DORA · Article 26 · Checklist

DORA TLPT checklist: preparation, phase by phase.

For BaFin/Bundesbank-supervised and other in-scope financial entities facing a Threat-Led Penetration Test under DORA Article 26. This page gives concrete check items per phase, a realistic timeline, and the mistakes that set programmes back most often.

Are we even in scope?

Who is required to run a TLPT — and who decides.

Size & systemic importance

Significant credit institutions, large payment service providers, market infrastructures, larger insurers and systemically important ICT third-party providers are the typical candidates.

Critical or important functions

What matters is not the size of the IT estate but whether a function is classified as critical or important under DORA.

Out of scope

Small and micro undertakings and the categories explicitly excluded under DORA Art. 16 are not required to run a TLPT.

Important: the binding decision rests solely with the competent authority — in Germany BaFin/Bundesbank. It designates the firms required to run a TLPT using the criteria in the TLPT RTS. This page supports self-assessment but does not replace formal designation.

The checklist

Four phases, concrete check items.

The structure follows TIBER-EU/DORA RTS logic: preparation, threat intelligence & scenario development, red team testing, closure & remediation.

Phase 1 — Preparation

  • White team appointed and mandate documented (size, escalation paths, stop authority)
  • Scoping to critical or important functions — not individual systems
  • Sign-off obtained from risk management and relevant control functions
  • Independence of external testers verified and documented (RTS requirement)
  • Communication with the competent authority opened on timeline and contacts
  • Budget and internal capacity for post-test remediation booked in advance

Phase 2 — Threat intelligence & scenario development

  • Threat-intelligence provider engaged early and separately from the red team (role separation under the RTS)
  • Sector-specific threat picture produced — real actors, techniques, target assets
  • Attack scenarios agreed and approved with the white team
  • Target-system mapping completed against the critical functions in scope
  • Leg-up rules pre-defined for cases where realistic progress would otherwise stall

Phase 3 — Red team testing

  • Test runs covertly against production systems — only the white team is informed
  • Leg-ups are applied and documented whenever progress would otherwise be unrealistic
  • Ongoing coordination between threat intelligence and red team on scenario adjustments
  • Purple-team replay of key attack paths scheduled with the blue team
  • Evidence capture and logging run in parallel for the later attestation

Phase 4 — Closure & remediation

  • Prioritised remediation plan with dates and owners produced
  • Summary report and attestation prepared for the competent authority
  • Follow-up tracking of remediation progress scheduled (not just documented once)
  • Lessons learned captured for the next three-year cycle
Timeline

What typically takes how long.

Preparation

4–8 weeks: mandate, scoping, internal sign-offs.

Threat intelligence & scenarios

4–6 weeks to an approved scenario baseline.

Red team testing

Typically 8–12 weeks per scenario for complex engagements.

Closure & remediation

4–6 weeks for report, purple-team replay and attestation — remediation continues afterwards.

Overall a realistic 6–9 months from kick-off to attestation. These are typical ranges, not guarantees — scope and internal availability shift the timeline in either direction.

Common mistakes

What sets programmes back most often.

White team too large

The more people are briefed in advance, the less realistic the test becomes. A lean, documented mandate is part of what the RTS expects.

Scoping to systems instead of critical functions

The RTS requires scoping to critical or important functions. A scope that stops at individual applications misses the actual purpose of the test.

Treating it as a regular pentest

TLPT is covert, scenario-based and intelligence-led. An announced, fully coordinated test does not satisfy the requirement.

No remediation capacity booked

The test does not end with the report. Without budgeted capacity for follow-up, the attestation to the supervisor slips.

Threat intelligence commissioned too late

Scenario development needs lead time. If the threat-intelligence provider is engaged only shortly before the planned red-team start, the scenarios stay generic.

FAQ

Frequently asked questions about TLPT preparation

What belongs in a DORA TLPT checklist?

Four blocks: preparation (mandate, white team, scoping), threat intelligence & scenarios, the actual red-team execution including leg-ups and the purple-team replay, and closure with a remediation plan and reporting to the supervisor. This page lists the concrete check items per phase.

How long does TLPT preparation take?

Realistically 6–9 months from kick-off to attestation, depending on scoping complexity and internal stakeholder availability. Pure red-team execution per scenario typically runs 8–12 weeks for complex engagements.

Who decides whether we are in scope for TLPT?

Only the competent authority — in Germany BaFin/Bundesbank. It designates in-scope firms using the criteria in the TLPT RTS. A self-assessment can help you prepare, but it does not replace formal designation.

What is the biggest mistake in TLPT preparation?

Treating it like a regular pentest: scoping to systems instead of critical functions, and commissioning threat intelligence only once the red team is meant to start. Both cause delays and generic scenarios.

Does the white team need its own sign-off process?

Yes. The white team is small (typically 3–6 people), knows about the test in advance and needs a documented mandate including escalation paths, leg-up criteria and stop authority. Risk management and control functions must sign off the approach before start.

What happens after the red-team test closes?

A purple-team replay of the key attack paths, a prioritised remediation plan with dates, and a summary attestation to the supervisor. The RTS also expects follow-up tracking of remediation progress.

Ready to turn the checklist into a plan?

We work through scope, deadlines and roles with you and set a realistic timeline through to attestation together.

DORA & TLPT updates

RTS updates, BaFin/Bundesbank guidance and lessons from live TLPT cycles.

Compliance-adjacent updates for CISOs, chief risk officers and TLPT test managers. Kept short, no marketing.

Subscribe to DORA updates

Concise, monthly, opt out any time.