DORA Penetration Testing & TLPT
DORA penetration testing and TLPT aligned to Articles 24-27 and the RTS, from baseline pentests to threat-led exercises. Get a fixed quote.
DORA penetration testing proves that a financial entity’s digital operational resilience holds up against a real attacker, from routine vulnerability testing all the way to threat-led penetration testing for the firms that reach the threshold. We scope the test to the Regulation (EU) 2022/2554 requirements that apply to you and deliver evidence your supervisor and your board can both act on.
What DORA penetration testing actually covers
The Digital Operational Resilience Act sets a tiered testing regime. Every in-scope financial entity has to run a program of digital operational resilience testing, and that program has to include appropriate tests of its ICT systems. A smaller subset, identified by their systemic importance and risk profile, must additionally undergo advanced testing in the form of threat-led penetration testing, or TLPT. We handle both ends of that spectrum and everything in between.
SafetyBis works with banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and their critical ICT third parties across Europe. Every test is manual and evidence-based, because a regulator reviewing your resilience program wants proof of exploitability, not a scanner export.
How DORA structures its testing requirements
The relevant obligations sit in Chapter IV of the regulation. Knowing which article applies to you decides the test you actually need.
Articles 24 and 25: the baseline testing program
Article 24 requires every in-scope entity to establish a sound, comprehensive digital operational resilience testing program as part of its ICT risk-management framework. Article 25 lists the tools that program can use, including vulnerability assessments, network security assessments, penetration testing, and source-code reviews where relevant. This is the layer most financial entities live at, and it maps directly onto the web, network, API and cloud testing we run every week.
Articles 26 and 27: threat-led penetration testing
Article 26 introduces advanced testing through TLPT for the entities identified as significant enough to warrant it. It sets the ground rules: testing on live production systems, covering several critical functions, carried out at least every three years. Article 27 sets the requirements for the testers and the threat intelligence behind the test, and the accompanying RTS on threat-led penetration testing fills in the detail on scope, methodology and the tester pool.
What TLPT demands of a provider
The RTS expects the red team and the threat intelligence to meet specific competence and independence standards, and expects the exercise to be coordinated with the relevant authority. We deliver the red team and intelligence component to that standard. We do not claim to grant our own regulatory accreditation, and a formal DORA TLPT is coordinated with your authority, drawing on the TIBER-EU model that many European supervisors use as the operating framework.
Baseline testing: how we run it
For the Article 24 and 25 program, the method is a disciplined, mostly manual penetration test of the ICT systems behind your critical or important functions.
Scoping and reconnaissance
We identify the systems that support your critical functions, agree rules of engagement, and map the external surface with tooling such as nmap and passive reconnaissance before anything intrusive runs.
Manual testing and exploitation
Burp Suite drives the web and API work; custom tooling and hands-on tradecraft cover network, cloud and business-logic testing. We prove each weakness by exploiting it safely and chain findings to show the real path from the internet to a system that matters.
Reporting and retest
You receive an executive summary and a technical report, each finding scored with CVSS, evidenced and paired with a prioritized fix. After remediation we retest for free and confirm the issues are closed.
Threat-led penetration testing: how a TLPT runs
A DORA TLPT follows the same three-stage rhythm as TIBER-EU, because that framework is what most European authorities use to operate the requirement. It is a longer, quieter, more realistic exercise than a baseline test.
Preparation
You form a small control group, we agree the critical functions in scope and the rules of engagement, and for a formal test your authority is involved from the start. The scope has to cover several critical or important functions, per Article 26.
Intelligence and testing
A threat intelligence provider builds a targeted picture of the actors that attack your part of the financial sector, referenced to MITRE ATT&CK. The red team turns that into scenarios and executes them on live systems, attempting initial access, escalation and lateral movement toward the flags, staying stealthy enough to test your detection.
Closure
We disclose to your blue team, replay the whole attack path with them, and help produce the remediation plan and the test summary the authority reviews. A retest of the fixes is included.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Vulnerability classes we find most often in financial estates
The financial sector is well-defended on paper, but the same weaknesses recur under the surface.
Broken access control and IDOR
In customer portals and banking APIs, we regularly find that one authenticated user can read or move another’s data by changing an identifier. It is the most common serious finding in web finance, and a scanner rarely catches it.
