§ 03 Guide 3 / 4

Pulled into a bank’s red team: TLPT participation for suppliers

Updated 9 min read dorasupplier.eu

A threat-led penetration test is not a scan of your product and not a scheduled window agreed with your operations team. It is an intelligence-led red team exercise run against live production to a supervisory methodology, with an active phase of at least twelve weeks, and Article 30(3)(d) turns your participation into a contractual duty. This guide explains how a supplier ends up in scope, what the exercise costs in calendar time, and the one route in the Regulation that puts the supplier in control of the schedule.

How a supplier ends up inside somebody else’s test

DORA defines threat-led penetration testing in Article 3(17) as “a framework that mimics the tactics, techniques and procedures of real-life threat actors perceived as posing a genuine cyber threat, that delivers a controlled, bespoke, intelligence-led (red team) test of the financial entity’s critical live production systems”. The chain that reaches a supplier runs through three articles.

Article 26(1) requires financial entities identified by their competent authority, other than microenterprises and the entities under the simplified framework in Article 16(1), to carry out advanced testing by means of TLPT at least every 3 years. The authority may raise or lower that frequency based on the entity’s risk profile.

Article 26(2) sets the scope. Each test “shall cover several or all critical or important functions of a financial entity, and shall be performed on live production systems supporting such functions”. Then the sentence that matters to you: financial entities “shall identify all relevant underlying ICT systems, processes and technologies supporting critical or important functions and ICT services, including those supporting the critical or important functions which have been outsourced or contracted to ICT third-party service providers”. The resulting scope is validated by the competent authority, which is why it is not renegotiable once the exercise starts.

Article 26(3) makes getting you there the customer’s job: “Where ICT third-party service providers are included in the scope of TLPT, the financial entity shall take the necessary measures and safeguards to ensure the participation of such ICT third-party service providers in the TLPT and shall retain at all times full responsibility for ensuring compliance with this Regulation.” The necessary measure, in practice, is the clause it already put in your contract under Article 30(3)(d).

What the exercise looks like, phase by phase

Commission Delegated Regulation (EU) 2025/1190, the regulatory technical standard on TLPT, was developed in accordance with the TIBER-EU framework and sets the methodology in detail. The numbers below are from its text, and they are the ones that decide how much of your year this consumes.

The phases of a DORA TLPT, and where the supplier appears
PhaseWhat happensWhere you sitBasis
IdentificationThe competent authority identifies which entities must test, on impact, financial-stability and ICT-maturity criteriaNot involved; you learn of it from your customerArt. 26(8)
ScopingThe entity identifies the critical or important functions and every underlying system, including those contracted to providers; the authority validates the scopeYou supply the system inventory and the interface mapArt. 26(2)
Threat intelligenceA threat intelligence provider builds targeted intelligence; the control team lead selects at least three scenarios, of which at most one may be non-threat-ledYou are inside at least one scenario in a pooled testRTS 2025/1190, Art. 10
Active red teamTesters execute against live production for at least 12 weeks, reporting weekly to the control teamYour production estate is in the target set; your staff are normally not toldRTS 2025/1190, Art. 11
ClosureReports and remediation plans are agreed and submitted; the authority issues an attestationYou negotiate and own your remediation commitmentsArt. 26(6), 26(7)

Twelve weeks, minimum

Article 11(5) of the delegated regulation states that the duration of the active red team testing phase “shall be proportionate to the TLPT scope, to the scale, activity, complexity and number of the financial entities and ICT third-party or ICT intragroup service providers involved in the TLPT, and in any case shall last for at least 12 weeks”. That is the active phase alone. Scoping, threat intelligence, remediation agreement and the authority’s attestation sit outside it. A supplier that budgets a fortnight of support has misread the exercise by a factor of five.

