Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Regulatory Compliance

DORA Article 26 TLPT: Who Gets Designated for Threat-Led Penetration Testing in 2026 and How to Prepare Before Your NCA Calls

DORA's advanced testing obligation under Article 26 is different from the ICT third-party risk requirements you've been building for. 2026 is the year national competent authorities begin issuing TLPT designations. Here's who is in scope, what a TLPT engagement actually covers, and what to have ready before you receive the call.

By Rebecca Leung · June 16, 2026 ·
Table of Contents

TL;DR:

  • DORA Article 26 TLPT is a separate, more demanding obligation than the Article 25 standard testing program — reserved for systemically important entities designated by their national competent authority.
  • G-SIIs are automatically in scope; NCAs are issuing additional designations in 2026 as DORA enters active supervisory phase.
  • TLPT targets live production systems (not test environments), uses real threat intelligence, and must cover critical or important functions including outsourced ones — meaning your cloud vendors and critical third parties can be in scope.
  • A TIBER-EU test that meets the RTS scope and methodology standards can satisfy the DORA TLPT obligation.
  • Preparation matters before designation: the entities that fare best are those who treated TIBER-EU or DORA TLPT preparedness as a capability to build, not a reactive compliance task.

For most of 2025, the DORA conversation was about the Register of Information, the 19 Critical ICT Third-Party Providers, and getting Article 30 contract clauses in place before supervisory reviews started. That work isn’t done — NCAs are actively cross-referencing Register submissions and finding gaps.

But there’s a parallel obligation that has received significantly less attention: the advanced testing requirement under Article 26. That’s starting to change. 2026 is when national competent authorities are moving from awareness to active designation. If your institution is systemically important enough to be on the TLPT list, you may not know it yet.

TLPT vs. Standard ICT Testing: Why Article 26 Is Different

DORA’s ICT testing framework has two tiers.

Article 25 — Standard testing: All financial entities must maintain an ICT testing program proportionate to their size and risk profile. This includes vulnerability assessments, penetration tests, and scenario-based exercises. Most financial entities operate here. The standard penetration test you do annually is an Article 25 requirement.

Article 26 — Advanced testing (TLPT): Designated entities must conduct Threat-Led Penetration Testing (TLPT) — a materially different type of engagement:

DimensionStandard Pentest (Article 25)TLPT (Article 26)
Target environmentCan use test/staging environmentsMust be conducted on live production systems
Threat modelGeneric vulnerability scanningBased on current threat intelligence about real adversaries
ScopeDefined by institutionMust cover critical or important functions including outsourced ones
TestersInternal or externalMust involve independent external testers; internal testers allowed in hybrid arrangements
FrequencyAnnual (best practice)At least every 3 years
NCA involvementNone requiredNCA notified; NCA may observe or coordinate
Third-party scopeOptionalOutsourced critical/important functions can be in scope; pooled testing available

The production systems requirement is what makes TLPT operationally distinct. You can’t run a simulated red-team exercise on a staging environment and satisfy Article 26. The test is meant to assess how your actual operating environment would respond to a real, targeted threat actor using real attack techniques.

Who Is Designated for TLPT

Automatic designation: G-SIIs

Financial entities classified as globally systemically important institutions (G-SIIs) under CRR/CRD (or updated CRR III/CRD VI) are automatically subject to TLPT under Article 26. If your institution carries a G-SII buffer, TLPT is not discretionary.

NCA discretionary designation

Beyond G-SIIs, each national competent authority may designate additional financial entities for TLPT based on the criteria in the joint ESA Regulatory Technical Standard (JC 2024-29). The designation criteria include:

  • Size and systemic importance: Total assets, market share in key financial services, interconnectedness with other financial entities
  • Risk profile: ICT complexity, concentration in critical third-party providers, cross-border activity
  • Business model: Nature of services, reliance on digital channels, exposure to cyber threats based on NCA threat intelligence
  • Prior incidents: History of significant ICT-related incidents or near-misses

NCAs have discretion in how they apply these criteria. An institution that sits just below G-SII thresholds but operates highly complex ICT infrastructure or has experienced significant incidents may still receive a designation notice.

The 2026 designation cycle

DORA entered full enforcement phase in January 2025. Through 2025, NCAs were focused on reviewing Register of Information submissions and assessing entity compliance with core obligations. 2026 marks the transition to active advanced testing supervision: NCAs are now issuing TLPT designation notices and coordinating first-cycle timelines.

If you haven’t received a designation notice yet, that doesn’t mean you’re clear. NCAs are working through designation processes systematically, and notices are going out at different times across member states. An institution that is borderline for designation should treat 2026 as the year to build TLPT readiness, not wait for formal notice to start.

