main logo icon

Published on

July 8, 2026

|

12 min read

What a DORA Threat-Led Penetration Test Costs in 2026 (and What Drives the Price)

A DORA threat-led penetration test (TLPT) is a multi-month, dual-provider program run by accredited external testers, so it is priced far above a standard test. Here is the 2026 cost-driver breakdown for a financial entity budgeting before an RFP.

Arafat Afzalzada

Arafat Afzalzada

Founder

Advisories

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

A DORA threat-led penetration test (TLPT) is not a bigger penetration test and it is not priced like one. It is a regulated, intelligence-led program run over months by two accredited external providers against live production systems, mandated at least every three years for designated financial entities (DORA Article 26). That structure, not a day rate, sets the price. As third-party market context, one European TLPT provider guide puts realistic full-cycle budgets starting around EUR 150,000 and scaling higher with scope (slashsec, 2026), well above the £18,000 to £48,000 a standard red team exercise runs in the UK market (EJN Labs, 2026). Six drivers move a TLPT number: the count of critical or important functions in scope, program duration and red-team days, threat-intelligence depth, the requirement for dual accredited external providers, remediation and purple-team work, and cross-border or multi-authority coordination. Scoping choices change the total. Pooled testing can share cost across entities on a shared ICT provider, significant credit institutions must use external testers only, and where internal red-teamers run the test the threat-intelligence provider must still be external (DORA Articles 26 to 27). Stingrai prices every engagement to scope; current packages live on the pricing page. A hybrid model, where the Snipe agent adds autonomous web-application depth and senior humans run the threat-led scenarios, keeps day-count efficient without narrowing coverage.

A DORA threat-led penetration test is not a bigger penetration test, and it is not priced like one. It is a regulated, intelligence-led program run over months by two accredited external providers against live production systems, mandated at least every three years for designated financial entities under Article 26 of the Digital Operational Resilience Act. That structure, not a headline day rate, is what sets the price. As third-party market context, one European TLPT provider guide puts realistic full-cycle budgets starting around EUR 150,000 and scaling significantly higher with scope (slashsec, 2026), well above the £18,000 to £48,000 a standard red team exercise runs over three to eight weeks in the UK market (EJN Labs, 2026).

Here is the direct answer to how much a DORA TLPT costs and what drives the price. A TLPT is priced as a multi-month program, so the total tracks the work the program demands rather than a per-asset line item. Six factors move it: the number of critical or important functions in scope, program duration and red-team days, threat-intelligence depth, the mandate for dual accredited external providers, remediation and purple-team work, and any cross-border or multi-authority coordination. Stingrai prices every TLPT engagement to scope, because no two designations need the same coverage; current packages and scoping live on the Stingrai pricing page. This post is written for compliance, risk, and security leaders at designated financial entities who need to budget a TLPT before they write an RFP.

This is the Stingrai team's 2026 cost-driver reference for DORA TLPT. Structural cost drivers trace to primary regulatory sources: DORA Articles 26 and 27, the TLPT Regulatory Technical Standards in Commission Delegated Regulation (EU) 2025/1190, and the ECB TIBER-EU framework. Every cost figure is clearly labeled third-party market context, drawn from named provider guides, not a Stingrai quote. Market and regulatory content is current to July 2026; where a figure could not be traced to a named source, it was dropped rather than estimated, and every claim links to its source so any statement can be audited inline.

Hero Dora Tlpt Cost 2026

TL;DR: what drives a DORA TLPT price

  • The unit of cost (2026): a multi-month program, not a per-asset test. Price tracks scope, duration, and the two accredited providers the framework requires, not a single day rate (ECB TIBER-EU).

  • Third-party full-cycle context (2026): realistic TLPT budgets start around EUR 150,000 and scale higher with scope, per one European provider guide (slashsec, 2026).

  • The reference point it beats (2026): a standard UK red team exercise runs £18,000 to £48,000 over three to eight weeks (EJN Labs, 2026). A TLPT sits well above that because it lasts months, not weeks.

