TLPT obligation (Art. 26 DORA):
Significant financial institutions are required by BaFin / Deutsche Bundesbank to conduct Threat-Led Penetration Tests - at least every three years. The authority may shorten this cycle.
DORA Art. 26 · TIBER-DE · RTS 2025/1190
DORA Art. 26 obliges significant financial institutions to conduct Threat-Led Penetration Tests against live production systems. The DORA-TLPT-RTS (EU 2025/1190, in force from 8 July 2025) specifies requirements for RTT providers, TI providers and the three-phase process. AWARE7 conducts these regulatory-recognised engagements as a qualified RTT provider under TIBER-DE - with transparent methodology and a binding fixed-price quote.
Regulatory Framework
EU Regulation (EU) 2022/2554 (DORA) has been directly applicable since 17 January 2025. The Commission Delegated Regulation (EU) 2025/1190 - the DORA-TLPT-RTS - specifies Art. 26 with 17 articles and 8 annexes. It entered into force on 8 July 2025.
TLPT obligation (Art. 26 DORA):
Significant financial institutions are required by BaFin / Deutsche Bundesbank to conduct Threat-Led Penetration Tests - at least every three years. The authority may shorten this cycle.
Live production systems (no staging):
TLPT is directed exclusively against live production systems that host critical functions (CIF) of the institution. Test environments and staging systems do not fulfil the regulatory requirement.
RTT and TI providers: qualification obligation (RTS Art. 5):
The Red Team Test Leader must demonstrate at least 5 years of proven experience in penetration testing/red teaming and 5 documented reference engagements. Team size: at least 3 persons each with ≥ 2 years of experience. Recognised certifications: OSCP+, CREST CCRTS, GIAC GCIH, CompTIA PenTest+.
Provider independence (Art. 26(9) DORA):
The RTT provider and TI provider must be fully independent of each other and may not have any economic connection to the entity being tested. Group membership precludes engagement.
Involving third-party providers (Art. 26(8) DORA):
If critical ICT functions are outsourced to external providers (e.g. cloud providers, core banking SaaS), these must be included in the TLPT scope definition. The financial institution remains responsible for the overall process.
Regulatory oversight and closure report:
Scope, methodology and results are coordinated with the authority. After completion of the closure phase, a closure report must be submitted containing purple team findings, remediation plan and MITRE ATT&CK documentation.
RTS 2025/1190: Commission Delegated Regulation (EU) 2025/1190 was published in the EU Official Journal on 13 February 2025 and has been in force since 8 July 2025. It supersedes the previous TIBER-EU guidelines as the binding legal basis. TIBER-DE was fully aligned with it in February 2025.
Timeline
After official notification by BaFin or Deutsche Bundesbank, binding deadlines begin. Typical total duration: 5-7 months.
Milestone
BaFin or Deutsche Bundesbank (TCT) identifies the institution and initiates the TLPT process. The institution selects the RTT provider (AWARE7) and TI provider.
Milestone
The white team (control team) must be reported to the authority. It typically consists of CISO, board/management and legal/compliance. Kick-off RTT provider: Generic Threat Landscape (GTL) commences.
Milestone
Scope for Scoping Document (SSD) / Generic Scope Document with defined critical functions (CIF) is agreed with the authority and submitted. TI provider begins threat intelligence collection.
Milestone
TI provider delivers the Targeted Threat Intelligence Report (TTI). AWARE7 red team commences attack simulation against live production systems. MITRE ATT&CK documentation of all techniques, tactics and artefacts.
Milestone
Mandatory deadline: within 10 weeks after end of active test phase, purple team exercises must be conducted and documented. Red team and SOC jointly work through attack chains and detection improvements.
Milestone
Closure report with findings, remediation plan, purple team results and MITRE ATT&CK mapping is submitted to BaFin / Deutsche Bundesbank (TCT). Lessons-learned session with board and CISO.
Comparison
TLPT is not an extension of a pentest - it is a fundamentally different testing methodology.
Swipe table horizontally
| Characteristic | Regulatory DORA TLPT | Market standard Conventional pentest |
|---|---|---|
| Basis | Real threat intelligence (TTI report) | Standard methodology (OWASP, PTES) |
| Systems | Live production (mandatory under RTS) | Staging / production - selectable |
| Blue team | Uninformed (realistic condition) | Often informed |
| Scope | Critical functions (CIF) | Freely definable |
| Regulation | Authority approves, closure report to BaFin | No regulatory framework |
| Duration | 5-7 months (min. test phase 12 weeks) | 3-10 days |
| TI provider | Mandatory (independent, RTS Art. 5) | Not required |
| Purple team | Mandatory within 10 weeks after test end | Optional |
| Recognised for | DORA Art. 26 evidence (regulatory) | ISMS audit, ISO 27001, NIS-2 |
| Cost | €140,000-560,000 (market average) | €5,000-50,000 |
Process
TIBER-DE prescribes a three-part process. AWARE7 fulfils the RTT role (Red Team Test provider).
Phase
Duration
4-6 weeks
Phase
Duration
≥ 12 weeks (RTS mandatory)
Phase
Duration
4-6 weeks
Scope Core
DORA Art. 2 and RTS Art. 8-12 define which functions are to be classified as Critical or Important Functions (CIF). The CIF assessment is the basis of the entire scope definition and is carried out jointly with the white team and the authority during the preparation phase.
