- Articles 12 to 14 and Annexes V to VIII define closure reports, replay and purple teaming, remediation-plan content, and attestation content.
"Content of the red team test report"
A source-linked runbook structure for financial entities that must perform DORA threat-led penetration testing.
Use it to organise authority touchpoints, critical-function scoping, tester and threat-intelligence controls, active red-team testing, closure reports, remediation evidence, and attestation records.
Structured answer sets in this page tree.
Cited legal and guidance references.
DORA TLPT is not a generic penetration-test checklist. Under Article 26, identified financial entities must run advanced threat-led penetration testing on live production systems supporting several or all critical or important functions, with scope validation, risk controls, reports, remediation plans, and authority attestation. This runbook turns those requirements into a practical operating record without adding unsupported test steps. Timings in this page are source-linked; verify current legal source language before implementation decisions.
The scope section should list all critical or important functions considered for TLPT, not only the functions selected for testing. For each function, record whether it is included, why it is included or excluded, the supporting ICT systems, outsourced or contracted ICT services, relevant jurisdictions, and preliminary flags tied to confidentiality, integrity, authenticity, or availability.
DORA requires each TLPT to cover several or all critical or important functions and to be performed on live production systems supporting them. The precise scope is determined by the financial entity's assessment and validated by the competent authority or TLPT authority. Where ICT third-party providers support in-scope functions, the runbook should show how their participation is covered, including whether pooled TLPT is being considered where direct provider participation could affect other customers or confidentiality.
Use the provider-control section to prove that the threat intelligence provider and testers meet DORA and TLPT RTS requirements before contracting or assigning them. The TLPT RTS expects an external threat intelligence provider, and it sets detailed evidence expectations for skills, references, certifications, insurance, independence, conflicts of interest, secure restoration, and prohibited conduct.
The testing section should keep three records together: the targeted threat intelligence report, the scenario-selection record, and the red team test plan. The threat intelligence provider must produce concrete, actionable, contextualised target and threat intelligence. The control team lead selects at least three scenarios using the provider's recommendation, test-manager input, tester feasibility judgement, and the entity's size, complexity, and risk profile. No more than one selected scenario may be non-threat-led.
The closure section should not stop at the red team report. After active red-team testing ends, the control team informs the blue team, testers submit the red team test report, the blue team submits its report, and the parties replay offensive and defensive actions. The control team also runs purple teaming on jointly identified topics based on vulnerabilities found during testing and, where relevant, topics not fully tested during the active phase.
After the TLPT authority has assessed the blue team and red team reports, the financial entity submits the summary report of relevant findings for approval, then provides the remediation plans and documentation required under DORA. The remediation plan should track each finding to the shortcoming, remediation measure, priority and expected completion, root cause, responsible staff or function, and risks of not implementing the measure. Keep the attestation and notify the relevant competent authority of the attestation, summary findings, and remediation plans.
Use the cited sources listed here to verify obligations and the supporting evidence requirements.
Verify the following areas from the cited sources: TLPT scope, testers, reports, remediation, and authority evidence using the cited sources on this page.
Review the authority touchpoints, provider evidence, testing records, and remediation fields needed for your DORA TLPT runbook.
"Content of the red team test report"
"Adopting TIBER-EU will help fulfil DORA requirements"
"summary of the relevant findings"