Article 26. If your institution carries a G-SII buffer, TLPT is not discretionary.
NCA discretionary designation
Beyond G-SIIs, each national competent authority may designate additional financial entities for TLPT based on the criteria in the joint ESA Regulatory Technical Standard (JC 2024-29). The designation criteria include:
- Size and systemic importance: Total assets, market share in key financial services, interconnectedness with other financial entities
- Risk profile: ICT complexity, concentration in critical third-party providers, cross-border activity
- Business model: Nature of services, reliance on digital channels, exposure to cyber threats based on NCA threat intelligence
- Prior incidents: History of significant ICT-related incidents or near-misses
NCAs have discretion in how they apply these criteria. An institution that sits just below G-SII thresholds but operates highly complex ICT infrastructure or has experienced significant incidents may still receive a designation notice.
The 2026 designation cycle
DORA entered full enforcement phase in January 2025. Through 2025, NCAs were focused on reviewing Register of Information submissions and assessing entity compliance with core obligations. 2026 marks the transition to active advanced testing supervision: NCAs are now issuing TLPT designation notices and coordinating first-cycle timelines.
If you haven’t received a designation notice yet, that doesn’t mean you’re clear. NCAs are working through designation processes systematically, and notices are going out at different times across member states. An institution that is borderline for designation should treat 2026 as the year to build TLPT readiness, not wait for formal notice to start.
What a TLPT Engagement Actually Involves
A TLPT engagement under the DORA RTS has three phases that distinguish it from a conventional red-team exercise:
Phase 1: Threat Intelligence
Before any testing begins, a threat intelligence provider produces a Threat Intelligence Report. This report analyzes your institution’s specific threat landscape — the threat actors most likely to target you, based on sector, geography, business model, and public information. It identifies high-probability attack vectors, relevant TTPs (tactics, techniques, and procedures), and what a sophisticated adversary would realistically attempt.
This is not generic threat intelligence from a vendor feed. The Threat Intelligence Report is produced specifically for your institution and drives the red team’s attack scenarios.
Phase 2: Red Team Testing
Red team testers execute targeted attack scenarios against your live production environment. The test is adversarial — the red team does not share their attack paths with your defensive team (blue team) in advance. The goal is to assess how your actual environment responds to real attack techniques, not how it performs under known test conditions.
Scope must include critical or important functions. When those functions rely on outsourced third-party providers — a cloud infrastructure provider, a core banking platform, a settlement system — the TLPT may need to extend into those providers’ environments. Article 27 allows multiple financial entities using the same provider to pool their TLPT exercises, which both reduces burden and produces more realistic cross-entity testing.
Phase 3: Results and Remediation
After testing, the red team and blue team conduct a “purple team” review — joint analysis of the attack scenarios, what was detected, what was missed, and what the detection and response gaps reveal. The output is a TLPT Summary Report submitted to the NCA, which includes findings, remediation commitments, and timelines.
The NCA may observe TLPT exercises directly or review summary reports. For entities that have completed a TIBER-EU test meeting the RTS standards, that test satisfies the DORA TLPT obligation if the scope and methodology are consistent.
The Outsourced Functions Problem
The requirement to include outsourced critical and important functions in TLPT scope is where institutional preparation most often falls short.
Your cloud provider’s environment may be in scope for your TLPT. Major cloud providers — including those designated as Critical ICT Third-Party Providers under DORA Article 31 — have TLPT participation frameworks, but coordinating access requires contractual provisions and advance planning. If your existing cloud contracts don’t include DORA TLPT cooperation obligations, you need to address that now.
This is directly connected to DORA Article 28 compliance: Article 30 contract requirements include provisions for competent authority access and cooperation — which extends to TLPT coordination. Entities that have updated their Article 30 clauses are in better shape to execute TLPT scope discussions with third parties. Those that haven’t completed the contract remediation work face a compound problem when designation arrives.
What US-Owned EU Entities Need to Know
US banks with EU branches and subsidiaries cannot treat Article 26 TLPT as a European local issue. Several implications flow back to the US parent:
ICT systems shared from the US are in scope. If your EU branch uses shared IT infrastructure hosted or managed from the US — which is common — those systems support critical or important EU functions and can be in TLPT scope. The TLPT tester will assess how an adversary who reaches the EU environment can leverage shared infrastructure.
The US parent may need to participate in scoping. Defining TLPT scope requires mapping which ICT systems support which functions. That mapping exercise may reveal that decisions about what’s in scope must involve US IT and risk teams, not just the EU entity.
Coordination with multiple NCAs. A US bank with branches in Germany and the Netherlands operates under different NCAs — Bundesbank/BaFin and DNB respectively, both of which have implemented TIBER-EU/DORA TLPT frameworks. If both branches receive TLPT designations, you may be running exercises under two different NCA coordination processes simultaneously.
