← Back to the cybersecurity blog

TLPT under DORA in Spain: what the regulation demands and what the TIBER-ES guide still omits

By Daniel O'Grady · CIO y socio fundador · Published: 20 August 2026 · Updated: 20 August 2026
TLPT under DORA in Spain

Spain's TIBER-ES implementation guide is dated January 2022 and never mentions DORA. It is signed by the Banco de España, the securities regulator CNMV and the insurance and pensions authority DGSFP, and it states that participation is voluntary: institutions are invited to take the tests, not obliged to. Since January 2025, for entities designated by their competent authority, that same procedure has not been voluntary at all.

Anyone preparing a first TLPT from the national guide alone is working off the pre-DORA map. Three regulatory layers now coexist and do not say the same thing: the EU regulation, the TIBER-EU framework the Eurosystem updated in 2025, and the Spanish guide implementing it. The gap shows up in the tender and in the timetable.

This matters beyond Spain. Attestations issued under a national TIBER framework travel between competent authorities, so a cross-border group running its exercise in Madrid is producing a document its supervisors elsewhere will read. Get the procedure wrong and the authority can refuse to validate it, after half a year of work.

What DORA actually requires

Article 26 sets the regime. Entities identified by their competent authority carry out TLPT at least every 3 years, and that authority may reduce or increase the frequency according to risk profile and operating circumstances. Each test covers several or all critical or important functions and runs against live production systems. The entity identifies every system, process and technology supporting those functions, including anything outsourced, and competent authorities validate the resulting scope.

Three provisions inside that same article get skipped at the design stage and cost money later.

  • Third parties fall inside the scope. Where an ICT service provider supports a critical function, the entity takes the measures needed to secure that provider's participation and retains full responsibility for compliance. Third-party risk management stops being an annual questionnaire right here.
  • Pooled testing exists. Where a provider's participation could adversely affect the quality or security of services it delivers to customers outside the regulation's scope, or the confidentiality of that data, provider and entity may agree in writing that the provider contracts the testing team directly, for a pooled exercise directed by one designated financial entity and involving several participants.
  • The attestation is portable. Once the exercise closes and reports and remediation plans are agreed, the authority issues an attestation enabling mutual recognition between competent authorities.

Article 27 governs who may be hired. Testers must demonstrate the highest suitability and reputability, show specific expertise in threat intelligence, penetration testing and red team testing, hold certification from an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks, provide independent assurance or an audit report on the sound management of the risks involved, and carry professional indemnity insurance covering misconduct and negligence.

Internal testers are permitted on three cumulative conditions: approval by the competent authority, verification by that authority that the entity has sufficient dedicated resources and has avoided conflicts of interest across design and execution, and an external threat intelligence provider. Article 26 adds two limits: external testers must be contracted every three tests, and credit institutions classified as significant under the Single Supervisory Mechanism may only use external testers.

The technical detail is set by Commission Delegated Regulation (EU) 2025/1190 of 13 February 2025, published in the Official Journal on 18 June and in force since July 2025. It establishes the criteria for determining which entities are obliged to test, the requirements governing internal testers, and the demands on scope, methodology, testing phases, results and corrective measures.

TIBER-ES: who leads, who answers and who can stop it

The Banco de España owns the national framework and runs it through the TIBER Cyber Team, which also includes the CNMV and the DGSFP. Coordination of each exercise falls to whichever authority supervises the entity under test, and the TCT appoints a Team Test Manager per engagement.

There is an asymmetry in how responsibility is split, and it repays a hard look. The TCT does not supervise: the guide states that it "plays no supervisory role, and its actions are not tied to the imposition of requirements where weaknesses are identified" (our translation), and it is not liable for damage caused during execution. Yet among its functions is "invalidating tests not carried out in accordance with the requirements of TIBER-ES and TIBER-EU" (our translation). No supervision, no liability, and the power to write off six months of work. Which is why the provider's insurance policy is a clause you negotiate, not an annex you sign.

