How to select a DORA TLPT provider
A DORA TLPT provider should be assessed on three things: the offensive-security credentials held by the operators who will actually run the test, documented independence from the teams that build and defend your systems, and a threat-led methodology driven by intelligence about actors targeting your sector. Provider accreditation runs through the national TIBER-EU implementations, not through any vendor's own claim.
What this guide covers
- ✅ Credentials, and what “qualified” actually means
- ✅ Independence as a legal requirement rather than a preference
- ✅ Threat-led methodology, and how to spot a scan in disguise
- ✅ Seven questions to take into any provider conversation
- ✅ The timing trap nobody is pricing in yet
Credentials: what “qualified” actually means
DORA does not accept “we do penetration testing” as a qualification. The regulatory technical standards set expectations around tester competence, and in practice the market has settled on a set of offensive-security credentials as the baseline: OSCP as the entry benchmark for hands-on offensive skill, OSEP for advanced evasion and lateral movement, and CRTO for adversary simulation and red team tradecraft.
These are not the whole story, but their absence is a red flag. A provider who cannot tell you which certifications their operators hold, or who leans on one senior name while junior staff do the work, is not a DORA-grade red team. Ask about the people who will run your test, not the people on the website.
Independence: a legal requirement, not a preference
DORA requires testing to be genuinely independent, and that has consequences for who you can hire. The team running the test must be separate from the teams that build and defend your systems. If you use internal testers at all, DORA imposes strict conditions that most entities cannot satisfy, which is why external providers are the norm. Your provider should also be free of conflicts with the ICT providers whose systems fall inside scope.
Ask directly how they guarantee independence, and how they document it for your competent authority. A provider who has done this before will have a clean answer straight away.
Methodology: threat-led, not checklist-led
This is where real red teams separate themselves. A DORA-grade provider should be able to walk you through scenarios driven by the tactics of threat actors that genuinely target your sector rather than a generic template, testing against live production systems safely and in coordination with your monitoring team, a purple-teaming phase where red and blue work together, and a remediation plan that ends the exercise with a path to fixing things rather than a list.
If the pitch sounds like an automated scan, walk away. If they open by asking about your critical functions and your threat landscape, you are talking to the right kind of team.
Seven questions worth asking
Take these into any provider conversation. The quality of the answers tells you more than any brochure.
- Which certifications do the operators who will actually run our test hold, as opposed to the founder?
- How do you guarantee and document independence for our competent authority?
- How do you build threat scenarios specific to our sector and our critical functions?
- How do you test production safely, and how do you coordinate with our monitoring team?
- What do your purple teaming and remediation phases actually deliver?
- What is your current capacity, and when could you realistically start?
- Can you show that your approach has withstood supervisory scrutiny before?
The timing trap
A full TLPT cycle takes the better part of a year. Competent authorities have to be involved. And the pool of providers meeting DORA's criteria is small relative to the number of entities that will need them. Put those together and provider selection becomes a capacity race.
Entities that choose early lock in the good providers on a sensible timeline. The ones that wait until a deadline looms find the best teams booked, and end up choosing from whoever is left, under time pressure, at whatever price scarcity dictates. Choosing early is not just good practice. It is how you avoid paying a premium for a worse outcome.
Where breachr fits
A formal Article 26 engagement requires an independent accredited testing provider, and accreditation runs through the national TIBER-EU implementations. That is a specific role, and it is worth being clear that it is not the one breachr plays.
What we do is the testing either side of it. breachr runs continuous penetration testing designed around DORA and NIS2, so the estate a TLPT eventually examines has already been tested, confirmed by a named security professional, and ranked against your business by the Business Risk Engine. Turning up to a threat-led exercise with a clean, evidenced estate is a considerably better position than turning up cold.
You can see what an attacker reaches on your estate today in a few minutes. No credentials, no card.
In summary
Judge a provider on the operators who will run your test, on independence they can document, and on whether their methodology starts from threat intelligence rather than a checklist. Then judge the calendar, because capacity is finite and the good teams book up. Both halves of that decision get harder the longer you leave them.
This article is general information, not legal or compliance advice. Requirements for testers and threat-intelligence providers are set out in DORA and its regulatory technical standards, and accreditation runs through the national TIBER-EU implementations.
Frequently asked
Ready to produce the evidence?
Start free, or talk to us about a DORA programme on EU infrastructure.