Functions whose failure would endanger the financial stability of the institution or the financial sector - e.g. liquidity management, capital calculation, supervisory reporting.
Functions that, if compromised, would have systemic impact on other market participants - e.g. interbank clearing, TARGET2 interfaces, CCPs.
Functions that cannot be taken over by replacement systems within a reasonable timeframe - e.g. proprietary core banking systems without redundancy, critical trading platforms.
Functions essential for supervisory reporting and compliance - e.g. reporting systems, AML/KYC infrastructure, MiFID reporting.
Typical CIF systems in practice:
Core banking system · Payment processing · TARGET2 connection · Online banking platform · Trading platform · Authentication infrastructure · Reporting system · AML/KYC engine · Clearing & Settlement · Mobile banking app
Why AWARE7
The DORA-TLPT-RTS sets clear requirements for red team test providers. AWARE7 meets all of them.
11 offensive security consultants, including 4 × OSCP+ (OffSec). Multiple CVE authors (Adobe, WooCommerce, Pi-hole). Led by Vincent Heinen, M.Sc. IT Security (RUB), Head of Offensive Services. Meets RTS Art. 5: RT test leader ≥ 5 years, team size ≥ 3 persons.
Engagements at BaFin-regulated institutions - including multi-year red team exercises for credit institutions and payment service providers under regulatory requirements. More than 500 completed penetration test projects.
AWARE7 GmbH is certified to ISO/IEC 27001:2022. Auditors, clients and authorities accept our ISMS certification as a quality credential. Important for RTT provider qualification under TIBER-DE procurement guidelines.
Professional indemnity insurance (Errors & Omissions) with Hiscox SA for €3,000,000 under the NET IT by Hiscox product. Mandatory evidence in the TIBER-DE procurement process - verifiable by authority and white team.
Complete documentation of all attack techniques under MITRE ATT&CK Enterprise: tactics, techniques, procedures (TTPs) with timestamps and artefacts. RTS-compliant closure report included. Purple team preparation from day one.
AWARE7 is a German company based in Gelsenkirchen. All test data is processed exclusively on German servers. No data transfer to third countries - relevant for BSI-KRITIS, regulatory data protection requirements and banking secrecy.
Affected Institutions
RTS Art. 2 (EU 2025/1190) sets objective thresholds. Beyond these, the authority designates further institutions based on a risk analysis.
Automatically included under RTS Art. 2:
Systemically important banks
O-SII/G-SIB automatically; others following BaFin risk assessment
Insurance undertakings
BaFin-supervised primary and reinsurers > €500m GWP
Payment service providers
Payment institutions, e-money institutions > €120bn transaction volume
Investment firms
CRR investment firms and larger investment houses
Central counterparties
CCPs, central securities depositories (CSDs), trading venues
On regulatory direction
Smaller institutions may be included by regulatory order
Exempt under DORA Art. 16 are small non-interconnected financial institutions. The exact classification is made by BaFin or Deutsche Bundesbank.
Budget
TLPT engagements are substantially more extensive than conventional penetration tests - the costs reflect duration, team size and regulatory overhead.
Component
Range
€80,000 - €300,000
Scope complexity, number of CIF systems, duration of active phase (min. 12 weeks), team size (min. 3 persons per RTS)
Component
Range
€30,000 - €80,000
Targeted Threat Intelligence Report (TTI): dark web research, OSINT, malware analysis, sector intelligence. Must be independent of the RTT provider.
Component
Range
€30,000 - €180,000
White team effort, legal/compliance, external legal advice, authority coordination, CISO time, remediation implementation
Total TLPT cost: €140,000 - €560,000
Market average for first TLPT engagements at large German banks: approx. €300,000-450,000. AWARE7 provides a binding fixed-price quote - no hourly rates, no retrospective claims. Quote within 48 hours of initial consultation.
International
TIBER-DE is part of a global ecosystem of regulatory red team frameworks. All follow the three-phase approach and mandate genuine threat intelligence.
Swipe table horizontally
| Framework | Country / Region | Authority | Since | Basis |
|---|---|---|---|---|
| TIBER-DE | Germany | Deutsche Bundesbank / BaFin | 2019 | TIBER-EU / DORA |
| CBEST | United Kingdom | Bank of England | 2014 | Standalone |
| TIBER-EU | EU (cross-border) | ECB | 2018 | Reference framework |
| TIBER-NL | Netherlands | DNB | 2016 | TIBER-EU |
| TIBER-SE | Sweden | Riksbank | 2020 | TIBER-EU |
| TIBER-BE | Belgium | BNB | 2019 | TIBER-EU |
| iCAST | Hong Kong | HKMA | 2021 | CBEST/TIBER-EU |
| CORIE | Australia | RBA / APRA | 2020 | Standalone |
A TIBER-DE completion can in certain constellations be mutually recognised across multiple EU jurisdictions - particularly for institutions with subsidiaries in several EU member states.
FAQ
Your contact for DORA TLPT
M.Sc. in IT Security with more than 5 years of experience in offensive security analysis. Leads the delivery of penetration tests, specializing in web applications, network infrastructure, reverse engineering and hardware security. Responsible for several responsible disclosures.
Fixed-price quote in 48h
We discuss scope, CIF assessment, timeline and authority coordination - free and non-binding. You receive a binding fixed-price quote within 48 hours.
Arturs Nikitins
Initial consultation & needs analysis
Looking for personal advice?
No obligation · Reply within 24h on business days