Home/Services/DORA Penetration Testing & TLPT
security service

DORA Penetration Testing & TLPT

DORA penetration testing and TLPT aligned to Articles 24-27 and the RTS, from baseline pentests to threat-led exercises. Get a fixed quote.

Manual, expert-ledEvidence-based findingsFree remediation retest

DORA penetration testing proves that a financial entity’s digital operational resilience holds up against a real attacker, from routine vulnerability testing all the way to threat-led penetration testing for the firms that reach the threshold. We scope the test to the Regulation (EU) 2022/2554 requirements that apply to you and deliver evidence your supervisor and your board can both act on.

What DORA penetration testing actually covers

The Digital Operational Resilience Act sets a tiered testing regime. Every in-scope financial entity has to run a program of digital operational resilience testing, and that program has to include appropriate tests of its ICT systems. A smaller subset, identified by their systemic importance and risk profile, must additionally undergo advanced testing in the form of threat-led penetration testing, or TLPT. We handle both ends of that spectrum and everything in between.

SafetyBis works with banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and their critical ICT third parties across Europe. Every test is manual and evidence-based, because a regulator reviewing your resilience program wants proof of exploitability, not a scanner export.

Vulnerability assessment and penetration testing of the ICT systems supporting critical functions
Threat-led penetration testing aligned to the DORA RTS and the TIBER-EU framework
Testing that reaches into critical ICT third-party providers where scope allows
Findings mapped to the Chapter IV testing articles for your supervisor
A pool of testers and threat intelligence that meets the RTS requirements
Remediation plan, attestation and a free retest of the fixes

How DORA structures its testing requirements

The relevant obligations sit in Chapter IV of the regulation. Knowing which article applies to you decides the test you actually need.

Articles 24 and 25: the baseline testing program

Article 24 requires every in-scope entity to establish a sound, comprehensive digital operational resilience testing program as part of its ICT risk-management framework. Article 25 lists the tools that program can use, including vulnerability assessments, network security assessments, penetration testing, and source-code reviews where relevant. This is the layer most financial entities live at, and it maps directly onto the web, network, API and cloud testing we run every week.

Articles 26 and 27: threat-led penetration testing

Article 26 introduces advanced testing through TLPT for the entities identified as significant enough to warrant it. It sets the ground rules: testing on live production systems, covering several critical functions, carried out at least every three years. Article 27 sets the requirements for the testers and the threat intelligence behind the test, and the accompanying RTS on threat-led penetration testing fills in the detail on scope, methodology and the tester pool.

What TLPT demands of a provider

The RTS expects the red team and the threat intelligence to meet specific competence and independence standards, and expects the exercise to be coordinated with the relevant authority. We deliver the red team and intelligence component to that standard. We do not claim to grant our own regulatory accreditation, and a formal DORA TLPT is coordinated with your authority, drawing on the TIBER-EU model that many European supervisors use as the operating framework.

Baseline testing: how we run it

For the Article 24 and 25 program, the method is a disciplined, mostly manual penetration test of the ICT systems behind your critical or important functions.

Scoping and reconnaissance

We identify the systems that support your critical functions, agree rules of engagement, and map the external surface with tooling such as nmap and passive reconnaissance before anything intrusive runs.

Manual testing and exploitation

Burp Suite drives the web and API work; custom tooling and hands-on tradecraft cover network, cloud and business-logic testing. We prove each weakness by exploiting it safely and chain findings to show the real path from the internet to a system that matters.

Reporting and retest

You receive an executive summary and a technical report, each finding scored with CVSS, evidenced and paired with a prioritized fix. After remediation we retest for free and confirm the issues are closed.

3 yrs
the maximum TLPT cycle under Article 26
48h
to first critical findings on a baseline test
Free
retest after your team remediates

Threat-led penetration testing: how a TLPT runs

A DORA TLPT follows the same three-stage rhythm as TIBER-EU, because that framework is what most European authorities use to operate the requirement. It is a longer, quieter, more realistic exercise than a baseline test.

Preparation

You form a small control group, we agree the critical functions in scope and the rules of engagement, and for a formal test your authority is involved from the start. The scope has to cover several critical or important functions, per Article 26.

Intelligence and testing

A threat intelligence provider builds a targeted picture of the actors that attack your part of the financial sector, referenced to MITRE ATT&CK. The red team turns that into scenarios and executes them on live systems, attempting initial access, escalation and lateral movement toward the flags, staying stealthy enough to test your detection.

Closure

We disclose to your blue team, replay the whole attack path with them, and help produce the remediation plan and the test summary the authority reviews. A retest of the fixes is included.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Vulnerability classes we find most often in financial estates

The financial sector is well-defended on paper, but the same weaknesses recur under the surface.

Broken access control and IDOR

In customer portals and banking APIs, we regularly find that one authenticated user can read or move another’s data by changing an identifier. It is the most common serious finding in web finance, and a scanner rarely catches it.

Authentication and session flaws

Weak multi-factor implementations, token handling mistakes and SSO misconfigurations that let an attacker bypass the login the business trusts.

Cloud and segmentation gaps

Overly broad IAM roles, exposed storage, and flat networks that let one compromised system reach a payment or settlement platform.

Third-party trust abuse

DORA puts ICT third-party risk front and center, and for good reason. We look at the standing access your critical providers hold and what an attacker could reach through it.