  • Two providers are mandatory: a threat-intelligence provider and a red team provider are both required under TIBER-EU, so you buy two specialist engagements, not one.

  • External and accredited is the rule, not the upgrade: significant credit institutions must use external testers only, and internal-tester programs must still contract external testers at least every third test (DORA Article 26).

  • The accreditation bar is priced in: testers must show threat-intelligence, penetration-testing, and red-team expertise, hold accreditation-body certification or adhere to formal codes of conduct, provide independent assurance, and carry professional indemnity insurance (DORA Article 27).

  • Scope is production and critical functions, on a repeating cycle: each test must cover several or all critical or important functions on live production, at least every three years, so budget it as a recurring program (DORA Article 26).

  • Pooled testing can share the bill: where a shared ICT third-party provider is in scope, entities may run a joint test under a written arrangement, splitting cost across participants (DORA Article 26).

  • The stakes justify the spend (2025): the global average breach cost US$4.44M last year (IBM, 2025), against a penetration testing market growing from US$2.72B in 2026 to US$5.54B by 2031 at a 15.29 percent CAGR (Mordor Intelligence).

Key takeaways

A TLPT is priced as a program, not a test. Because the work runs for months and requires two specialist providers, the cost is set by scope and duration, not by a per-application rate. The biggest lever a buyer controls is the number of critical or important functions in scope and the length of the active red-team window, both defined during scoping under DORA Article 26.

Duration is the driver buyers underestimate most. A standard red team runs three to eight weeks (EJN Labs, 2026); a TLPT runs six to nine months of active testing inside a full procurement-to-attestation cycle of roughly nine to fourteen months (slashsec, 2026). Every extra week of stealthy, intelligence-led operating is more senior time on the invoice.

Accreditation is not an optional premium, it is the baseline. DORA requires certified or code-bound external testers with independent assurance and professional indemnity insurance (DORA Article 27). In the broader UK market, accredited testing already commands a 20 to 40 percent premium over non-accredited providers (EJN Labs, 2026); under DORA that assurance is mandatory, so it is priced into every quote.

Two of the biggest savings are structural, not negotiated. Pooled testing lets entities on a shared ICT provider split a single test, and continuous adversary emulation between cycles keeps the mandated test a checkpoint rather than a first look (DORA Article 26). Both cut the marginal cost of the formal cycle far more than haggling a day rate.

Methodology

Structural cost drivers in this reference trace to primary regulatory sources: DORA Articles 26 and 27, source of the three-year cadence, the critical-function scope, the external-tester rules, the pooled-testing provision, and the tester-qualification bar; the TLPT Regulatory Technical Standards in Commission Delegated Regulation (EU) 2025/1190, applicable since 8 July 2025; and the ECB TIBER-EU framework, source of the dual-provider requirement and the preparation, testing, and closure phases. Cost and duration ranges come from two clearly labeled third-party market guides, slashsec (2026) for the full-cycle TLPT budget and durations and EJN Labs (2026) for standard UK red team and day-rate context; these are market context, not Stingrai pricing. Risk framing uses the IBM Cost of a Data Breach Report 2025 and the Mordor Intelligence penetration testing market report. The research pass closed on 8 July 2026. Figures that could not be matched to a named source were dropped rather than estimated, and Stingrai's own commercial terms are routed to the pricing page.

How much does a DORA TLPT cost in 2026?

There is no list price, and any provider that quotes one before scoping is guessing. The honest answer is a range anchored to program scale. As third-party context, one European TLPT provider guide states that "realistic budgets start at around EUR 150,000 and scale significantly higher based on scope" for a full TIBER-aligned DORA cycle (slashsec, 2026). For comparison, the same UK market that prices a full standard red team at £18,000 to £48,000 over three to eight weeks (EJN Labs, 2026) is pricing a fundamentally shorter, single-provider exercise. A TLPT is longer and structurally different, which is why it costs more.

