main logo icon

Published on

July 8, 2026

|

11 min read

Threat-Led Penetration Testing Frameworks Compared: A 2026 Global Reference

A verified 2026 reference comparing threat-led penetration testing frameworks by country: TIBER-EU, DORA TLPT, CBEST, STAR-FS, iCAST, FEER, CORIE, OSFI I-CRT and more.

Arafat Afzalzada

Arafat Afzalzada

Founder

Advisories

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Threat-led penetration testing (TLPT) is intelligence-led red teaming that regulators mandate or recommend to prove a firm can withstand a real adversary. At least a dozen national and regional frameworks now exist, most descended from the UK's CBEST and the ECB's TIBER-EU. - Which framework applies depends on your regulator, not your choice: EU firms fall under DORA TLPT delivered through TIBER-EU; UK firms under CBEST or STAR-FS; Canada under OSFI I-CRT; Hong Kong under HKMA iCAST; Saudi Arabia under SAMA FEER; Australia under CORIE; Singapore under ABS/MAS AASE. - One test rarely satisfies several regulators automatically. Inside the EU, TIBER-EU enables mutual recognition. Across regions, the shared methodology lets you reuse threat intelligence and red-team evidence, but each regulator keeps its own oversight. - Nearly every framework runs the same four phases: scoping, threat intelligence, red team execution on production, and closure or purple teaming.

Threat-led penetration testing (TLPT) is intelligence-led red teaming that a financial regulator mandates or strongly recommends to prove an institution can withstand a real, targeted adversary rather than a checklist scan. As of 2026 at least a dozen national and regional frameworks are live, and which one governs your firm is decided by your regulator, not by your procurement team. EU entities answer to DORA TLPT delivered through TIBER-EU. UK firms run CBEST or STAR-FS. Canada uses OSFI's I-CRT. Hong Kong uses HKMA iCAST, Saudi Arabia uses SAMA FEER, Australia uses CORIE, and Singapore uses the ABS and MAS AASE guidelines.

This post is a verified reference for multi-jurisdiction CISOs and compliance leads who need two answers fast: which threat-led penetration testing framework applies in each country where they operate, and whether a single test can satisfy more than one regulator. Every framework below is attributed to its issuing authority, from the European Central Bank and the Bank of England to the Hong Kong Monetary Authority, the Saudi Central Bank, Australia's Council of Financial Regulators, and Canada's OSFI.

The short answer: which framework applies to you

Your regulator picks the framework. If you are a bank, insurer, payment provider, market infrastructure operator or comparable critical entity, the framework is tied to your prudential supervisor in each jurisdiction where you hold that status.

  • European Union: DORA TLPT, the delivery mechanism for which is TIBER-EU.

  • United Kingdom (financial): CBEST for the largest systemic firms, STAR-FS for a broader population.

  • United Kingdom (other sectors): GBEST for central government, TBEST for telecoms.

  • Netherlands and other EU states: national TIBER implementations such as TIBER-NL, now feeding DORA TLPT.

  • Canada: OSFI Intelligence-led Cyber Resilience Testing (I-CRT).

  • Hong Kong: HKMA iCAST, the testing arm of the C-RAF.

  • Singapore: ABS and MAS Adversarial Attack Simulation Exercises (AASE).

  • Saudi Arabia: SAMA Financial Entities Ethical Red Teaming (FEER).

  • Australia: CORIE, run by the Council of Financial Regulators.

The nuance that follows is who exactly is in scope, whether the test is mandatory or voluntary, how often it must run, and what qualifications the testing providers need. That is where the frameworks diverge, and where the comparison matrix below earns its place.

Tlpt Global Lineage

Why the frameworks look so similar

They look similar because they share ancestry. The Bank of England launched CBEST in 2014 as the first regulator-driven, threat-intelligence-led testing scheme for systemically important financial firms. The European Central Bank generalised the model into TIBER-EU (Threat Intelligence-Based Ethical Red-teaming) in May 2018, giving national central banks a common template to localise. From there the pattern spread: the Netherlands stood up TIBER-NL, Australia adapted CBEST and TIBER into CORIE, Canada built I-CRT, and Gulf and Asian regulators wrote their own variants.

