Am I in scope for DORA TLPT?
DORA threat-led penetration testing applies only to financial entities designated by their competent authority, based on criteria including systemic importance and ICT risk profile. It is not a self-assessment and there is no published list to check yourself against. Entities that are not designated still carry proportionate testing obligations under DORA Articles 24 and 25.
What this guide covers
- ✅ Who DORA TLPT actually targets, and why systemic impact matters more than size
- ✅ A five-question self-assessment you can work through today
- ✅ What being in scope means for your timeline
- ✅ What you still owe if you are not in scope
Who DORA TLPT actually targets
DORA does not ask every financial entity to run threat-led testing. It targets the institutions whose disruption would ripple outward into the wider financial system. In practice the entities most likely to be designated include systemically important credit institutions, including global and other systemically important institutions and entities forming part of such a group. Payment institutions and electronic money institutions operating above certain thresholds are also candidates, as are entities singled out by a competent authority on the basis of their risk profile or their role in critical functions.
The through-line is systemic impact rather than headcount or balance sheet. A mid-sized payments firm sitting in a critical part of the settlement chain can be in scope where a larger but less critical entity is not.
The self-assessment: five questions
Work through these in order. They will not replace a formal designation from your competent authority, but they will tell you how seriously to be planning right now.
- Are you a credit institution classified as systemically important, or part of such a group?
If yes, assume you are in scope until told otherwise. - Are you a payment institution or e-money institution operating above the regulatory thresholds?
If yes, you are a likely candidate. Confirm with your competent authority. - Do you support critical or important functions whose failure would materially affect the financial system?
The more central your role, the more likely designation becomes. - Has your competent authority already engaged with you on operational resilience testing?
Early supervisory contact is often the first signal. - Do you rely on third-party ICT providers for critical functions?
Those dependencies can fall inside a TLPT's scope, which affects your planning even where the provider is not the entity being tested.
If you answered yes to the first three in any combination, treat yourself as in scope and begin planning. The cost of being ready early is far lower than the cost of being caught late.
You are in scope. Now what?
Being in scope is not the emergency. Being in scope and starting late is. Timing is the part teams underestimate, for three compounding reasons. A full TLPT cycle covering scoping, threat intelligence, red teaming, purple teaming and remediation runs for many months rather than weeks. Providers meeting DORA's criteria are not numerous, and their capacity is finite. Competent authorities have to be involved in scoping and approval, which adds lead time you do not control.
Put those together and the practical deadline for starting sits a long way ahead of any headline compliance date. Institutions that move first get the good providers and a calm timeline. The ones that wait compete for scarce capacity against a hard cut-off.
Not in scope? You still have testing obligations
If you sit outside the TLPT designation, DORA does not leave you alone. It asks for proportionate digital operational resilience testing rather than a full threat-led exercise. That still means a structured testing programme, vulnerability assessments, and evidence you can put in front of a supervisor. The bar is lower. It is not zero.
Where breachr fits
breachr is a continuous penetration testing platform designed for DORA and NIS2. We test the way you would actually be attacked, a named security professional confirms every critical finding, and the Business Risk Engine ranks what we find against your own business so the order you fix things in reflects your exposure. Whether you are heading for a full threat-led programme or proportionate testing under Articles 24 and 25, the point is the same: be ready on your own timeline rather than the market's.
The fastest way to see what your estate looks like from the outside is to run a scan. It is free, it needs nothing but a URL, and it takes minutes.
In summary
TLPT is narrower than DORA as a whole, and designation belongs to your competent authority rather than to you. If the first three questions above point at you, plan as though you are in scope, because the lead times are long and the capacity is finite. If they do not, you still owe a structured testing programme with evidence behind it. Either way the work starts earlier than most teams expect.
This article is general information, not legal or compliance advice. Your competent authority makes the formal determination of whether you are subject to TLPT under DORA.
Frequently asked
Ready to produce the evidence?
Start free, or talk to us about a DORA programme on EU infrastructure.