Threat-led penetration testing (TLPT) is intelligence-led red teaming that a financial regulator mandates or strongly recommends to prove an institution can withstand a real, targeted adversary rather than a checklist scan. As of 2026 at least a dozen national and regional frameworks are live, and which one governs your firm is decided by your regulator, not by your procurement team. EU entities answer to DORA TLPT delivered through TIBER-EU. UK firms run CBEST or STAR-FS. Canada uses OSFI's I-CRT. Hong Kong uses HKMA iCAST, Saudi Arabia uses SAMA FEER, Australia uses CORIE, and Singapore uses the ABS and MAS AASE guidelines.
This post is a verified reference for multi-jurisdiction CISOs and compliance leads who need two answers fast: which threat-led penetration testing framework applies in each country where they operate, and whether a single test can satisfy more than one regulator. Every framework below is attributed to its issuing authority, from the European Central Bank and the Bank of England to the Hong Kong Monetary Authority, the Saudi Central Bank, Australia's Council of Financial Regulators, and Canada's OSFI.
The short answer: which framework applies to you
Your regulator picks the framework. If you are a bank, insurer, payment provider, market infrastructure operator or comparable critical entity, the framework is tied to your prudential supervisor in each jurisdiction where you hold that status.
European Union: DORA TLPT, the delivery mechanism for which is TIBER-EU.
United Kingdom (financial): CBEST for the largest systemic firms, STAR-FS for a broader population.
United Kingdom (other sectors): GBEST for central government, TBEST for telecoms.
Netherlands and other EU states: national TIBER implementations such as TIBER-NL, now feeding DORA TLPT.
Canada: OSFI Intelligence-led Cyber Resilience Testing (I-CRT).
Hong Kong: HKMA iCAST, the testing arm of the C-RAF.
Singapore: ABS and MAS Adversarial Attack Simulation Exercises (AASE).
Saudi Arabia: SAMA Financial Entities Ethical Red Teaming (FEER).
Australia: CORIE, run by the Council of Financial Regulators.
The nuance that follows is who exactly is in scope, whether the test is mandatory or voluntary, how often it must run, and what qualifications the testing providers need. That is where the frameworks diverge, and where the comparison matrix below earns its place.

Why the frameworks look so similar
They look similar because they share ancestry. The Bank of England launched CBEST in 2014 as the first regulator-driven, threat-intelligence-led testing scheme for systemically important financial firms. The European Central Bank generalised the model into TIBER-EU (Threat Intelligence-Based Ethical Red-teaming) in May 2018, giving national central banks a common template to localise. From there the pattern spread: the Netherlands stood up TIBER-NL, Australia adapted CBEST and TIBER into CORIE, Canada built I-CRT, and Gulf and Asian regulators wrote their own variants.
That common lineage is good news for anyone operating across borders. The vocabulary, the phases, the emphasis on realistic threat intelligence, and the bar for provider competence are broadly consistent from one framework to the next. The differences are in governance, legal force, and who selects the targets.
Key takeaways
The framework is assigned to you, not chosen by you. Scope is a function of your regulatory status in each market, most often systemic or critical financial-sector designation.
Mandatory versus voluntary is the sharpest dividing line. DORA TLPT, OSFI I-CRT and HKMA iCAST carry real obligation for in-scope firms, while TIBER-NL and AASE are framed as voluntary or guidance even though supervisors expect participation.
A single test rarely clears multiple regulators on its own. Inside the EU, TIBER-EU is explicitly designed for mutual recognition. Across regions, you reuse evidence rather than the approval.
The four-phase engagement model is nearly universal, which is what makes cross-framework evidence reuse practical in the first place.
Methodology and sources
This reference draws only on primary or issuing-authority material, verified in July 2026. Each framework is attributed to the body that publishes it: the European Central Bank for TIBER-EU; the European Supervisory Authorities and competent authorities for DORA TLPT under Article 26; the Bank of England with the PRA and FCA for CBEST and STAR-FS; the UK Cabinet Office for GBEST and DCMS with Ofcom for TBEST; De Nederlandsche Bank for TIBER-NL; the Hong Kong Monetary Authority for iCAST; the Association of Banks in Singapore with MAS for AASE; the Saudi Central Bank (SAMA) for FEER; Australia's Council of Financial Regulators for CORIE; and Canada's OSFI for I-CRT. Where a detail such as exact cadence or entity-selection threshold was not clearly stated in issuing-authority material, we describe it qualitatively rather than assert a precise figure. Full source links appear in the References section, so any claim here can be audited against the regulator that published it.
