July 16, 2026
DORA threat-led penetration testing (TLPT): who is in scope and what it tests
DORA — Regulation (EU) 2022/2554, the Digital Operational Resilience Act — has applied since 17 January 2025. Financial entities across the EU now operate under a new framework for testing ICT resilience. One of its most demanding requirements is threat-led penetration testing, or TLPT. Unlike annual vulnerability scans or staged penetration tests run on isolated test systems, TLPT is intelligence-driven, runs against live production systems, and requires independent testers. Understanding who must run it, what it covers, and how file transfer systems fit into scope is now a compliance necessity, not a future concern.
Who must run TLPT under DORA
DORA applies broadly to financial entities — banks, insurance companies, investment firms, and more. TLPT is narrower: under Articles 26 and 27, entities identified by their national authorities based on their significance and risk profile must conduct threat-led penetration testing at least once every three years. The test must be carried out by independent testers meeting the requirements of Article 27 — external by default, with internal testers permitted only under strict conditions and never for every consecutive test.
ICT third-party service providers supporting critical functions can be pulled into scope as well. If a cloud provider, managed file transfer platform, or integration specialist handles data critical to the financial entity's operations, they may be required to participate in or support TLPT as part of their customer's compliance obligation. Pooled testing — where multiple financial entities coordinate a single TLPT campaign against a provider serving all of them — is permitted under DORA and often reduces cost and complexity.
What TLPT actually does
Threat-led penetration testing follows the TIBER-EU framework model published by the European Central Bank. TIBER stands for Threat Intelligence Based Ethical Red teaming. The test is intelligence-led: testers do not start with a checklist of common vulnerabilities. Instead, they begin with threat intelligence relevant to the financial sector, identifying the tactics, techniques, and procedures that actual threat actors use. They then simulate those attacks against live production systems, with the goal of proving whether the entity can detect, respond to, and recover from an intrusion.
TLPT differs from regular vulnerability assessments and penetration tests in three critical ways. First, it runs on live systems — staging or sandbox environments do not count. Second, it mimics real attackers, meaning testers use tactics that threat actors actually employ: lateral movement, credential theft, data exfiltration, and persistence techniques. Third, it evaluates not just technical defenses but also detection and response capabilities: can your security team spot the attack in progress, and how fast can they evict the attacker?
Why file transfer systems are in scope
File transfer platforms — SFTP gateways, AS2 endpoints, and managed file transfer solutions — move sensitive and regulated data between entities. In a TLPT scenario, an attacker who gains access to the file transfer layer can do several high-impact things: intercept data in motion, modify files before delivery, exfiltrate backup archives, or manipulate audit logs to hide their activity. Regulators and TLPT testers therefore focus on the MFT layer when assessing the financial entity's resilience.
What testers look for in your file transfer infrastructure includes tenant isolation (can a compromised operator account access another customer's data?), per-transfer audit trails (is there a tamper-evident log of who accessed what and when?), and credential management (are SSH keys rotated, revoked promptly, and tracked?). The ability to prove that a specific file was transmitted, by whom, and whether it was modified in transit becomes evidence of resilience under DORA.
Regular testing versus TLPT
DORA Articles 24 and 25 require an annual ICT resilience testing programme — vulnerability assessments, scenario-based tests, and assessments of critical systems. These are less intensive than TLPT and can include staged environments and tabletop exercises. TLPT is the capstone: a real-world adversary simulation running every three years on live production systems. Both are mandatory; TLPT is the more demanding one.
For more detail, review DORA on EUR-Lex and the ECB TIBER-EU framework page. If your organization handles regulated data — especially across file transfer platforms — start an inventory of every endpoint and access pattern now. See our DORA readiness checklist for a starting point, and why DORA made file transfer a board-level risk for the governance side.
xEvolve provides the audit trail, tenant isolation, and Entra SSO integration that TLPT scoping conversations focus on — per-transfer logging that testers and regulators can verify, and HTTPS/SFTP/AS2 support with EU data residency.