On the entity's side, the White Team answers for risks being identified, analysed and mitigated across the exercise, and may abandon execution where objective circumstances justify it. Defenders know nothing until the closure phase; if the Team Test Manager suspects they know and are manipulating results, the test may not be validated.

On White Team composition the document is meticulous: a small number of members, confidentiality towards the rest of the organisation, executive and management profiles, and among them cybersecurity experts and the owners of incident escalation and notification processes. That last point is not there for symmetry. Somebody has to stop a simulated incident from triggering the real incident response process, and with it the mandatory notifications to outside parties, police included.

Six months, if the tender runs smoothly

Preparation, 4 to 6 weeks. Testing, 16 to 18. Closure, 4. The guide publishes those durations, and they remain the only public reference of the kind for an exercise in Spain.

One caveat before they go into a plan. The ECB notes that the delegated regulation introduced strict timelines for completing the deliverables, now built into the updated TIBER-EU. The 2022 figures are useful for sizing the effort, not for setting contractual milestones.

Inside the testing phase, the document allocates 5 weeks to intelligence gathering, 1 or 2 to the red team test plan and 10 to 12 to execution. Preparation expressly excludes procurement time, which in market practice is not trivial. Across the three phases, the exercise runs six to seven months from kick-off, tender aside. The document also fails to reconcile with itself: the testing steps total 16 to 19 weeks against the 16 to 18 declared for the phase. The higher sum is the one to take to the board.

The deliverables that decide whether the exercise counts

The documentary chain has nine pieces and a sequence. It opens with the Generic Threat Landscape, the sector picture the TCT shares with the intelligence provider when one is available. On that base the external provider produces the Targeted Threat Intelligence: systems supporting critical functions, actors, recent attack examples and likely scenarios. The White Team validates it alongside the TCT, and the guide marks red team validation of the scenarios as the critical step.

With the TTI closed, the red team writes its test plan: scenarios, objectives to capture, fallback routes if the first one fails. Execution follows, and two reports come out of it. The Red Team Test Report has a hard deadline, two weeks from the end of the test, and goes to the White Team and the TCT. The Blue Team Test Report is written from it and must be finished before the exercise is replayed.

Red team and blue team run the replay together, walking back through the steps; a full replay is not strictly necessary, nor does it have to happen in production. Out of that come the two pieces outsiders see: the action plan, drawn up by the entity and agreed with the providers and the TCT before it reaches the supervisory authority, and the test summary report, stripped of technical detail because that stays inside.

Last comes the attestation, and everything hinges on it. The White Team certifies that the test met the framework in a document signed by the board and the providers, which the TCT must validate for mutual recognition to apply. Without that validation, what remains is an expensive red team.

One further element of the procedure rarely appears in tenders and it decides what the result is worth. During execution the red team may ask the White Team to disable internal barriers or controls to unblock progress. It is anticipated for cases where defenders successfully protect an objective, or where both sides judge an intermediate step trivial.

The guide does not leave it open: if that assistance is granted, it "must be reflected in the reports, since results arising from the disconnection of a control or security mechanism must be placed in a context of their own" (our translation). A report that presents post-switch-off activity as a finding, and says nothing about the switch-off, says nothing about how that entity defends itself.

Where the Spanish guide has fallen behind

On 11 February 2025 the Eurosystem updated TIBER-EU to align it with the DORA regulatory technical standards on TLPT. The ECB note lists the changes; three land directly on anyone working from the Spanish guide.

  • The White Team becomes the Control Team, for terminological consistency with DORA. TIBER-ES and the ECB documents it points to still say White Team.
  • Purple teaming becomes mandatory under TIBER-EU, as the delegated regulation prescribes. In the TIBER-ES guide, the Purple Team is optional.
  • Process steps are aligned with the deliverables set by the delegated regulation, which introduced strict timelines for completing them. The timelines sit in TIBER-EU already and appear nowhere in the 2022 guide.

Norton Rose Fulbright's regulatory tracker notes that the ECB went on to publish, in November 2025, a guide to how it adopts and implements TIBER-EU for threat-led testing at significant institutions under the Single Supervisory Mechanism.