Your own team is not told

The exercise depends on secrecy from the defenders. Article 11(9) addresses what happens when that breaks: “In the case of detection of the testing activities by any staff member of the financial entity or of its ICT third-party service providers …, the control team, in consultation with the testers … shall propose and submit measures allowing to continue the TLPT while ensuring its secrecy to the test managers for validation.” In other words, your security operations team is expected to be surprised, and detection is a result rather than a reason to stop.

Article 11(10) is the safety valve. Where the test threatens data, assets or the continuity of critical or important functions at the entity, at its providers, at counterparts or in the sector, the control team lead may suspend it, or as a last resort continue it as a limited purple teaming exercise, whose duration still counts towards the twelve weeks.

Scenarios and targets

Article 10(3) requires the control team lead to select at least three scenarios; Article 10(4) allows no more than one of them to be non-threat-led. For a pooled test, the same article adds a requirement aimed squarely at the supplier: without prejudice to the scenarios targeting the participating entities’ own critical or important functions, “at least one scenario shall include the ICT third-party services provider’s relevant underlying ICT systems, processes, and technologies supporting the critical or important functions of the financial entities in scope”.

Article 26(4): the route where you hold the contract

The most useful paragraph in the whole of Chapter IV for a supplier is Article 26(4), and it is regularly missed because it is one very long sentence.

Without prejudice to paragraph 2, first and second subparagraphs, where the participation of an ICT third-party service provider in the TLPT … is reasonably expected to have an adverse impact on the quality or security of services delivered by the ICT third-party service provider to customers that are entities falling outside the scope of this Regulation, or on the confidentiality of the data related to such services, the financial entity and the ICT third-party service provider may agree in writing that the ICT third-party service provider directly enters into contractual arrangements with an external tester, for the purpose of conducting, under the direction of one designated financial entity, a pooled TLPT involving several financial entities (pooled testing) to which the ICT third-party service provider provides ICT services.

Three things follow. First, the gate is a harm test, and a multi-tenant platform with customers outside the financial sector meets it on its face: a red team exercise against shared production affects the quality, security and data confidentiality of every tenant, not only the bank that commissioned it. Second, the arrangement is a written agreement, not a supplier right, so it has to be proposed and accepted. Third, and commercially decisive, the supplier contracts the external tester. You choose the firm, you agree the scope, and the schedule fits your release calendar rather than four separate ones.

The paragraph continues: the pooled test “shall cover the relevant range of ICT services supporting critical or important functions contracted to the respective ICT third-party service provider by the financial entities”, and it “shall be considered TLPT carried out by the financial entities participating in the pooled testing”. It discharges their obligation. The number of participating entities is “duly calibrated taking into account the complexity and types of services involved”.

The delegated regulation adds the plumbing. Article 2 defines the pool as all the financial entities participating in a pooled TLPT under Article 26(4), and distinguishes it from a joint TLPT, which involves entities sharing an intra-group provider or the same systems. Article 7 keeps risk management with each entity: “the control team of each financial entity shall conduct its own risk assessment and establish its own risk management measures”. Article 16(5) handles the cross-border case, where the authorities agree which financial entity is designated to conduct the pooled test and whose authority leads.

Who is allowed to run it

Article 27(1) sets five cumulative conditions on the testers a financial entity may use, and they apply equally to the tester you contract under Article 26(4). Testers must be of the highest suitability and reputability; possess technical and organisational capabilities and demonstrate specific expertise in threat intelligence, penetration testing and red team testing; be certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks; provide independent assurance or an audit report on the sound management of the risks of carrying out TLPT, including protection of the entity’s confidential information; and be fully covered by professional indemnity insurance, including against misconduct and negligence.

Article 26(8) adds a constraint worth checking against your customer. Entities using internal testers must contract external testers every three tests, and credit institutions classified as significant under Article 6(4) of Regulation (EU) No 1024/2013 “shall only use external testers”. If your customer is a significant institution, expect a named external red team rather than its own function.

