Pulled into a bank’s red team: TLPT participation for suppliers
A threat-led penetration test is not a scan of your product and not a scheduled window agreed with your operations team. It is an intelligence-led red team exercise run against live production to a supervisory methodology, with an active phase of at least twelve weeks, and Article 30(3)(d) turns your participation into a contractual duty. This guide explains how a supplier ends up in scope, what the exercise costs in calendar time, and the one route in the Regulation that puts the supplier in control of the schedule.
How a supplier ends up inside somebody else’s test
DORA defines threat-led penetration testing in Article 3(17) as “a framework that mimics the tactics, techniques and procedures of real-life threat actors perceived as posing a genuine cyber threat, that delivers a controlled, bespoke, intelligence-led (red team) test of the financial entity’s critical live production systems”. The chain that reaches a supplier runs through three articles.
Article 26(1) requires financial entities identified by their competent authority, other than microenterprises and the entities under the simplified framework in Article 16(1), to carry out advanced testing by means of TLPT at least every 3 years. The authority may raise or lower that frequency based on the entity’s risk profile.
Article 26(2) sets the scope. Each test “shall cover several or all critical or important functions of a financial entity, and shall be performed on live production systems supporting such functions”. Then the sentence that matters to you: financial entities “shall identify all relevant underlying ICT systems, processes and technologies supporting critical or important functions and ICT services, including those supporting the critical or important functions which have been outsourced or contracted to ICT third-party service providers”. The resulting scope is validated by the competent authority, which is why it is not renegotiable once the exercise starts.
Article 26(3) makes getting you there the customer’s job: “Where ICT third-party service providers are included in the scope of TLPT, the financial entity shall take the necessary measures and safeguards to ensure the participation of such ICT third-party service providers in the TLPT and shall retain at all times full responsibility for ensuring compliance with this Regulation.” The necessary measure, in practice, is the clause it already put in your contract under Article 30(3)(d).
What the exercise looks like, phase by phase
Commission Delegated Regulation (EU) 2025/1190, the regulatory technical standard on TLPT, was developed in accordance with the TIBER-EU framework and sets the methodology in detail. The numbers below are from its text, and they are the ones that decide how much of your year this consumes.
| Phase | What happens | Where you sit | Basis |
|---|---|---|---|
| Identification | The competent authority identifies which entities must test, on impact, financial-stability and ICT-maturity criteria | Not involved; you learn of it from your customer | Art. 26(8) |
| Scoping | The entity identifies the critical or important functions and every underlying system, including those contracted to providers; the authority validates the scope | You supply the system inventory and the interface map | Art. 26(2) |
| Threat intelligence | A threat intelligence provider builds targeted intelligence; the control team lead selects at least three scenarios, of which at most one may be non-threat-led | You are inside at least one scenario in a pooled test | RTS 2025/1190, Art. 10 |
| Active red team | Testers execute against live production for at least 12 weeks, reporting weekly to the control team | Your production estate is in the target set; your staff are normally not told | RTS 2025/1190, Art. 11 |
| Closure | Reports and remediation plans are agreed and submitted; the authority issues an attestation | You negotiate and own your remediation commitments | Art. 26(6), 26(7) |
Twelve weeks, minimum
Article 11(5) of the delegated regulation states that the duration of the active red team testing phase “shall be proportionate to the TLPT scope, to the scale, activity, complexity and number of the financial entities and ICT third-party or ICT intragroup service providers involved in the TLPT, and in any case shall last for at least 12 weeks”. That is the active phase alone. Scoping, threat intelligence, remediation agreement and the authority’s attestation sit outside it. A supplier that budgets a fortnight of support has misread the exercise by a factor of five.
Your own team is not told
The exercise depends on secrecy from the defenders. Article 11(9) addresses what happens when that breaks: “In the case of detection of the testing activities by any staff member of the financial entity or of its ICT third-party service providers …, the control team, in consultation with the testers … shall propose and submit measures allowing to continue the TLPT while ensuring its secrecy to the test managers for validation.” In other words, your security operations team is expected to be surprised, and detection is a result rather than a reason to stop.
Article 11(10) is the safety valve. Where the test threatens data, assets or the continuity of critical or important functions at the entity, at its providers, at counterparts or in the sector, the control team lead may suspend it, or as a last resort continue it as a limited purple teaming exercise, whose duration still counts towards the twelve weeks.
Scenarios and targets
Article 10(3) requires the control team lead to select at least three scenarios; Article 10(4) allows no more than one of them to be non-threat-led. For a pooled test, the same article adds a requirement aimed squarely at the supplier: without prejudice to the scenarios targeting the participating entities’ own critical or important functions, “at least one scenario shall include the ICT third-party services provider’s relevant underlying ICT systems, processes, and technologies supporting the critical or important functions of the financial entities in scope”.