What you receive

Every engagement produces documentation built for two readers: the management body that owns ICT risk under DORA, and the engineers who fix the findings.

Reports and mapping

An executive summary, a technical report with CVSS-scored findings, evidence and reproduction steps, and a mapping to the Chapter IV testing articles so your supervisor sees exactly how the test satisfies the regulation.

Attestation and remediation support

An attestation letter for your resilience program file, a prioritized remediation plan, and a free retest that produces the confirmation letter audit wants to see.

Why manual testing is the right fit for DORA

DORA is about resilience under real conditions, and real conditions are not what a scanner models. An automated tool cannot exploit a business-logic flaw in a payment flow, cannot chain three minor issues into access to a settlement system, and cannot behave like the threat actors DORA’s TLPT regime asks you to rehearse against. Article 25 allows automated tools as part of a broader program, and we use them where they add value. But the evidence a supervisor trusts, and the findings that actually reduce your risk, come from a human operator who has attacked estates like yours before.

Who is in scope and when to start

DORA applies broadly across the financial sector, and the practical question for most firms is not whether they are in scope but which tier of testing they owe. Getting that answer early shapes your whole resilience program.

The range of covered entities

The regulation reaches credit institutions, payment and e-money institutions, investment firms, insurance and reinsurance undertakings, crypto-asset service providers, trading venues, central securities depositories and more, plus the ICT third-party providers that serve them. Proportionality applies, so a small firm carries a lighter load than a systemic bank, but the baseline testing obligation is close to universal.

Building the testing into your program early

A resilience program is not a single test; it is a documented cycle. The sensible pattern is an annual baseline penetration test of the systems behind your critical functions, extra testing after any material change, and, for entities that reach the TLPT threshold, a threat-led exercise at least every three years. Starting a year ahead of any supervisory review gives you room to remediate and produce a clean retest letter rather than presenting open findings.

Coordinating a formal TLPT

Because a formal threat-led test is coordinated with your authority and typically runs on the TIBER-EU model, the lead time is long. Firms that expect to be in the TLPT population should open the conversation with us and their supervisor well before the deadline, so the intelligence and scoping are not rushed.

Pricing

DORA testing spans two very different exercises, so the pricing does too. A baseline penetration test under Articles 24 and 25 is scoped like any serious pentest; a threat-led penetration test is a longer, intelligence-driven engagement. Both are fixed-price after a scoping call.

Engagement What’s included Timeline Price
Baseline resilience test Penetration test of the ICT systems behind one critical function, report and free retest, mapped to Articles 24–25 5–8 working days from €3,000
Extended program test Multiple critical functions, network, applications, APIs and cloud, attack-chaining and Chapter IV mapping 8–15 working days €8,000–€20,000
TLPT-aligned exercise Targeted threat intelligence, multi-scenario red team on live systems, full report, remediation plan and replay 8–12 weeks from €18,000
Formal DORA TLPT Full RTS-aligned delivery coordinated with your authority, control-group support, closure artifacts 10–16 weeks from €35,000
Custom / group estate Cross-border group or shared ICT third party, scoped after a free call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with attestation and a retest included. Get a fixed quote

FAQ

How much does DORA penetration testing cost?
A baseline penetration test under Articles 24 and 25 starts from €3,000. A threat-led penetration test is a larger exercise, typically from €18,000, rising with the number of critical functions and the depth of the intelligence phase. You get a fixed quote after a free scoping call.
Do we need a full TLPT, or is a baseline test enough?
Most in-scope entities meet DORA with the baseline testing program under Articles 24 and 25. Only entities identified as significant, based on systemic importance and risk profile, must undergo threat-led penetration testing under Article 26. We help you work out which applies and scope accordingly.
Are you an accredited DORA TLPT provider?
A formal DORA threat-led penetration test is coordinated with your competent authority, which validates the process, and many authorities operate it through the TIBER-EU framework. We deliver the red team and threat intelligence to the DORA RTS standard and coordinate with your authority. We do not claim to issue our own regulatory accreditation.
How often does DORA require testing?
The baseline testing program runs regularly as part of your ICT risk-management framework, usually annually and after significant change. Threat-led penetration testing under Article 26 must happen at least every three years for the entities required to perform it.
Can you test our critical ICT third-party providers?
Where scope and contracts allow, yes. DORA makes third-party ICT risk a core concern, so we can model the access a critical provider holds and, with the right authorization, test into that relationship.
Will testing disrupt our live systems?
No. Baseline tests are run carefully with any intrusive checks agreed in advance. TLPT runs on production by design but stops short of harm once access to a critical function is proven, with a control group able to pause the test at any point.
What documentation do we get for our supervisor?
An executive summary, a technical report with CVSS-scored findings mapped to the Chapter IV testing articles, an attestation letter, a remediation plan and a free retest report. For a TLPT, you also get the closure artifacts the framework expects.
Are the findings kept confidential?
Yes. We work under NDA, handle all evidence and reports through secure channels, and share results only with the people you nominate and, for a formal TLPT, your authority.

Related services

Who needs this

Banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and their critical ICT third parties across Europe that must build a DORA testing program under Articles 24 and 25, and the significant entities that additionally face threat-led penetration testing under Article 26.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "DORA Penetration Testing & TLPT"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.