The global TLPT frameworks comparison matrix
The table below is the reference core. Read a row to understand a single framework, or read a column to compare one attribute across all of them.
Framework | Jurisdiction and authority | Who is in scope | Mandatory or voluntary | Cadence | Provider and threat-intel requirement | Cross-regulator reach |
|---|---|---|---|---|---|---|
DORA TLPT | EU-wide. European Supervisory Authorities and national competent authorities, under DORA Article 26 | Financial entities identified as significant by competent authorities (major banks, payment providers, market infrastructure above thresholds) | Mandatory for identified entities | At least once every three years, adjustable for risk profile | External testers required; threat intelligence external; every third test uses an external red team | Delivered via TIBER-EU; strongest mutual-recognition path inside the EU |
TIBER-EU | EU. European Central Bank with national central banks | Core financial infrastructure, extensible to other critical sectors | Voluntary adoption; now the delivery vehicle for mandatory DORA TLPT | Set by the adopting authority or by DORA | Accredited threat-intel and red-team providers meeting TIBER standards | Explicitly built to facilitate mutual recognition across adopting states |
CBEST | UK. Bank of England with the PRA and FCA | Systemically important UK financial institutions | Regulator-led; firms are selected by supervisors | Regulator-driven, periodic | CREST-accredited threat-intel and penetration-testing providers | Methodological basis for many other frameworks |
STAR-FS | UK. Bank of England with supervisory partners, accreditation via CREST | A broader population of UK financial firms below the CBEST cohort | Firm-led with regulator oversight; more scalable than CBEST | Firm-driven | Same CREST-accredited provider pool and consultant qualifications as CBEST | Aligns with CBEST within the UK |
GBEST | UK. Cabinet Office and the Government Security Red Team | UK central government departments and critical public services | Government-directed | Programme-driven | CREST STAR members | UK public-sector counterpart to CBEST |
TBEST | UK. DCMS and Ofcom | UK telecommunications providers | Regulator-directed under telecoms security duties | Programme-driven | CREST-accredited threat-intel and penetration-testing providers | UK telecoms counterpart to CBEST |
TIBER-NL | Netherlands. De Nederlandsche Bank | Financial sector and critical national infrastructure | Voluntary, no pass or fail; DNB now runs DORA TLPT for in-scope firms | Firm-driven | Providers meeting TIBER standards | National TIBER implementation, recognised across TIBER states |
HKMA iCAST | Hong Kong. Hong Kong Monetary Authority, within the C-RAF | Authorised institutions (banks); high and medium inherent-risk tiers | Mandatory for high and medium risk-tier institutions | Aligned to the C-RAF assessment cycle | HKMA-recognised threat-intel and red-team providers | Standalone Hong Kong regime |
AASE | Singapore. Association of Banks in Singapore, supported by MAS | Financial institutions in Singapore | Industry guidance; supervisors expect significant firms to participate | Guidance-driven | Qualified red-team providers | Standalone Singapore regime |
SAMA FEER | Saudi Arabia. Saudi Central Bank (SAMA) | Member organisations regulated by SAMA: Tier-1 banks, digital banks, payment providers, large fintechs | Regulatory expectation for the in-scope tier | SAMA-directed | SAMA-recognised red-team and threat-intel providers | Standalone Saudi regime |
CORIE | Australia. Council of Financial Regulators (RBA, APRA, ASIC, Treasury) | Systemically important Australian financial institutions | Regulator-coordinated targeted rollout | Programme-driven | Accredited providers | Adapted from CBEST and TIBER |
OSFI I-CRT | Canada. Office of the Superintendent of Financial Institutions | Systemically important banks (D-SIBs) and internationally active insurance groups (IAIGs); others case by case | Mandatory for in-scope FRFIs; OSFI initiates the assessment | Once during each three-year supervisory cycle | Qualified threat-intel and red-team providers | Standalone Canadian regime, methodologically aligned with TIBER and CBEST |
For a deeper EU-specific breakdown, see our companion piece on how TIBER, CBEST and DORA TLPT compare, and our detailed guide to DORA threat-led penetration testing. Canadian readers should start with our OSFI I-CRT walkthrough.

The shared engagement model
One reason cross-framework planning is feasible is that almost every regime runs the same four phases. Naming varies, but the structure holds.
Initiation and scoping. A small, confidential control group inside the firm defines the critical functions to be tested and agrees on rules of engagement with the supervisor.
Threat intelligence. A dedicated provider builds realistic threat scenarios grounded in the firm's actual adversaries, sectors and geography. This is what makes the test "threat-led" rather than generic.