One question has no public answer and it affects live projects: whether mandatory purple teaming reaches an exercise contracted before February 2025 is clarified neither in the ECB note nor in the Spanish guide. We work on the assumption that it does, because getting that wrong costs a joint working session while getting it wrong the other way leaves an attestation hanging. It remains an assumption.

None of that invalidates the national guide, which remains the reference on governance and division of responsibility in Spain. But the published guide is still the January 2022 edition, and the Banco de España's own page continues to describe the framework in voluntary terms and to point at the ECB's White Team Guidance. A mandatory TLPT requires reading all three layers at once.

The mistakes that invalidate a TLPT

  1. Trimming the scope until outsourced critical functions fall outside it. Article 26 requires identifying the systems supporting those functions even when contracted to a third party, and authorities validate the scope. The guide even suggests considering a representative of the outsourcing provider for the White Team.
  2. Assembling a White Team with no authority to stop. If nobody in the room can abandon the exercise or control incident escalation, the organisation carries the operational risk of the test without having decided to.
  3. Buying threat intelligence and red teaming from the same provider without checking resources. The guide allows it and notes that separating the two is preferable where a single provider cannot guarantee sufficient technical and human resources. With internal testers, DORA requires external intelligence regardless.
  4. Nobody wrote down that the control was switched off. Without that line in the report, the finding is an artefact of the exercise rather than a weakness of the entity.
  5. The defenders find out. It happens more than people admit, it is the failure the guide ties expressly to non-validation, and it rests entirely on White Team discipline.
  6. The budget leaves out procurement. Contracting the providers means agreeing commercial terms, scope, execution limits, prohibited activities, resources, liabilities and, where relevant, insurance. Procurement time sits outside the guide's published calendar.
  7. Reading the attestation as a pass mark. The framework's purpose, the guide says, is to understand an institution's weaknesses and strengths, not to grade it. Costs and risks fall entirely on the entity, never on the authority.

In the procurement processes Hard2bit supports, the first meeting rarely concerns a provider's methodology. It concerns which of those seven points already has a written answer, and whose signature sits under it.

What the board signs and cannot delegate to the CISO

Two board signatures bracket the exercise. The first is formal approval of the preliminary scope document. The second is the closing attestation. Between them, the board has accepted that real attacks will run against production systems and that the outcome reaches the supervisor as an action plan and a summary report. Neither signature is delegated.

For a board already tracking cyber resilience indicators, a TLPT supplies the most complete empirical evidence of whether the organisation detects and responds to an adversary who gives no warning. Every scenario the red team executed without raising an alert marks a missing analytic, which is direct input for detection engineering work. The exercise also leaves a record of the human process: who escalated, to whom, and how quickly. The same material gets examined when a crisis enters its first 24 hours.

How far this exercise actually goes

The document sets no quantitative thresholds for what makes an institution significant, and no formal application procedure with deadlines: designation criteria are applied by the competent authority under the delegated regulation, not by the national guide. Nor are there cost figures. Neither the guide nor the Banco de España's page publishes what an exercise costs, and the ranges circulating in the market have no public source behind them.

The framework carries a further warning worth reading before anything is contracted. The tests are advisable only for institutions that already hold a certain level of cyber resilience maturity, because less mature ones will likely show weaknesses detectable through simpler exercises carrying lower cost and lower risk. A TLPT replaces neither a penetration test nor a conventional red team engagement: the framework takes both as given when it speaks of prior maturity.

A TLPT is run separately from the rest of the testing programme. Penetration testing methodologies and the criteria for reading a technical report still govern day-to-day work at a financial sector institution. A TLPT has a different buyer, different timescales and a different final reader.

Before the scope is signed

The distance between guide and regulation is not closed by reading more carefully. It is closed by deciding before signing, and it fits in a three-column table: what DORA says, what the updated TIBER-EU says and what the TIBER-ES guide says about each decision in the project. Where all three agree, the answer is clear; where they do not, the regulation prevails.