That common lineage is good news for anyone operating across borders. The vocabulary, the phases, the emphasis on realistic threat intelligence, and the bar for provider competence are broadly consistent from one framework to the next. The differences are in governance, legal force, and who selects the targets.

Key takeaways

  • The framework is assigned to you, not chosen by you. Scope is a function of your regulatory status in each market, most often systemic or critical financial-sector designation.

  • Mandatory versus voluntary is the sharpest dividing line. DORA TLPT, OSFI I-CRT and HKMA iCAST carry real obligation for in-scope firms, while TIBER-NL and AASE are framed as voluntary or guidance even though supervisors expect participation.

  • A single test rarely clears multiple regulators on its own. Inside the EU, TIBER-EU is explicitly designed for mutual recognition. Across regions, you reuse evidence rather than the approval.

  • The four-phase engagement model is nearly universal, which is what makes cross-framework evidence reuse practical in the first place.

Methodology and sources

This reference draws only on primary or issuing-authority material, verified in July 2026. Each framework is attributed to the body that publishes it: the European Central Bank for TIBER-EU; the European Supervisory Authorities and competent authorities for DORA TLPT under Article 26; the Bank of England with the PRA and FCA for CBEST and STAR-FS; the UK Cabinet Office for GBEST and DCMS with Ofcom for TBEST; De Nederlandsche Bank for TIBER-NL; the Hong Kong Monetary Authority for iCAST; the Association of Banks in Singapore with MAS for AASE; the Saudi Central Bank (SAMA) for FEER; Australia's Council of Financial Regulators for CORIE; and Canada's OSFI for I-CRT. Where a detail such as exact cadence or entity-selection threshold was not clearly stated in issuing-authority material, we describe it qualitatively rather than assert a precise figure. Full source links appear in the References section, so any claim here can be audited against the regulator that published it.

The global TLPT frameworks comparison matrix

The table below is the reference core. Read a row to understand a single framework, or read a column to compare one attribute across all of them.

Framework

Jurisdiction and authority

Who is in scope

Mandatory or voluntary

Cadence

Provider and threat-intel requirement

Cross-regulator reach

DORA TLPT

EU-wide. European Supervisory Authorities and national competent authorities, under DORA Article 26

Financial entities identified as significant by competent authorities (major banks, payment providers, market infrastructure above thresholds)

Mandatory for identified entities

At least once every three years, adjustable for risk profile

External testers required; threat intelligence external; every third test uses an external red team