Red team execution. Testers emulate those scenarios against live production systems, usually with only the control group aware, targeting people, processes and technology.
Closure and purple teaming. The red and blue teams reconcile the attack narrative, measure detection and response, and agree remediation.

Can one test satisfy several regulators?
This is the question that decides your testing budget when you operate across borders. The honest answer has three layers.
Inside the EU, largely yes. TIBER-EU was designed to "facilitate mutual recognition," in the ECB's own words, so a single TIBER-EU test that meets the DORA regulatory technical standards can serve the mandatory DORA TLPT for a cross-border group, coordinated through a lead authority. This is the cleanest case of one test clearing multiple supervisors.
Across regions, not automatically. A TIBER-EU test does not by itself discharge an HKMA iCAST, a SAMA FEER or an OSFI I-CRT obligation. Each of those regulators keeps its own lead-authority relationship, its own test-manager oversight, its own view of which critical functions matter locally, and its own provider-recognition rules. A framework in the CREST-accredited UK "BEST" family and a TIBER-standard EU test also apply different provider-qualification bars.
Evidence reuse is where the real saving lives. Because the frameworks share a lineage and a four-phase model, the threat-intelligence products, scoping artifacts, attack narratives and detection findings from one engagement transfer with modest rework into another regulator's template. Sophisticated groups run one well-scoped "anchor" test per cycle and map its deliverables to each supervisor, rather than commissioning fully independent exercises everywhere. You reuse the work, not the approval.

What this means for defenders
Map your regulatory footprint first. List every jurisdiction where you hold a systemic or critical designation, then match each to its framework using the matrix above. That list, not a testing calendar, drives scope.
Design the anchor test for reuse. Scope the most demanding applicable framework, usually DORA TLPT or OSFI I-CRT, so its evidence maps cleanly onto lighter regimes.
Separate threat intelligence from red teaming deliberately. Every framework treats intelligence-led scenario design as the load-bearing step; a generic red team without it will not satisfy a supervisor.
Keep the evidence audit-ready. Attack narratives, TTP-to-control mappings and detection timelines are what your supervisor and your board actually read.
Stingrai runs threat-led red team scenarios and adversary emulation that produce exactly this kind of evidence, and our work supports firms preparing DORA, CBEST-aligned and OSFI I-CRT engagements. As a CREST-accredited penetration testing firm based in Toronto and London, we build the attack narratives, TTP mappings and detection-and-response findings your compliance program needs. Our AI web-application agent, Snipe, handles the application-layer discovery, hunting complex flaws such as IDOR and broken authorization, while senior human testers drive the intelligence-led scenarios that these frameworks require. Explore our red teaming service, our web application penetration testing, and our PTaaS platform, or review packages on the pricing page.
Frequently Asked Questions
Which threat-led penetration testing framework applies in my country?
It depends on your regulator. EU financial entities fall under DORA TLPT delivered through TIBER-EU, UK financial firms under CBEST or STAR-FS, Canadian systemic banks and internationally active insurers under OSFI I-CRT, Hong Kong banks under HKMA iCAST, Saudi financial entities under SAMA FEER, Australian systemic firms under CORIE, and Singapore financial institutions under the ABS and MAS AASE guidelines. Your regulatory status in each market, not your preference, assigns the framework.
Can one threat-led penetration test satisfy multiple regulators?
Inside the EU, largely yes: TIBER-EU is explicitly designed to facilitate mutual recognition, so one DORA-aligned TIBER-EU test can serve several EU competent authorities for a cross-border group. Across regions it does not work automatically, because each regulator keeps its own oversight and provider rules. The practical saving comes from reusing threat-intelligence and red-team evidence from an anchor test across each regulator's template.
What is the difference between TLPT and a standard penetration test?
A standard penetration test checks a defined scope for vulnerabilities, often against a checklist. Threat-led penetration testing is intelligence-led: a dedicated provider first builds realistic scenarios from your actual adversaries, then a red team emulates them against live production systems to measure real detection and response. TLPT tests the organisation, not just the application.
Is DORA threat-led penetration testing mandatory?
Yes, for financial entities that competent authorities identify as significant. DORA Article 26 requires those entities to perform TLPT at least once every three years, adjustable for risk profile, with external testers and, on a recurring basis, an external red team. Our DORA TLPT guide covers the detail.
How often do these tests have to run?
Cadence varies by framework. DORA TLPT and OSFI I-CRT both work on roughly a three-year cycle for in-scope firms. Others, such as CBEST, STAR-FS and CORIE, are programme or regulator-driven rather than fixed to a published interval. Confirm the current cadence with your supervisor, as several frameworks were updated in 2024 and 2025.