The structural reason sits in the framework. A TIBER-EU test, the methodology DORA adopts, requires two mandatory service providers, a threat-intelligence provider that profiles realistic adversaries and a red team that executes the simulated attack (ECB TIBER-EU). You are not buying one engagement. You are buying a bespoke intelligence phase and a red-team phase, wrapped in a controlled, supervised program that runs for months and ends in supervisory reporting. The next sections break down where that money goes and what moves it.

Dora Tlpt Cost Anatomy

The six cost drivers of a DORA TLPT

Every TLPT quote is the sum of the same decisions, ranked here by how much they typically move the total.

Dora Tlpt Cost Drivers

1. Number of critical or important functions in scope

DORA requires that each test "cover several or all critical or important functions" of the entity, on live production systems (DORA Article 26). The count and complexity of those functions is the single biggest lever. Each additional critical function means more systems, more attack paths, more intelligence to gather, and more red-team time to reach an agreed objective. A firm with two in-scope functions and a firm with eight are budgeting for different programs, even before duration is discussed. Scoping this precisely, and defending the boundary with your competent authority, is where the largest savings are won or lost.

2. Program duration and red-team days

Duration is where a TLPT separates itself from a standard test on cost. The active red-teaming window alone runs at least twelve weeks in a typical cycle, with the full engagement spanning six to nine months (slashsec, 2026). Once procurement, scoping, and supervisory coordination are added, the end-to-end cycle commonly stretches to nine to fourteen months. Every week of stealthy, low-and-slow operating is senior tester time, and senior time is the largest line in the invoice. Buyers who compare TLPT quotes should compare the number of active red-team days and the objective first, not the day rate in isolation.

3. Threat-intelligence depth

The intelligence phase is a discrete, billable body of work, not a preamble. TIBER-EU requires a bespoke threat-intelligence report that profiles realistic adversaries and their tactics before the red team moves (ECB TIBER-EU), and DORA reinforces its independence: where internal testers run the red team, the threat-intelligence provider must be external to the financial entity (DORA Article 27). Deeper adversary profiling, more scenarios, and wider supply-chain reconnaissance all add to this phase. It is one of the clearest places where a cheaper quote usually means a thinner intelligence product.

4. Dual accredited external providers

The framework requires two providers, and DORA requires both to clear a high accreditation bar. Testers must possess "specific expertise in threat intelligence, penetration testing and red team testing," be "certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks," provide independent assurance, and carry professional indemnity insurance (DORA Article 27). That assurance is not free. In the wider market, accredited testing already runs a 20 to 40 percent premium over non-accredited work (EJN Labs, 2026); under DORA it is mandatory. Buying two accredited specialist engagements rather than one general one is a structural cost of the regime.

5. Remediation, purple teaming, and replay

The test does not end when the red team stops. The closure phase includes reporting, a purple-team replay where red and blue teams walk the attack together, and remediation planning (ECB TIBER-EU). This is often where the most defensive value is created, so firms that want a thorough replay, detailed remediation guidance, and retesting of fixes will budget more here. Treating closure as a formality is a false economy: it is the phase that converts findings into resilience the supervisor can see.

6. Cross-border and multi-authority coordination

A TLPT is coordinated with the competent authority, and for groups operating across several EU jurisdictions that coordination multiplies. Mutual recognition and joint testing provisions in the TLPT RTS (Commission Delegated Regulation (EU) 2025/1190) reduce duplication, but aligning scope, timing, and reporting across authorities still adds program-management overhead borne by the control and white-team functions.

Scoping factors that change your TLPT number

Beyond the six drivers, several scoping choices move the total up or down before a single tester-day is booked.

Dora Tlpt Cost Scale Vs Standard
  • Internal versus external testers. Using internal red-teamers can shift cost, but the relief is limited: significant credit institutions must use external testers only, all internal-tester programs must contract external testers at least every third test, and the threat-intelligence provider must be external regardless (DORA Articles 26 to 27). Budget for external specialists as the default.

  • Pooled testing. Where a shared ICT third-party provider is in scope and testing it individually would risk harming other clients' service quality, entities may run a joint pooled test under a written arrangement (DORA Article 26). Splitting one test across participants is one of the few ways to genuinely lower the per-entity cost of the formal cycle.

