The Digital Operational Resilience Act (Regulation (EU) 2022/2554) starts applying in January 2025, but Article 26 — the threat-led penetration testing obligation — is the one most incident-response teams underestimate. A DORA TLPT is not a bigger pentest. It is an adversary emulation with three seated parties, regulator-visible scope, and a report that reads like a post-incident forensics deliverable.
Three parties, always seated
The regulatory technical standards, drawn largely from TIBER-EU, require named participants in three distinct roles. The red team executes the attack. The blue team is the in-house security operation, uninformed about the exercise. The white team — usually the CISO office and the compliance function — knows about the test, controls its safety envelope, and speaks to the regulator. If any of the three is missing, the exercise is not a TLPT for Article 26 purposes; it is a pentest with an ambitious brief.
Threat intelligence must precede the exploit
Article 26 is explicit that the emulated adversary must be justified by threat intelligence relevant to the entity. In practice that means a targeted-threat-intelligence provider produces a document that names the actor cluster, the campaigns modelled, the TTPs derived from ATT&CK for Enterprise v14, and the initial access vector selected. This document is delivered to the regulator with the final report; skipping it means the report does not qualify.
What the report has to contain
The final dossier is not a bullet list of findings. Each attack path in scope receives a narrative — reconnaissance, initial access, execution, persistence, lateral movement, exfiltration — with the timestamps, the payloads, the C2 infrastructure, and the blue-team detection posture at each hop. Every technique gets its ATT&CK identifier, every finding a CVSS 4.0 vector, every remediation an owner and an ETA. The regulator reads it. It is signed.
What we recommend before commissioning
- Confirm your competent authority accepts your TLPT provider — some national regulators publish a shortlist.
- Write the white-team RACI in month one, not month five. Everything downstream stalls without it.
- Budget for threat intelligence separately. It is a distinct deliverable and materially affects the report.
- Run at least one tabletop with the blue team before authorising initial access. The exercise value is limited if defenders are simply overwhelmed.
- Reserve calendar days after the test for the debriefs required by Article 26(6) — the point of the exercise lives in the closeouts.
A TLPT is not an assurance exercise. It is a controlled failure exercise. If nothing fails, the emulator did not push hard enough — or the intelligence was too soft.
For an engagement brief that maps to DORA Article 26 deliverables from scoping through closeout, use the intake at /engagement/nda. We work with an in-house threat-intelligence function and, on request, with a client-nominated provider.