Pre-Designation Preparation: What to Have in Place
Whether or not you’ve received a designation notice, these are the baseline capabilities to have before TLPT coordination begins:
1. Critical function mapping. You need a documented map of which ICT systems and third-party services support which critical or important functions. Without this, you cannot define TLPT scope, and the designation process will expose the gap.
2. Third-party TLPT participation provisions. Review your contracts with third-party ICT service providers that support critical or important functions. Do they include explicit provisions allowing your NCA to conduct or coordinate testing on their systems? Article 30 mandates this — if it’s not in your contracts, you need a remediation timeline.
3. TIBER-EU history review. If your institution has previously conducted TIBER-EU tests, review whether those tests covered the scope and met the methodology standards in the DORA TLPT RTS. A qualifying TIBER-EU test can satisfy your first DORA TLPT obligation, potentially deferring your next cycle by three years from the test date.
4. Internal tester documentation. If you intend to use internal testers as part of a hybrid arrangement, the RTS requires documented criteria for internal tester qualification, independence safeguards, and approval from the NCA. Establish this documentation before you need it.
5. Blue team baseline. TLPT reveals gaps in your detection and response capabilities. Before your first TLPT, know what your current detection coverage looks like — what you log, what you alert on, what your SOC response times are. A TLPT without a documented pre-test baseline produces findings you can’t contextualize.
So What? What to Do Before Your NCA Calls
The entities that manage DORA Article 26 TLPT most smoothly share one characteristic: they treated it as a capability to build rather than a compliance task to complete on receiving formal notice.
If you are a significant EU financial entity that hasn’t received a designation notice yet, use 2026 to do three things:
Assess designation likelihood. Apply the RTS criteria to your own profile: total assets, ICT complexity, third-party concentration, cross-border activity, incident history. Calibrate your exposure honestly. If you’re close to the threshold in multiple dimensions, treat designation as likely.
Close the Article 30 gap that blocks TLPT scope. The contracts that don’t have DORA Article 30-compliant audit rights and cooperation clauses will be the contracts that create scope negotiation problems when TLPT arrives. Prioritizing those remediations now serves both Article 28 compliance and TLPT readiness.
Use TPRM infrastructure to prepare the critical function map. Your third-party risk management program should already be tracking which vendors support which critical or important functions. If that mapping isn’t documented to the standard the TLPT scoping process will require, that’s the foundational gap to fix.
Managing the vendor oversight, contract remediation, and Register of Information requirements that underpin DORA TLPT readiness? The Third-Party Risk Management Kit includes vendor criticality classification templates, contract clause checklists, and the critical function mapping framework that both Article 28 and Article 26 TLPT preparation depend on.
Related Reading
- DORA Article 28 in 2026: What US Financial Institutions with EU Operations Are Still Getting Wrong
- DORA Third-Party ICT Risk: Contracts, Concentration Risk, and the 19 Critical Providers You Now Answer To
- Vendor Due Diligence Techniques: What to Verify When the Questionnaire Comes Back
Sources:
- DORA Article 26 — Advanced Testing of ICT Tools, Systems and Processes Based on TLPT
- JC 2024-29 — Final Report: DORA RTS on Threat-Led Penetration Testing (ESA Joint Committee)
- DORA TLPT: Threat-Led Penetration Testing Requirements 2026
- Implementing DORA in 2026: Leveraging Threat-Led Penetration Testing for Financial Institutions (Filigran Blog)
- DORA Delegated Regulation on TLPT Published in Official Journal (Katten)
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does DORA Article 26 TLPT apply to all EU financial entities?
What's the difference between standard penetration testing (Article 25) and TLPT (Article 26)?
How does TIBER-EU relate to DORA TLPT?
Does TLPT need to cover outsourced ICT service providers and cloud vendors?
How often must designated entities conduct TLPT under DORA?
What happens when a US parent bank's EU branch or subsidiary is designated for TLPT?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Regulatory Compliance
Effective Challenge in Model Risk Management: Document the Disagreement
Model risk management effective challenge needs a decision trail. Build a challenge memo that preserves evidence, responses, conditions, and escalation.
Jul 24, 2026
Regulatory Compliance
FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now
FinCEN's student aid fraud alert gives banks nine red flags, a SAR keyword, and a clear transaction-monitoring task for ACH refunds.
Jul 23, 2026
Regulatory Compliance
Magnolia Diagnostics False Claims Act Settlement: Why Investors Paid Part of the $24 Million
The Magnolia Diagnostics False Claims Act settlement reached investors, requisition controls, and $24M in payments. Here is what to fix.
Jul 23, 2026