  • Control and white-team overhead. A small internal control team must run the test discreetly while the wider blue team stays unaware. That is real internal cost, in senior staff time, that sits outside the provider invoice and is easy to forget at budgeting time.

  • Readiness of the estate. A production environment that is well mapped, with critical functions clearly documented, shortens scoping and intelligence work. A firm still discovering its own critical-function dependencies during scoping will pay for that discovery in program time.

  • Cadence planning. Because the obligation repeats at least every three years (DORA Article 26), the cheapest programs are the ones that treat each cycle as a checkpoint. Firms that run continuous adversary emulation between cycles arrive at the formal test with fewer surprises, and fewer surprises mean fewer expensive remediation cycles.

What this means for a financial-entity buyer

Budget the TLPT as a recurring, multi-month program with two specialist providers, not as a single line item, and start procurement early. Provider capacity concentrates when many designated entities hit their first cycle in the same window, and early procurement is a genuine cost and quality advantage, not just good hygiene. Our companion guides on how to choose a threat-led penetration testing provider and the DORA TLPT 2026 readiness playbook cover selection and lifecycle in depth, and the generic red team engagement cost breakdown covers non-regulated exercises.

The most reliable way to control the formal cycle is to stay test-ready between cycles. Stingrai is a CREST-accredited penetration testing service provider whose red teaming and continuous PTaaS programs let designated firms treat the mandated TLPT as a scheduled checkpoint rather than a scramble. Stingrai's testing supports the operational-resilience evidence a DORA program needs, produced by senior testers who run the threat-led scenarios. On the technical side, the Snipe agent adds autonomous web-application depth, hunting complex classes such as broken authorization, IDOR, and business-logic flaws, while senior humans run and validate the adversary scenarios, keeping the day-count efficient without narrowing coverage. For current packages and scoping, see the Stingrai pricing page.

Frequently asked questions

How much does a DORA threat-led penetration test cost in 2026?

There is no fixed list price, because a TLPT is scoped to the entity. As third-party market context, one European provider guide puts realistic full-cycle budgets starting around EUR 150,000 and scaling significantly higher with scope (slashsec, 2026). That sits well above the £18,000 to £48,000 a standard UK red team runs (EJN Labs, 2026), because a TLPT is a months-long, dual-provider program against live production, not a single short exercise. Stingrai scopes each engagement individually; see the pricing page.

Why is a TLPT more expensive than a standard penetration test or red team?

Three structural reasons. It runs for months, not weeks, so it carries far more senior tester time (slashsec, 2026). It requires two mandatory providers, a threat-intelligence provider and a red team, rather than one (ECB TIBER-EU). And it demands accredited external testers with independent assurance and professional indemnity insurance, a bar that carries a premium (DORA Article 27).

What is the single biggest driver of TLPT cost?

The combination of scope and duration. Each critical or important function in scope adds systems, intelligence, and red-team time, and DORA requires several or all critical functions to be covered on live production (DORA Article 26). Because the active red-team window runs at least twelve weeks and the full cycle six to nine months (slashsec, 2026), duration turns scope decisions into large cost differences.

Can I reduce the cost of a DORA TLPT?

Legitimately, yes, and mostly through structure rather than negotiation. Pooled testing lets entities on a shared ICT provider split one test under a written arrangement (DORA Article 26). Tight, well-documented scoping of critical functions shortens the intelligence and scoping phases. And continuous adversary emulation between cycles means fewer costly surprises during the formal test.

How often do I have to pay for a TLPT?

At least every three years for designated entities, and supervisors can require more frequent testing based on risk (DORA Article 26). Budget it as a recurring program rather than a one-time project, and factor in the internal control and white-team time that recurs with each cycle.

Do I need two separate providers, and does that raise the price?

Yes. TIBER-EU, the framework DORA adopts, requires both a threat-intelligence provider and a red team provider (ECB TIBER-EU). Where internal red-teamers are used, the threat-intelligence provider must still be external to the entity (DORA Article 27). You are buying two specialist engagements, which is part of why a TLPT costs more than a single red team.