DORA has applied since January 2025 and the minimum TLPT frequency is three years, so the first cycle is already running. Neither the guide nor the Banco de España's page publishes which entities have been designated. Whoever is on that list hears it from their supervisor; whoever suspects they might be has a call to make before they have a tender to write. That is the starting point any cybersecurity firm with DORA experience should raise, ahead of methodology, the threat intelligence capability or the composition of the offensive team.

This article summarises the regulatory framework and procedure as published in August 2026, drawing on the text of DORA, Commission Delegated Regulation (EU) 2025/1190 and the TIBER-ES implementation guide. Designations of obliged entities change, and so do deadlines and framework versions: checking with the competent authority and against current Banco de España and ECB documentation is always the step before any decision on a specific exercise.

Frequently asked questions

What is a TLPT and how does it differ from a normal red team?

A TLPT is a threat-led penetration test that DORA imposes on financial entities designated by their competent authority. It differs from a conventional red team engagement in its client and its procedure: authorities validate the scope, it runs against live production systems, it requires an external threat intelligence provider, it produces a fixed documentary chain and it ends in an attestation signed by the board and validated by the supervisor.

Which entities are required to carry out TLPT?

Those identified by their competent authority on the basis of impact-related factors on the financial sector, possible financial stability concerns, and their specific ICT risk profile and level of technological maturity. It is not a blanket obligation across the financial sector. The identification criteria are developed in Commission Delegated Regulation (EU) 2025/1190.

How often must a TLPT be performed?

At least every three years under Article 26 of DORA. The competent authority may require the entity to reduce or increase that frequency where necessary, based on its risk profile and operating circumstances.

Can a TLPT be run with an in-house red team?

DORA permits it on three conditions: approval by the competent authority, verification by that authority that the entity has sufficient dedicated resources and has avoided conflicts of interest across design and execution, and an external threat intelligence provider. External testers must also be contracted every three tests, and credit institutions classified as significant under the Single Supervisory Mechanism may use external testers only.

Who coordinates TLPT in Spain?

The Banco de España owns the TIBER-ES framework and runs it through the TIBER Cyber Team, which also includes the CNMV and the DGSFP. Coordination of each exercise falls to the authority supervising the institution concerned, and the TCT appoints a Team Test Manager for every test.

How long does a TLPT take under TIBER-ES?

The implementation guide estimates four to six weeks for preparation, sixteen to eighteen for the testing phase and four for closure. Six to seven months in total, and the guide itself warns that preparation excludes the time needed to procure the intelligence and red team providers.

What is a TLPT attestation for?

It is the document in which the White Team certifies that the exercise was run in line with the framework. The institution's board and the providers sign it, and the TIBER Cyber Team must validate it. Once validated, it enables mutual recognition of the test before authorities in other jurisdictions that have adopted TIBER-EU. It is not a pass or fail grade.

Where has the 2022 TIBER-ES guide fallen behind?

In February 2025 the Eurosystem updated TIBER-EU to align it with the DORA technical standards. Three relevant changes: the White Team is renamed the Control Team, purple teaming becomes mandatory, and the process steps align with the deliverables set by the delegated regulation, which introduced strict timelines. The January 2022 Spanish guide keeps the old naming, treats the Purple Team as optional and carries none of those timelines. The national guide remains valid on governance and deliverables, but it has to be read alongside the regulation and the current European framework.

Not sure which EU rules reach you — or what meeting them costs?

NIS2 and DORA reach further than most companies expect, usually through a contract with a customer already in scope. We work out what genuinely applies to you in a 30-minute call with a technical consultant, not a salesperson, and you leave with priorities ranked and a price range. With what comes out of that call, we turn it into a fixed proposal. ISO 27001, NIS2, DORA and ENS — Spain's framework for suppliers to the public sector.

If your situation is different, tell us anyway — we also take one-off questions on cybersecurity and regulatory compliance.

Based in Spain · Working across the EU and LATAM · ENS High · ISO 27001 · We usually reply in under 24 business hours