DORA
Penetration testing vs TLPT under DORA: the differences, who they apply to and how to prepare
Penetration testing vs TLPT under DORA: tests under Arts. 24-25 vs TLPT under Arts. 26-27, who must run TLPT, how the test works and how to prepare.
Insights
DORA has applied since 17 January 2025. Our articles explain its testing requirements - from the digital operational resilience testing programme to TLPT - based on the text of the regulation, the regulatory technical standards and communications from the Polish Financial Supervision Authority (KNF).
01About this category
The Digital Operational Resilience Act (DORA) requires financial entities to manage ICT risk, report major ICT-related incidents, test their digital operational resilience regularly and oversee their ICT third-party service providers. These requirements pass down the supply chain to software houses, cloud providers and companies that maintain systems, whose contracts must include the provisions set out in Article 30 of the regulation.
Our article on penetration testing vs TLPT explains the two levels of testing under DORA: the digital operational resilience testing programme under Arts. 24-25, which almost every financial entity has to run, and threat-led penetration testing (TLPT) under Arts. 26-27, which is carried out only by entities designated by the supervisory authority - in Poland, the KNF. It also covers how TLPT works, how to prepare for it before the authority's decision arrives and how to read proposals from TLPT providers.
We write for risk, security and IT teams at financial institutions, and for suppliers who want to know what their financial-sector clients will expect of them.
We take our facts from the text of the regulation, the regulatory technical standards and KNF communications, always with the date of the legal status. Our articles are for information only and are no substitute for legal advice.
How we help financial institutions: DORA compliance, TLPT preparation and ICT risk assessment.
DORA
Penetration testing vs TLPT under DORA: tests under Arts. 24-25 vs TLPT under Arts. 26-27, who must run TLPT, how the test works and how to prepare.
Compliance · DORA
DORA compliance: who Regulation (EU) 2022/2554 applies to, the key requirements, testing under Arts. 24-25 and TLPT, ICT risk and rules for ICT providers.
DORA · TLPT
Threat-led penetration testing (TLPT) under DORA: Arts. 26-27, RTS 2025/1190, who must test and how often, the red team process and tester requirements.
DORA · ICT risk
DORA ICT risk management framework assessment against Arts. 5-16 and RTS 2024/1774: scope, the simplified framework, method, compliance matrix and action plan.
Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.
or call +48 575 621 877