Does DORA require external testers, or can we use our own team?

Both are possible, with limits. Significant credit institutions must use external testers only, and any internal-tester program must contract external testers at least every third test (DORA Article 26). Testers must also meet the qualification, certification, assurance, and insurance requirements of DORA Article 27, so accredited external specialists are the default assumption for budgeting.

When should we start budgeting and procuring for a TLPT?

Early. A full cycle from procurement to supervisory reporting runs roughly nine to fourteen months (slashsec, 2026), and accredited-provider capacity tightens when many entities reach their first cycle together. Confirm your likely designation, map your critical functions, and begin provider conversations well before the deadline year to avoid scarcity pricing.

References

  1. European Union. Digital Operational Resilience Act (Regulation (EU) 2022/2554), Article 26: Advanced testing of ICT tools, systems and processes based on TLPT. https://www.digital-operational-resilience-act.com/Article_26.html. Establishes the at-least-every-three-years TLPT obligation, critical-function scope, live-production requirement, external-tester rules, and pooled testing.

  2. European Union. Digital Operational Resilience Act (Regulation (EU) 2022/2554), Article 27: Requirements for testers for the carrying out of TLPT. https://www.digital-operational-resilience-act.com/Article_27.html. Sets the tester qualification, certification, independent-assurance, and professional-indemnity requirements, and the external threat-intelligence-provider rule.

  3. European Commission. Commission Delegated Regulation (EU) 2025/1190 (TLPT Regulatory Technical Standards). Applicable 8 July 2025. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202501190. Specifies how TLPT is conducted, including mutual recognition and joint testing provisions.

  4. European Central Bank. TIBER-EU: Threat Intelligence-based Ethical Red Teaming framework. https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html. Defines the dual-provider model, the preparation, testing, and closure phases, and the not-pass-or-fail assessment approach that DORA TLPT adopts.

  5. slashsec. TIBER-AT and DORA TLPT: phases and cost. 2026. https://slashsec.at/en/docs/tiber-at. Third-party provider guide stating that realistic full-cycle TLPT budgets start around EUR 150,000 and scale with scope, with phase durations.

  6. EJN Labs. Penetration Testing Cost UK. 2026. https://ejnlabs.com/penetration-testing-cost-uk/. Third-party UK market guide for senior CREST day rates, standard red team exercise cost, and the accreditation premium.

  7. IBM. Cost of a Data Breach Report 2025 (with the Ponemon Institute). https://www.ibm.com/reports/data-breach. Source of the US$4.44M global average breach cost.

  8. Mordor Intelligence. Penetration Testing Market. 2026. https://www.mordorintelligence.com/industry-reports/penetration-testing-market. Source of the US$2.72B to US$5.54B market projection at a 15.29 percent CAGR from 2026 to 2031.

0 views

0

X

Related reading

TIBER-EU vs CBEST vs DORA TLPT: Which Threat-Led Test Your Regulator Actually Requires
Advisories

TIBER-EU vs CBEST vs DORA TLPT: Which Threat-Led Test Your Regulator Actually Requires

TIBER-EU vs CBEST vs DORA TLPT compared: authority, scope, mandatory vs voluntary, cadence, and how to tell which threat-led test applies to you.

10 min read

Red Team Objectives and Crown Jewels: How to Scope by Outcome Before Your RFP
Advisories

Red Team Objectives and Crown Jewels: How to Scope by Outcome Before Your RFP

Scope a red team by objectives and crown jewels before you write the RFP. A buyer's step-by-step guide with an objectives worksheet and sector examples.

10 min read

Autonomous Pentest Contracts: The Clauses That Make an SLA Enforceable
Advisories

Autonomous Pentest Contracts: The Clauses That Make an SLA Enforceable

Paste-ready SOW clauses for a continuous autonomous pentest SLA: validated-PoC acceptance, human sign-off, retest windows, audit rights, service credits.

10 min read

Contents

X