What to do before the first test lands

  1. Establish which of your contracts sit under Article 30(3). Only those carry a participation duty, and knowing the count tells you how many tests you can be pulled into over a three-year cycle.
  2. Build the system inventory your customer needs for Article 26(2) scoping: which of your components support its critical or important function, which interfaces it uses, which data flows cross the boundary. Producing this under time pressure is how scope creeps.
  3. Decide who inside your company forms the small cleared group that will know. Article 11(9) assumes your defenders do not, so somebody senior has to hold the secret and the escalation path.
  4. Agree the suspension criteria in advance with your customer, mapped to Article 11(10): what constitutes a risk to data, assets or the continuity of the service, and who can call a halt.
  5. Prepare the Article 26(4) argument now, in writing, if you serve customers outside DORA on the same platform. The harm test is easier to make before a test is scheduled than during a negotiation about one.
  6. Test yourself first. A twelve-week red team exercise against live production is an expensive way to discover an unauthenticated management interface. An ordinary penetration test and a remediation cycle beforehand changes what the red team finds, and therefore what your customer’s remediation plan says about you.

Point six is not self-serving advice dressed as guidance, or not only. The closure phase in Article 26(6) requires a summary of findings, remediation plans and supporting documentation to go to the authority, and your customer negotiates its remediation plan with you in the room. Findings you already knew about and had already fixed do not appear there.

If you have not yet established which clause set your contracts fall under, start with the guide to the critical or important function determination. If the addendum is still in draft, the addendum guide sets out where the TLPT clause sits among the other fourteen elements.

Sources

  1. Regulation (EU) 2022/2554 (DORA), Articles 3(17), 26 and 27 EUR-Lex · 2022
  2. Commission Delegated Regulation (EU) 2025/1190: regulatory technical standards on threat-led penetration testing EUR-Lex · 2025 Articles 2, 7, 10, 11 and 16 are quoted in this guide.
  3. Commission Delegated Regulation (EU) 2024/1773 on the policy for contractual arrangements covering critical or important functions EUR-Lex · 2024

Related questions

Can we refuse to take part?

Not if the contract falls under Article 30(3). Participation and full cooperation are a mandatory contractual element under Article 30(3)(d), and Article 26(3) obliges the financial entity to take the necessary measures and safeguards to ensure your participation. What you can do is propose the Article 26(4) pooled route, agree suspension criteria under Article 11(10) of the delegated regulation, and negotiate the scope while it is still being set.

Who pays?

The Regulation does not allocate the cost, which means the contract does. In the ordinary case the financial entity contracts and pays the testers and you absorb your own participation effort. Under Article 26(4) the supplier “directly enters into contractual arrangements with an external tester”, so the supplier pays the tester and typically recovers it across the participating customers. Settle this at addendum stage; it is far harder once a test is scheduled.

Is a normal penetration test enough?

No, and they answer different questions. An ordinary penetration test is scoped, announced and bounded. A TLPT is intelligence-led, covers several or all critical or important functions, runs on live production, uses at least three threat-led scenarios and lasts at least twelve weeks in its active phase. A penetration test is excellent preparation for one, and it is also the evidence your customer relies on under Delegated Regulation (EU) 2024/1773 for ordinary assurance. It is not a substitute.

How often will this happen?

Article 26(1) sets at least every three years for each identified financial entity, and the competent authority may increase or reduce that frequency. If several of your customers are in the TLPT population, their cycles are independent, which is the practical argument for a pooled test under Article 26(4) rather than a queue of separate exercises against the same platform.

Will we see the findings?

You will see the ones that concern you, because you have to remediate them, and the closure phase under Article 26(6) requires agreed remediation plans before the summary goes to the authority. You should not expect the full report about your customer’s estate. Agree the information flow in the contract rather than assuming it.

Does our ISO 27001 certificate exempt us?

No. Certification is an assurance route under Delegated Regulation (EU) 2024/1773, Article 8(2)(c), and even there Article 8(3) forbids the financial entity from relying on it alone over time. TLPT is a separate obligation in Article 26 with its own methodology and its own tester requirements in Article 27(1).