Do We Need TLPT or Will a Normal Penetration Test Do?

Do We Need TLPT, or Will a Normal Penetration Test Do?

Key Takeaways

  • TLPT is not self-selected. Under DORA Article 26(8) your authority identifies you and the obligation begins on notification.
  • Designated entities test at least every three years and the authority can raise or lower that frequency.
  • In Sweden, Finansinspektionen decides who tests and how often. The Riksbank supervises the tests and issues the attestation.
  • Commission Delegated Regulation (EU) 2025/1190 was adopted on 13 February 2025 published on 18 June 2025 and has applied since 8 July 2025.
  • The Riksbank expected between ten and twelve firms to fall under its TLPT fee regulations when they took effect on 1 January 2026.
  • Everyone else still owes yearly testing of the ICT systems supporting critical or important functions under Article 24(6).

The Letter Decides, Not Your Risk Register

Commission Delegated Regulation (EU) 2025/1190 has applied across the EU since 8 July 2025 and the Riksbank’s fee regulations for threat-led penetration testing took effect on 1 January 2026. The question in the room is usually put more simply. Do we need TLPT or is the penetration test already in the budget enough? If you run risk or compliance at a Swedish bank, insurer, payment institution or market infrastructure operator, that answer is not yours to reach. It arrives in writing from Finansinspektionen, and until it does you are not in scope.

Sweden has coordinated threat-intelligence-led tests through TIBER-SE since 2019 and firms joined by agreement with the Riksbank. That programme still shapes how a test runs. What changed is who decides that it runs at all. Under Article 26(8) the competent authority identifies the entities that must test and the criteria behind that decision are now written down and quantitative.

What is Threat-Led Penetration Testing?

Threat-led penetration testing is an intelligence-led red team exercise run against the live production systems that support an entity’s critical or important functions. A threat intelligence provider builds scenarios from the adversaries who would realistically target the firm, testers execute them covertly and the people defending the estate are not told that the attack is a test.

The rulebook has three dates worth keeping straight. The Commission adopted Delegated Regulation (EU) 2025/1190 on 13 February 2025, it was published in the Official Journal on 18 June 2025 and it became directly applicable on 8 July 2025. Recital 1 says the regulation was drafted in accordance with the TIBER-EU framework and mirrors its methodology and structure.

The European Central Bank updated TIBER-EU on 11 February 2025 to match making purple teaming mandatory and renaming the white team the control team.

Who Is Required to Do TLPT?

Article 2 of the delegated regulation works in two layers. The first is an assessment each TLPT authority runs on impact and systemic character and on the entity’s ICT risk profile covering size, interconnectedness, criticality, substitutability, the complexity of the business model and the maturity of detection and response. The second is a list with numbers attached, set out below.

The list is not the end of it. Recital 2 lets an authority release an entity that meets the quantitative criteria where its risk profile does not justify a test. Recital 3 lets an authority pull in a type the list never mentions and names crypto-asset service providers as the example. Microenterprises and entities on the simplified ICT risk framework in Article 16(1) sit outside Article 26 altogether and nobody can opt in.

Who the Thresholds Name

  • Credit institutions : Global or other systemically important institutions and entities forming part of one
  • Payment institutions : Above EUR 150 billion in payment transaction value in each of the two preceding calendar years
  • E-money institutions : Above EUR 150 billion in payments or above EUR 40 billion in outstanding electronic money
  • Market infrastructure : Central securities depositories and central counterparties, named outright
  • Trading venues : Highest national turnover share or a Union turnover share above 5 %
  • Insurers : A three-part test on premium, technical provisions and assets, then a higher subset test

How Sweden Splits the Job Between Two Authorities

Under 2 kap. 1 § lagen (2024:1278) Finansinspektionen decides which entities must run threat-led penetration testing and how often, after the Riksbank has been heard. Under 2 kap. 2 § the Riksbank supervises and coordinates the tests, validates which critical or important functions fall inside the scope, checks that the tester meets Article 27 and issues the attestation. That attestation carries mutual recognition across the EU and no other Swedish authority can issue it.

The scale is small. Deciding its fee regulations on 3 December 2025, the Riksbank expected between ten and twelve firms to fall under them at entry into force on 1 January 2026. An earlier legislative memorandum put the outer estimate at around twenty. Neither figure is a designation list and the only notice that binds you is the one addressed to you.

TIBER-SE Is the How, TLPT Is the What

The Riksbank draws the line in exactly those terms. TLPT describes what must be done and TIBER-SE describes how it is done. The framework is being revised so work from the current documents rather than a saved copy.

TLPT vs a Normal Penetration Test

Recital 12 of the delegated regulation states the difference better than most vendor comparisons manage. A conventional penetration test gives a detailed and useful assessment of technical and configuration weaknesses often in a single system or environment in isolation. It does not test the full scenario of a targeted attack against an entire entity including its people, its processes and its technology.

Three things follow. Scenarios come from intelligence about actors who would realistically target you rather than from a checklist. The exercise runs covertly against live production so your own detection and response are part of what is measured. And the results reach a supervisor which a normal penetration test report does not.