What a TLPT Engagement Actually Involves

A TLPT engagement under the DORA RTS has three phases that distinguish it from a conventional red-team exercise:

Phase 1: Threat Intelligence

Before any testing begins, a threat intelligence provider produces a Threat Intelligence Report. This report analyzes your institution’s specific threat landscape — the threat actors most likely to target you, based on sector, geography, business model, and public information. It identifies high-probability attack vectors, relevant TTPs (tactics, techniques, and procedures), and what a sophisticated adversary would realistically attempt.

This is not generic threat intelligence from a vendor feed. The Threat Intelligence Report is produced specifically for your institution and drives the red team’s attack scenarios.

Phase 2: Red Team Testing

Red team testers execute targeted attack scenarios against your live production environment. The test is adversarial — the red team does not share their attack paths with your defensive team (blue team) in advance. The goal is to assess how your actual environment responds to real attack techniques, not how it performs under known test conditions.

Scope must include critical or important functions. When those functions rely on outsourced third-party providers — a cloud infrastructure provider, a core banking platform, a settlement system — the TLPT may need to extend into those providers’ environments. Article 27 allows multiple financial entities using the same provider to pool their TLPT exercises, which both reduces burden and produces more realistic cross-entity testing.

Phase 3: Results and Remediation

After testing, the red team and blue team conduct a “purple team” review — joint analysis of the attack scenarios, what was detected, what was missed, and what the detection and response gaps reveal. The output is a TLPT Summary Report submitted to the NCA, which includes findings, remediation commitments, and timelines.

The NCA may observe TLPT exercises directly or review summary reports. For entities that have completed a TIBER-EU test meeting the RTS standards, that test satisfies the DORA TLPT obligation if the scope and methodology are consistent.

The Outsourced Functions Problem

The requirement to include outsourced critical and important functions in TLPT scope is where institutional preparation most often falls short.

Your cloud provider’s environment may be in scope for your TLPT. Major cloud providers — including those designated as Critical ICT Third-Party Providers under DORA Article 31 — have TLPT participation frameworks, but coordinating access requires contractual provisions and advance planning. If your existing cloud contracts don’t include DORA TLPT cooperation obligations, you need to address that now.

This is directly connected to DORA Article 28 compliance: Article 30 contract requirements include provisions for competent authority access and cooperation — which extends to TLPT coordination. Entities that have updated their Article 30 clauses are in better shape to execute TLPT scope discussions with third parties. Those that haven’t completed the contract remediation work face a compound problem when designation arrives.

What US-Owned EU Entities Need to Know

US banks with EU branches and subsidiaries cannot treat Article 26 TLPT as a European local issue. Several implications flow back to the US parent:

ICT systems shared from the US are in scope. If your EU branch uses shared IT infrastructure hosted or managed from the US — which is common — those systems support critical or important EU functions and can be in TLPT scope. The TLPT tester will assess how an adversary who reaches the EU environment can leverage shared infrastructure.

The US parent may need to participate in scoping. Defining TLPT scope requires mapping which ICT systems support which functions. That mapping exercise may reveal that decisions about what’s in scope must involve US IT and risk teams, not just the EU entity.

Coordination with multiple NCAs. A US bank with branches in Germany and the Netherlands operates under different NCAs — Bundesbank/BaFin and DNB respectively, both of which have implemented TIBER-EU/DORA TLPT frameworks. If both branches receive TLPT designations, you may be running exercises under two different NCA coordination processes simultaneously.

Pre-Designation Preparation: What to Have in Place

Whether or not you’ve received a designation notice, these are the baseline capabilities to have before TLPT coordination begins:

1. Critical function mapping. You need a documented map of which ICT systems and third-party services support which critical or important functions. Without this, you cannot define TLPT scope, and the designation process will expose the gap.

2. Third-party TLPT participation provisions. Review your contracts with third-party ICT service providers that support critical or important functions. Do they include explicit provisions allowing your NCA to conduct or coordinate testing on their systems? Article 30 mandates this — if it’s not in your contracts, you need a remediation timeline.

3. TIBER-EU history review. If your institution has previously conducted TIBER-EU tests, review whether those tests covered the scope and met the methodology standards in the DORA TLPT RTS. A qualifying TIBER-EU test can satisfy your first DORA TLPT obligation, potentially deferring your next cycle by three years from the test date.

4. Internal tester documentation. If you intend to use internal testers as part of a hybrid arrangement, the RTS requires documented criteria for internal tester qualification, independence safeguards, and approval from the NCA. Establish this documentation before you need it.

5. Blue team baseline. TLPT reveals gaps in your detection and response capabilities. Before your first TLPT, know what your current detection coverage looks like — what you log, what you alert on, what your SOC response times are. A TLPT without a documented pre-test baseline produces findings you can’t contextualize.

