🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
DORACR-DORA-05

DORA TLPT — Threat-Led Penetration Testing (Premium)

DORA Art. 26–27 TLPT for significant financial entities. TIBER-EU aligned, live production red team, threat intelligence, regulator summary. From €15,000. Every 3 years.

DORA TLPT — Threat-Led Penetration Testing (Premium) by Optimum Web is a fixed-price compliance service covering DORA Articles 26–27 — Threat-Led Penetration Testing (TLPT), TIBER-EU aligned. It costs from €15,000 with 12–16 weeks delivery by senior security engineers. Threat intelligence report (targeted to your institution and sector). 14-day warranty included.

from €15,000
Fixed price, VAT excluded
12–16 weeksSenior only
Threat intelligence report (targeted to your institution and sector)
Red team execution report (full attack path documentation, critical function coverage)
Blue team replay workshop (attacker perspective debrief)
Regulator summary report (DORA Art. 26(6) compliant)
🛡️
14-Day Warranty
If the delivered pack does not match your ISMS scope and Statement of Applicability, we rework it at no cost, or refund in full within 14 days of delivery.
Premium · Custom Quote · €15,000+
Request Consultation
or order without payment
+373 22 843569
PayPal · SSL
👨‍💻 Senior only
14-day warranty
🆔 CR-DORA-05

This Service Covers

DORAArticles 26–27 — Threat-Led Penetration Testing (TLPT)

What You Get

Full Threat-Led Penetration Testing (TLPT) aligned with TIBER-EU framework. Mandatory for significant financial entities under DORA Article 26–27. Phase 1: preparation, generic threat landscape, scope definition with regulator coordination. Phase 2: targeted threat intelligence for your institution. Phase 3: red team execution on live production targeting critical or important functions. Phase 4: reporting, replay workshop with blue team, regulator summary. Performed by TIBER-accredited testers.

Who Needs This

  • Significant credit institutions, payment institutions, e-money institutions in the EU
  • Major insurance and reinsurance undertakings
  • Critical ICT third-party service providers designated under DORA
  • Financial market infrastructures (central counterparties, trade repositories)
  • Organisations whose national competent authority has notified them of TLPT obligation

How It Works

  1. 1
    Phase 1 — Preparation

    Scope definition, regulator coordination, white team formation, generic threat landscape

  2. 2
    Phase 2 — Threat Intelligence

    Targeted threat intelligence report for your institution and sector

  3. 3
    Phase 3 — Red Team Execution

    Live production red team engagement targeting critical/important functions

  4. 4
    Phase 4 — Reporting

    Full technical report, blue team replay workshop, regulator summary

ONGOING COMPLIANCE

Don't Want to Think About Compliance Every Quarter?

Compliance-as-a-Service: €729/month. Quarterly reviews, scans, documentation, and security questionnaire support — as an extension of your team, not a replacement for your compliance owner.

Start CaaS — €729/month

Ready to Start?

from €15,000 · 12–16 weeks · 14-day warranty

Order — from €15,000
or order without payment

Want ongoing compliance? Compliance-as-a-Service — €729/month

Learn more

Frequently Asked Questions

How is TLPT different from a regular pentest?+
TLPT uses real, fresh threat intelligence about active adversaries targeting your sector and tests live production with red team tradecraft. Regular pentests use generic methodology and often staging environments.
Why is this not a fixed price?+
Scope varies enormously — number of critical/important functions, target institutions, regulator coordination overhead. Each TLPT is bespoke.
Who at our company is involved?+
The white team (typically CISO + 3–5 senior staff who know about the test) plus regulator liaison. The blue team is NOT informed in advance.
What's TIBER-EU?+
The ECB's framework for intelligence-led red team testing of financial market infrastructures. DORA TLPT is closely aligned.
Can we use our existing pentest team?+
Only if they're TIBER-accredited. Otherwise no — DORA Art. 27 requires accredited testers.
Is the result shared with the regulator?+
A summary, yes — Art. 26(6) requires it. The full technical detail stays with you.

Service page last reviewed 11 August 2026 by the Optimum Web compliance team.

Order — from €15,000
or order without payment