None of that replaces the baseline. Article 24(6) requires every financial entity other than a microenterprise to ensure appropriate tests are conducted at least yearly on all ICT systems and applications supporting critical or important functions.

What Happens After the Notification

The obligation starts when the TLPT authority notifies you and every deadline runs from that date rather than from your planning cycle.

You have three months to file the initiation information covering the project charter and high-level plan, the control team lead whether you intend to use internal or external testers, the communication channels and the code name. You have six months to submit the scope specification document and your management body has to approve it.

Then the exercise. The control team lead selects at least three scenarios of which no more than one may be non-threat-led and the testers report to the control team and the test managers at least weekly. Closure carries its own clock and it is the part most firms underestimate.

The Clock From Notification to Attestation

On notificationThe obligation starts. Nothing before the letter counts towards it.
Within 3 monthsInitiation information including the project charter and the code name.
Within 6 monthsScope specification document, approved by the management body.
About 4 weeksThreat intelligence gathering on TIBER-EU experience.
At least 12 weeksThe active red team phase against live production systems.
Within 4 weeks of the endThe red team test report reaches the control team.
Within 10 weeks of the endBlue team report, replay and purple teaming.
Within 8 weeks after thatTest summary report to the authority, then the remediation plan.

The Risks the Exercise Itself Creates

Recital 11 is blunt about what can go wrong. Critical functions are tested in a live production environment which brings the possibility of denial-of-service incidents, unexpected system crashes, damage to critical live production systems and the loss, modification or disclosure of data.

The regulation answers that with control rather than caution. Knowledge is limited to the control team, the management body, the testers, the threat intelligence provider and the authority. The test runs under a code name, and where testers cannot progress on their own the control team grants a leg-up, agreed with the test managers.

If the risk turns real the control team lead can suspend the test or with the authority’s agreement, continue it as a limited purple teaming exercise. That time still counts towards the twelve weeks.

Who Is Allowed to Run the Test

Article 27 of DORA sets five conditions. Testers must be of the highest suitability and reputability, hold specific expertise in threat intelligence and in penetration and red team testing, be certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks, provide independent assurance on how they manage the risks of the work and carry professional indemnity insurance covering misconduct and negligence.

Article 7 of the delegated regulation adds numbers. The threat intelligence provider supplies at least three references and external testers at least five. The red team needs a manager with at least five years in penetration and red team testing plus two further testers with at least two years each.

Internal testers are allowed with conditions. You need a documented policy, a test lead and at least two further members, all employed for the preceding twelve months. The threat intelligence provider must always be external and every third test has to use external testers.

No Credential Is Named in Article 27

Article 27(1)(c) names no credential. A tester certified by an accreditation body in a Member State satisfies it and so does a tester adhering to formal codes of conduct or ethical frameworks. A CREST accreditation is one route to the condition rather than a requirement of DORA in itself.

What Failure Actually Costs

No fine attaches to Article 26 on its own. What bites first is the attestation, because without a compliant test there is nothing to show a supervisor in Sweden or anywhere else in the EU. The delegated regulation treats the absence of that attestation as a risk the control team manages from the start.

Administrative sanctions are left to national law, and in Sweden the ceiling depends on which act governs your business.

How to Stay Ready Between Tests

Three years is the cadence, not the workload. Map your critical or important functions and the ICT systems behind them now because the scope specification document is due six months after a letter you cannot schedule. Include third-party and intra-group providers since the rationale for leaving a function out is reviewed as closely as the rationale for putting one in.

Keep the control team small and senior, led by someone with the mandate to run the test. Test your detection rather than only your perimeter because the blue team report is half of what the authority reads.

The Answer to the Question

If no notification has arrived, you are not in scope for TLPT and your obligation is the annual programme under Article 24(6). If one has arrived, the clock started on the date it carries and your first deadline is three months out. Establish which of those two you are in before you scope anything.

Frequently Asked Questions

Do we need TLPT or a normal penetration test?

Only if your competent authority has designated you under DORA Article 26(8). Designated entities run threat-led testing at least every three years. Everyone else other than microenterprises still owes the Article 24(6) programme meaning appropriate tests at least yearly on the systems supporting critical or important functions.

Who designates TLPT entities in Sweden?

Finansinspektionen. Under 2 kap. 1 § lagen (2024:1278) it decides which entities must test and how often, after the Riksbank has been heard. The Riksbank then supervises and coordinates the test, validates the scope and the tester and issues the attestation under Article 26(7).

Does a CREST accreditation satisfy DORA Article 27?

It can but DORA does not require it. Article 27(1)(c) asks that testers are certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks. No named credential is mandated and the other four conditions apply either way.

Can we use our own internal testers for TLPT?

Yes, under conditions. You need a documented policy, a test lead and at least two further members, all employed for the preceding twelve months. The threat intelligence provider must always be external. Every third test has to use external testers and a mixed team counts as internal.

eBuilder Security works with financial entities and their suppliers on Penetration Testing and CISO Advisory.

This post is also available in: Svenska