So What? What to Do Before Your NCA Calls

The entities that manage DORA Article 26 TLPT most smoothly share one characteristic: they treated it as a capability to build rather than a compliance task to complete on receiving formal notice.

If you are a significant EU financial entity that hasn’t received a designation notice yet, use 2026 to do three things:

Assess designation likelihood. Apply the RTS criteria to your own profile: total assets, ICT complexity, third-party concentration, cross-border activity, incident history. Calibrate your exposure honestly. If you’re close to the threshold in multiple dimensions, treat designation as likely.

Close the Article 30 gap that blocks TLPT scope. The contracts that don’t have DORA Article 30-compliant audit rights and cooperation clauses will be the contracts that create scope negotiation problems when TLPT arrives. Prioritizing those remediations now serves both Article 28 compliance and TLPT readiness.

Use TPRM infrastructure to prepare the critical function map. Your third-party risk management program should already be tracking which vendors support which critical or important functions. If that mapping isn’t documented to the standard the TLPT scoping process will require, that’s the foundational gap to fix.


Managing the vendor oversight, contract remediation, and Register of Information requirements that underpin DORA TLPT readiness? The Third-Party Risk Management Kit includes vendor criticality classification templates, contract clause checklists, and the critical function mapping framework that both Article 28 and Article 26 TLPT preparation depend on.



Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does DORA Article 26 TLPT apply to all EU financial entities?
No. TLPT applies only to financial entities that are designated by their national competent authority (NCA) based on systemic importance, size, and risk profile. Globally systemically important institutions (G-SIIs) under CRR/CRD are automatically subject to TLPT. Beyond G-SIIs, NCAs may designate additional significant entities at their discretion using criteria in the joint ESA Regulatory Technical Standard. Most financial entities will be subject to standard penetration testing under Article 25 — TLPT under Article 26 is reserved for the most systemically important firms.
What's the difference between standard penetration testing (Article 25) and TLPT (Article 26)?
Article 25 requires all financial entities to maintain an ICT testing program that includes vulnerability assessments, penetration tests, and scenario-based exercises. Article 26 TLPT is a more advanced obligation for designated entities: it targets live production systems (not test environments), is based on current threat intelligence about real adversaries targeting the financial sector, must be conducted by independent external testers (or a combination of internal and external testers), and tests critical or important functions including those outsourced to third parties. A standard pentest checks for known vulnerabilities; TLPT simulates what a sophisticated, targeted threat actor would actually do.
How does TIBER-EU relate to DORA TLPT?
TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) is the ECB/central bank framework that predates DORA and established the methodology TLPT builds on. Countries including the Netherlands (DNB), Germany (Bundesbank/BaFin), France (ACPR/Banque de France), Luxembourg (BCL/CSSF), and ECB for SSM-supervised institutions had already implemented TIBER-EU before DORA. Under the DORA RTS on TLPT, a financial entity that has completed a TIBER-EU test covering the required scope and meeting the RTS standards can use that test to satisfy the DORA TLPT obligation. The DORA TLPT RTS was designed to be TIBER-EU-compatible specifically to avoid duplication.
Does TLPT need to cover outsourced ICT service providers and cloud vendors?
Yes. The scope of TLPT under Article 26 must include critical or important functions — and when those functions are supported by outsourced ICT third-party service providers, those providers' systems and infrastructure can be in scope. This is what makes TLPT significantly more operationally complex than internal penetration testing: you may need to coordinate with your cloud provider, a critical fintech, or a market infrastructure provider to test how an adversary would move through your full service delivery chain. Article 27 of DORA specifically addresses the pooled testing arrangements that allow multiple financial entities sharing the same third-party provider to conduct joint TLPT covering that provider.
How often must designated entities conduct TLPT under DORA?
Article 26 requires TLPT to be performed at least every three years. When internal testers are used as part of the TLPT team, external testers must be brought in at least every three test cycles (i.e., every nine years maximum). NCAs retain authority to request more frequent testing for entities that pose heightened risk. Between designated tests, the standard ICT testing program under Article 25 — penetration tests, vulnerability assessments, and tabletop exercises — continues to apply.
What happens when a US parent bank's EU branch or subsidiary is designated for TLPT?
EU branches and subsidiaries of US banks are subject to DORA as EU financial entities — the parent's location does not affect in-scope obligations. If an EU branch or subsidiary is designated for TLPT, the NCA will issue formal notice to the entity. For branches, the host NCA oversees compliance. For subsidiaries, the home NCA (and ECB for SSM-supervised entities) oversees it. The practical implication is that the US parent must participate in scoping decisions, because many ICT systems supporting EU operations are managed from or shared with the US parent — and those systems may be in TLPT scope if they support critical or important EU functions.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.