Who can perform a threat-led penetration test?
Every framework requires competent, independent providers for both threat intelligence and red teaming, and most require formal recognition. The UK "BEST" family relies on CREST-accredited providers with specific consultant qualifications, while TIBER and DORA require providers that meet their own standards. Frameworks also expect the threat-intelligence and red-team roles to be delivered to a defined competence bar.
How do I choose a threat-led testing provider?
Match the provider to the framework you must satisfy, confirm they can deliver both intelligence-led scenario design and red team execution, and check they produce supervisor-ready evidence. Our guide to choosing a threat-led penetration testing provider walks through the criteria.
Does Stingrai run regulator-mandated threat-led tests?
Stingrai runs threat-led red team scenarios and adversary emulation, and our work supports firms preparing DORA, CBEST-aligned and OSFI I-CRT engagements by producing the attack narratives, TTP mappings and detection findings these frameworks call for. Stingrai is a CREST-accredited penetration testing firm; engagement of a specific regulator-recognised test panel is arranged per framework and jurisdiction.
References
European Central Bank. TIBER-EU Framework: Threat Intelligence-Based Ethical Red-Teaming. 2018, updated 2024 and 2025. https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html. Defines TIBER-EU, its mandatory and optional requirements, mutual recognition, and alignment with DORA.
European Supervisory Authorities and ECB. Digital Operational Resilience Act (DORA), Article 26, and the Regulatory Technical Standards on Threat-Led Penetration Testing. 2024 to 2025. https://www.crest-approved.org/threat-led-penetration-testing-tlpt-under-dora-what-financial-institutions-need-to-know/. Sets who is in scope, the three-year cadence and provider requirements.
Bank of England. CBEST Threat Intelligence-Led Assessments Implementation Guide. https://www.bankofengland.co.uk/financial-stability/operational-resilience-of-the-financial-sector/cbest-threat-intelligence-led-assessments-implementation-guide. Describes CBEST scope, governance and provider accreditation.
CREST and Bank of England. STAR-FS Intelligence-Led Penetration Testing. https://www.crest-approved.org/membership/star-fs/. Documents STAR-FS scope, phases and CREST-accredited provider pool.
UK Government Security Red Team. GBEST Intelligence-Led Simulated Attack. https://www.crest-approved.org/membership/gbest/. Government-sector framework derived from CBEST.
Security Alliance and DCMS. TBEST Framework for Telecoms. https://www.secalliance.com/consulting/tbest. Telecoms-sector threat-intelligence-led testing with Ofcom.
De Nederlandsche Bank. Threat Intelligence-Based Ethical Red-teaming (TIBER-NL). https://www.dnb.nl/en/sector-information/cash-and-payment-systems/dnb-oversees-cyber-resilience-tests/threat-intelligence-based-ethical-red-teaming-tiber/. National TIBER implementation and DORA TLPT delivery.
Hong Kong Monetary Authority. Intelligence-led Cyber Attack Simulation Testing (iCAST), within the Cyber Resilience Assessment Framework (C-RAF). https://www.lrqa.com/en/insights/articles/icast-global-regulatory-frameworks-compared/. iCAST scope for high and medium risk-tier authorised institutions.
Association of Banks in Singapore with MAS. Adversarial Attack Simulation Exercises (AASE) Guidelines. September 2024. https://www.abs.org.sg/docs/library/abs-red-team-adversarial-attack-simulation-exercises-guidelines----september-2024.pdf. Red-teaming guidance for Singapore financial institutions.
Saudi Central Bank (SAMA). Financial Entities Ethical Red-Teaming (FEER) Framework. https://rulebook.sama.gov.sa/en/financial-entities-ethical-red-teaming-0. Scope for SAMA-regulated member organisations.
Council of Financial Regulators, Australia. Cyber Operational Resilience Intelligence-led Exercises (CORIE) Framework. 2022, v2.0. https://www.cfr.gov.au/publications/policy-statements-and-other-reports/2022/revised-corie-framework-rollout/cyber-operational-resilience-intelligence-led-exercises-corie-framework.html. Australian systemic-firm framework adapted from CBEST and TIBER.
Office of the Superintendent of Financial Institutions (Canada). Intelligence-led Cyber Resilience Testing (I-CRT) Framework. April 1, 2023. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/osfis-intelligence-led-cyber-resilience-testing-crt-framework. Scope, three-year cadence and OSFI oversight for D-SIBs and IAIGs.