Authentication and session flaws
Weak multi-factor implementations, token handling mistakes and SSO misconfigurations that let an attacker bypass the login the business trusts.
Cloud and segmentation gaps
Overly broad IAM roles, exposed storage, and flat networks that let one compromised system reach a payment or settlement platform.
Third-party trust abuse
DORA puts ICT third-party risk front and center, and for good reason. We look at the standing access your critical providers hold and what an attacker could reach through it.
What you receive
Every engagement produces documentation built for two readers: the management body that owns ICT risk under DORA, and the engineers who fix the findings.
Reports and mapping
An executive summary, a technical report with CVSS-scored findings, evidence and reproduction steps, and a mapping to the Chapter IV testing articles so your supervisor sees exactly how the test satisfies the regulation.
Attestation and remediation support
An attestation letter for your resilience program file, a prioritized remediation plan, and a free retest that produces the confirmation letter audit wants to see.
Why manual testing is the right fit for DORA
DORA is about resilience under real conditions, and real conditions are not what a scanner models. An automated tool cannot exploit a business-logic flaw in a payment flow, cannot chain three minor issues into access to a settlement system, and cannot behave like the threat actors DORA’s TLPT regime asks you to rehearse against. Article 25 allows automated tools as part of a broader program, and we use them where they add value. But the evidence a supervisor trusts, and the findings that actually reduce your risk, come from a human operator who has attacked estates like yours before.
Who is in scope and when to start
DORA applies broadly across the financial sector, and the practical question for most firms is not whether they are in scope but which tier of testing they owe. Getting that answer early shapes your whole resilience program.
The range of covered entities
The regulation reaches credit institutions, payment and e-money institutions, investment firms, insurance and reinsurance undertakings, crypto-asset service providers, trading venues, central securities depositories and more, plus the ICT third-party providers that serve them. Proportionality applies, so a small firm carries a lighter load than a systemic bank, but the baseline testing obligation is close to universal.
Building the testing into your program early
A resilience program is not a single test; it is a documented cycle. The sensible pattern is an annual baseline penetration test of the systems behind your critical functions, extra testing after any material change, and, for entities that reach the TLPT threshold, a threat-led exercise at least every three years. Starting a year ahead of any supervisory review gives you room to remediate and produce a clean retest letter rather than presenting open findings.
Coordinating a formal TLPT
Because a formal threat-led test is coordinated with your authority and typically runs on the TIBER-EU model, the lead time is long. Firms that expect to be in the TLPT population should open the conversation with us and their supervisor well before the deadline, so the intelligence and scoping are not rushed.
Pricing
DORA testing spans two very different exercises, so the pricing does too. A baseline penetration test under Articles 24 and 25 is scoped like any serious pentest; a threat-led penetration test is a longer, intelligence-driven engagement. Both are fixed-price after a scoping call.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Baseline resilience test | Penetration test of the ICT systems behind one critical function, report and free retest, mapped to Articles 24–25 | 5–8 working days | from €3,000 |
| Extended program test | Multiple critical functions, network, applications, APIs and cloud, attack-chaining and Chapter IV mapping | 8–15 working days | €8,000–€20,000 |
| TLPT-aligned exercise | Targeted threat intelligence, multi-scenario red team on live systems, full report, remediation plan and replay | 8–12 weeks | from €18,000 |
| Formal DORA TLPT | Full RTS-aligned delivery coordinated with your authority, control-group support, closure artifacts | 10–16 weeks | from €35,000 |
| Custom / group estate | Cross-border group or shared ICT third party, scoped after a free call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with attestation and a retest included. Get a fixed quote
FAQ
How much does DORA penetration testing cost?
Do we need a full TLPT, or is a baseline test enough?
Are you an accredited DORA TLPT provider?
How often does DORA require testing?
Can you test our critical ICT third-party providers?
Will testing disrupt our live systems?
What documentation do we get for our supervisor?
Are the findings kept confidential?
Related services
Banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and their critical ICT third parties across Europe that must build a DORA testing program under Articles 24 and 25, and the significant entities that additionally face threat-led penetration testing under Article 26.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.