Article 26(4): the route where you hold the contract
The most useful paragraph in the whole of Chapter IV for a supplier is Article 26(4), and it is regularly missed because it is one very long sentence.
Without prejudice to paragraph 2, first and second subparagraphs, where the participation of an ICT third-party service provider in the TLPT … is reasonably expected to have an adverse impact on the quality or security of services delivered by the ICT third-party service provider to customers that are entities falling outside the scope of this Regulation, or on the confidentiality of the data related to such services, the financial entity and the ICT third-party service provider may agree in writing that the ICT third-party service provider directly enters into contractual arrangements with an external tester, for the purpose of conducting, under the direction of one designated financial entity, a pooled TLPT involving several financial entities (pooled testing) to which the ICT third-party service provider provides ICT services.
Three things follow. First, the gate is a harm test, and a multi-tenant platform with customers outside the financial sector meets it on its face: a red team exercise against shared production affects the quality, security and data confidentiality of every tenant, not only the bank that commissioned it. Second, the arrangement is a written agreement, not a supplier right, so it has to be proposed and accepted. Third, and commercially decisive, the supplier contracts the external tester. You choose the firm, you agree the scope, and the schedule fits your release calendar rather than four separate ones.
The paragraph continues: the pooled test “shall cover the relevant range of ICT services supporting critical or important functions contracted to the respective ICT third-party service provider by the financial entities”, and it “shall be considered TLPT carried out by the financial entities participating in the pooled testing”. It discharges their obligation. The number of participating entities is “duly calibrated taking into account the complexity and types of services involved”.
The delegated regulation adds the plumbing. Article 2 defines the pool as all the financial entities participating in a pooled TLPT under Article 26(4), and distinguishes it from a joint TLPT, which involves entities sharing an intra-group provider or the same systems. Article 7 keeps risk management with each entity: “the control team of each financial entity shall conduct its own risk assessment and establish its own risk management measures”. Article 16(5) handles the cross-border case, where the authorities agree which financial entity is designated to conduct the pooled test and whose authority leads.
Who is allowed to run it
Article 27(1) sets five cumulative conditions on the testers a financial entity may use, and they apply equally to the tester you contract under Article 26(4). Testers must be of the highest suitability and reputability; possess technical and organisational capabilities and demonstrate specific expertise in threat intelligence, penetration testing and red team testing; be certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks; provide independent assurance or an audit report on the sound management of the risks of carrying out TLPT, including protection of the entity’s confidential information; and be fully covered by professional indemnity insurance, including against misconduct and negligence.
Article 26(8) adds a constraint worth checking against your customer. Entities using internal testers must contract external testers every three tests, and credit institutions classified as significant under Article 6(4) of Regulation (EU) No 1024/2013 “shall only use external testers”. If your customer is a significant institution, expect a named external red team rather than its own function.
What to do before the first test lands
- Establish which of your contracts sit under Article 30(3). Only those carry a participation duty, and knowing the count tells you how many tests you can be pulled into over a three-year cycle.
- Build the system inventory your customer needs for Article 26(2) scoping: which of your components support its critical or important function, which interfaces it uses, which data flows cross the boundary. Producing this under time pressure is how scope creeps.
- Decide who inside your company forms the small cleared group that will know. Article 11(9) assumes your defenders do not, so somebody senior has to hold the secret and the escalation path.
- Agree the suspension criteria in advance with your customer, mapped to Article 11(10): what constitutes a risk to data, assets or the continuity of the service, and who can call a halt.
- Prepare the Article 26(4) argument now, in writing, if you serve customers outside DORA on the same platform. The harm test is easier to make before a test is scheduled than during a negotiation about one.
- Test yourself first. A twelve-week red team exercise against live production is an expensive way to discover an unauthenticated management interface. An ordinary penetration test and a remediation cycle beforehand changes what the red team finds, and therefore what your customer’s remediation plan says about you.
Point six is not self-serving advice dressed as guidance, or not only. The closure phase in Article 26(6) requires a summary of findings, remediation plans and supporting documentation to go to the authority, and your customer negotiates its remediation plan with you in the room. Findings you already knew about and had already fixed do not appear there.
If you have not yet established which clause set your contracts fall under, start with the guide to the critical or important function determination. If the addendum is still in draft, the addendum guide sets out where the TLPT clause sits among the other fourteen elements.
Sources
- Regulation (EU) 2022/2554 (DORA), Articles 3(17), 26 and 27
- Commission Delegated Regulation (EU) 2025/1190: regulatory technical standards on threat-led penetration testing Articles 2, 7, 10, 11 and 16 are quoted in this guide.
- Commission Delegated Regulation (EU) 2024/1773 on the policy for contractual arrangements covering critical or important functions