- Articles 12 to 14 and Annexes V to VIII define closure reports, replay and purple teaming, remediation-plan content, and attestation content.
"Content of the red team test report"
A cited runbook structure for financial entities that must perform DORA threat-led penetration testing.
Use it to organise authority touchpoints, critical-function scoping, tester and threat-intelligence controls, active red-team testing, closure reports, remediation evidence, and attestation records.
Structured answer sets in this page tree.
Cited legal and guidance references.
DORA has applied since 17 January 2025. DORA is an authority-coordinated test of live production systems supporting several or all critical or important functions. Under Article 26, identified financial entities must control the scope and risks, document results, prepare remediation plans, and obtain an authority attestation. This runbook organises those requirements without adding test steps beyond DORA and Delegated Regulation (EU) 2025/1190.
The scope section should list all critical or important functions considered for , not only the functions selected for testing. For each function, record whether it is included, why it is included or excluded, the supporting ICT systems, outsourced or contracted ICT services, relevant jurisdictions, and preliminary flags tied to confidentiality, integrity, authenticity, or availability.
DORA requires each to cover several or all critical or important functions and to be performed on live production systems supporting them. The precise scope is determined by the financial entity's assessment and validated by the competent authority or TLPT authority. Where ICT third-party providers support in-scope functions, the runbook should show how their participation is covered, including whether pooled TLPT is being considered where direct provider participation could affect other customers or confidentiality.
Use the provider-control section to prove that the threat intelligence provider and testers meet DORA and RTS requirements before contracting or assigning them. The TLPT RTS expects an external threat intelligence provider, and it sets detailed evidence expectations for skills, references, certifications, insurance, independence, conflicts of interest, secure restoration, and prohibited conduct.
The testing section should keep three records together: the targeted threat intelligence report, the scenario-selection record, and the red team test plan. The threat intelligence provider must produce concrete, actionable, contextualised target and threat intelligence. The control team lead selects at least three scenarios using the provider's recommendation, test-manager input, tester feasibility judgement, and the entity's size, complexity, and risk profile. No more than one selected scenario may be non-threat-led.
The closure section should not stop at the red team report. After active red-team testing ends, the control team informs the blue team, testers submit the red team test report, the blue team submits its report, and the parties replay offensive and defensive actions. The control team also runs purple teaming on jointly identified topics based on vulnerabilities found during testing and, where relevant, topics not fully tested during the active phase.
The testers submit the red team report within four weeks after active testing ends. The blue team report, replay, and purple teaming are due no later than ten weeks after active testing ends. Once the authority confirms that it has assessed the red and blue team reports, the financial entity has eight weeks to submit the summary report for approval and eight weeks from the same notification to provide the remediation plan and supporting documentation.
The remediation plan should track each finding to the shortcoming, remediation measure, priority and expected completion, root cause, responsible staff or function, and risks of not implementing the measure. Keep the attestation and notify the relevant competent authority of the attestation, summary findings, and remediation plans.
Use the cited sources listed here to verify obligations and the supporting evidence requirements.
Verify the following areas from the cited sources: TLPT scope, testers, reports, remediation, and authority evidence using the cited sources on this page.
Review the authority touchpoints, provider evidence, testing records, and remediation fields needed for your DORA TLPT runbook.
"Content of the red team test report"
"updated its European framework for threat intelligence-based ethical red-teaming"
"summary of the relevant findings"