DORA · Guide

How to select a DORA TLPT provider

If you are in scope for threat-led penetration testing, choosing the provider is the most consequential decision in your compliance timeline. Here is how to tell a DORA-ready red team from a CV.

A DORA TLPT provider should be assessed on three things: the offensive-security credentials held by the operators who will actually run the test, documented independence from the teams that build and defend your systems, and a threat-led methodology driven by intelligence about actors targeting your sector. Provider accreditation runs through the national TIBER-EU implementations, not through any vendor's own claim.

What this guide covers

  • ✅ Credentials, and what “qualified” actually means
  • ✅ Independence as a legal requirement rather than a preference
  • ✅ Threat-led methodology, and how to spot a scan in disguise
  • ✅ Seven questions to take into any provider conversation
  • ✅ The timing trap nobody is pricing in yet

Credentials: what “qualified” actually means

DORA does not accept “we do penetration testing” as a qualification. The regulatory technical standards set expectations around tester competence, and in practice the market has settled on a set of offensive-security credentials as the baseline: OSCP as the entry benchmark for hands-on offensive skill, OSEP for advanced evasion and lateral movement, and CRTO for adversary simulation and red team tradecraft.

These are not the whole story, but their absence is a red flag. A provider who cannot tell you which certifications their operators hold, or who leans on one senior name while junior staff do the work, is not a DORA-grade red team. Ask about the people who will run your test, not the people on the website.

Independence: a legal requirement, not a preference

DORA requires testing to be genuinely independent, and that has consequences for who you can hire. The team running the test must be separate from the teams that build and defend your systems. If you use internal testers at all, DORA imposes strict conditions that most entities cannot satisfy, which is why external providers are the norm. Your provider should also be free of conflicts with the ICT providers whose systems fall inside scope.

Ask directly how they guarantee independence, and how they document it for your competent authority. A provider who has done this before will have a clean answer straight away.

Methodology: threat-led, not checklist-led

This is where real red teams separate themselves. A DORA-grade provider should be able to walk you through scenarios driven by the tactics of threat actors that genuinely target your sector rather than a generic template, testing against live production systems safely and in coordination with your monitoring team, a purple-teaming phase where red and blue work together, and a remediation plan that ends the exercise with a path to fixing things rather than a list.

If the pitch sounds like an automated scan, walk away. If they open by asking about your critical functions and your threat landscape, you are talking to the right kind of team.

Seven questions worth asking

Take these into any provider conversation. The quality of the answers tells you more than any brochure.

  1. Which certifications do the operators who will actually run our test hold, as opposed to the founder?
  2. How do you guarantee and document independence for our competent authority?
  3. How do you build threat scenarios specific to our sector and our critical functions?
  4. How do you test production safely, and how do you coordinate with our monitoring team?
  5. What do your purple teaming and remediation phases actually deliver?
  6. What is your current capacity, and when could you realistically start?
  7. Can you show that your approach has withstood supervisory scrutiny before?

The timing trap

A full TLPT cycle takes the better part of a year. Competent authorities have to be involved. And the pool of providers meeting DORA's criteria is small relative to the number of entities that will need them. Put those together and provider selection becomes a capacity race.

Entities that choose early lock in the good providers on a sensible timeline. The ones that wait until a deadline looms find the best teams booked, and end up choosing from whoever is left, under time pressure, at whatever price scarcity dictates. Choosing early is not just good practice. It is how you avoid paying a premium for a worse outcome.

Where breachr fits

A formal Article 26 engagement requires an independent accredited testing provider, and accreditation runs through the national TIBER-EU implementations. That is a specific role, and it is worth being clear that it is not the one breachr plays.

What we do is the testing either side of it. breachr runs continuous penetration testing designed around DORA and NIS2, so the estate a TLPT eventually examines has already been tested, confirmed by a named security professional, and ranked against your business by the Business Risk Engine. Turning up to a threat-led exercise with a clean, evidenced estate is a considerably better position than turning up cold.

You can see what an attacker reaches on your estate today in a few minutes. No credentials, no card.

In summary

Judge a provider on the operators who will run your test, on independence they can document, and on whether their methodology starts from threat intelligence rather than a checklist. Then judge the calendar, because capacity is finite and the good teams book up. Both halves of that decision get harder the longer you leave them.

This article is general information, not legal or compliance advice. Requirements for testers and threat-intelligence providers are set out in DORA and its regulatory technical standards, and accreditation runs through the national TIBER-EU implementations.

Frequently asked

What qualifications should a DORA TLPT provider have?
DORA and its regulatory technical standards set expectations around tester competence. In practice the market looks for offensive-security credentials such as OSCP, OSEP and CRTO among the operators who will run the test, alongside documented independence. Accreditation of providers runs through the national TIBER implementations rather than any vendor self-declaration.
Does a DORA TLPT provider have to be external?
Not strictly, but DORA imposes strict conditions on the use of internal testers, and most entities cannot satisfy them. External providers are the norm for that reason.
Why does provider capacity matter?
The pool of providers meeting DORA criteria is small relative to the number of entities that will need one, and a full cycle runs for many months. Selection is a timing decision as much as a quality one.
What should a TLPT engagement deliver at the end?
A threat-led exercise ends with a purple-teaming phase where red and blue teams work together, a remediation plan, and reporting that supports supervisory review. A list of findings alone is not the deliverable.

Ready to produce the evidence?

Start free, or talk to us about a DORA programme on EU infrastructure.