
TLPT vs penetration testing: what changes under DORA?
Why a conventional penetration test does not automatically meet the requirements of a DORA threat-led exercise.
Read the perspective
THREAT-LED PENETRATION TESTING
Threat-led penetration testing for financial organisations with DORA obligations. We bring together targeted threat intelligence, controlled red teaming and remediation planning in one complete engagement.
Your critical functions depend on people, processes and technology. A meaningful test examines them together.
Atlant Security offers one integrated DORA TLPT engagement: targeted threat intelligence, controlled red-team testing, closure and remediation planning.
We connect realistic adversary scenarios to the services your organisation needs to keep running, with governance and operational safeguards established from the start.
Inside the engagement
An integrated process.
Accountability at every stage.
Map critical functions, dependencies and boundaries. Establish governance and authority coordination.
Use targeted intelligence to identify relevant adversaries and develop credible scenarios.
Execute red-team activity with agreed safeguards, control-team oversight and clear escalation.
Reconstruct the attack with defenders. Review detection, response and purple-team findings.
Prioritise remediation, assign ownership and prepare the evidence for the closure process.
Not every organisation subject to DORA is required to conduct TLPT.
Competent authorities identify the financial entities that must perform advanced testing. Confirm your designation and the applicable authority process before defining the engagement.
Understand who needs TLPTDORA articles covering advanced testing and the requirements for testers.
At least once every three years for identified entities, subject to authority adjustment.
The minimum active red-team phase under RTS Article 11(5), with other phases adding time.
PRIMARY SOURCES DORA Articles 26–27 TLPT RTS (EU) 2025/1190
THE VALUE OF THE ENGAGEMENT
The outcome should be useful to your security teams, decision-makers and the authority overseeing the engagement.
Explore the deliverablesConnect scenarios, actions and evidence to observed control outcomes.
Bring attack and defence observations together through replay and purple-team learning.
Set clear actions, accountable owners and a basis for follow-through.
04 / INSIGHTS & PERSPECTIVES

Why a conventional penetration test does not automatically meet the requirements of a DORA threat-led exercise.
Read the perspective
Start with the function, trace the dependencies and make the boundary of the test explicit.
Read the perspective
Understand the 12-week active-testing minimum and the preparation and closure work that sit around it.
Read the perspectiveA PRACTICAL STARTING POINT
Bring scope, governance and procurement into one working checklist.

LET’S START A CONVERSATION
Your critical functions. Your authority’s requirements. A clear starting point for your TLPT engagement.
Discuss your TLPT