Delivered via TIBER-EU; strongest mutual-recognition path inside the EU

TIBER-EU

EU. European Central Bank with national central banks

Core financial infrastructure, extensible to other critical sectors

Voluntary adoption; now the delivery vehicle for mandatory DORA TLPT

Set by the adopting authority or by DORA

Accredited threat-intel and red-team providers meeting TIBER standards

Explicitly built to facilitate mutual recognition across adopting states

CBEST

UK. Bank of England with the PRA and FCA

Systemically important UK financial institutions

Regulator-led; firms are selected by supervisors

Regulator-driven, periodic

CREST-accredited threat-intel and penetration-testing providers

Methodological basis for many other frameworks

STAR-FS

UK. Bank of England with supervisory partners, accreditation via CREST

A broader population of UK financial firms below the CBEST cohort

Firm-led with regulator oversight; more scalable than CBEST

Firm-driven

Same CREST-accredited provider pool and consultant qualifications as CBEST

Aligns with CBEST within the UK

GBEST

UK. Cabinet Office and the Government Security Red Team

UK central government departments and critical public services

Government-directed

Programme-driven

CREST STAR members

UK public-sector counterpart to CBEST

TBEST

UK. DCMS and Ofcom

UK telecommunications providers

Regulator-directed under telecoms security duties

Programme-driven

CREST-accredited threat-intel and penetration-testing providers

UK telecoms counterpart to CBEST

TIBER-NL

Netherlands. De Nederlandsche Bank

Financial sector and critical national infrastructure

Voluntary, no pass or fail; DNB now runs DORA TLPT for in-scope firms

Firm-driven

Providers meeting TIBER standards

National TIBER implementation, recognised across TIBER states

HKMA iCAST

Hong Kong. Hong Kong Monetary Authority, within the C-RAF

Authorised institutions (banks); high and medium inherent-risk tiers

Mandatory for high and medium risk-tier institutions

Aligned to the C-RAF assessment cycle

HKMA-recognised threat-intel and red-team providers

Standalone Hong Kong regime

AASE

Singapore. Association of Banks in Singapore, supported by MAS

Financial institutions in Singapore

Industry guidance; supervisors expect significant firms to participate

Guidance-driven

Qualified red-team providers

Standalone Singapore regime

SAMA FEER

Saudi Arabia. Saudi Central Bank (SAMA)

Member organisations regulated by SAMA: Tier-1 banks, digital banks, payment providers, large fintechs

Regulatory expectation for the in-scope tier

SAMA-directed

SAMA-recognised red-team and threat-intel providers

Standalone Saudi regime

CORIE

Australia. Council of Financial Regulators (RBA, APRA, ASIC, Treasury)

Systemically important Australian financial institutions

Regulator-coordinated targeted rollout

Programme-driven

Accredited providers

Adapted from CBEST and TIBER

OSFI I-CRT

Canada. Office of the Superintendent of Financial Institutions

Systemically important banks (D-SIBs) and internationally active insurance groups (IAIGs); others case by case

Mandatory for in-scope FRFIs; OSFI initiates the assessment

Once during each three-year supervisory cycle

Qualified threat-intel and red-team providers

Standalone Canadian regime, methodologically aligned with TIBER and CBEST

For a deeper EU-specific breakdown, see our companion piece on how TIBER, CBEST and DORA TLPT compare, and our detailed guide to DORA threat-led penetration testing. Canadian readers should start with our OSFI I-CRT walkthrough.

Tlpt Global Jurisdiction Map

The shared engagement model

One reason cross-framework planning is feasible is that almost every regime runs the same four phases. Naming varies, but the structure holds.

  1. Initiation and scoping. A small, confidential control group inside the firm defines the critical functions to be tested and agrees on rules of engagement with the supervisor.

  2. Threat intelligence. A dedicated provider builds realistic threat scenarios grounded in the firm's actual adversaries, sectors and geography. This is what makes the test "threat-led" rather than generic.

  3. Red team execution. Testers emulate those scenarios against live production systems, usually with only the control group aware, targeting people, processes and technology.

  4. Closure and purple teaming. The red and blue teams reconcile the attack narrative, measure detection and response, and agree remediation.

Tlpt Global Phases

Can one test satisfy several regulators?

This is the question that decides your testing budget when you operate across borders. The honest answer has three layers.

Inside the EU, largely yes. TIBER-EU was designed to "facilitate mutual recognition," in the ECB's own words, so a single TIBER-EU test that meets the DORA regulatory technical standards can serve the mandatory DORA TLPT for a cross-border group, coordinated through a lead authority. This is the cleanest case of one test clearing multiple supervisors.

Across regions, not automatically. A TIBER-EU test does not by itself discharge an HKMA iCAST, a SAMA FEER or an OSFI I-CRT obligation. Each of those regulators keeps its own lead-authority relationship, its own test-manager oversight, its own view of which critical functions matter locally, and its own provider-recognition rules. A framework in the CREST-accredited UK "BEST" family and a TIBER-standard EU test also apply different provider-qualification bars.

Evidence reuse is where the real saving lives. Because the frameworks share a lineage and a four-phase model, the threat-intelligence products, scoping artifacts, attack narratives and detection findings from one engagement transfer with modest rework into another regulator's template. Sophisticated groups run one well-scoped "anchor" test per cycle and map its deliverables to each supervisor, rather than commissioning fully independent exercises everywhere. You reuse the work, not the approval.

Tlpt Global One Test

What this means for defenders

  • Map your regulatory footprint first. List every jurisdiction where you hold a systemic or critical designation, then match each to its framework using the matrix above. That list, not a testing calendar, drives scope.

  • Design the anchor test for reuse. Scope the most demanding applicable framework, usually DORA TLPT or OSFI I-CRT, so its evidence maps cleanly onto lighter regimes.

  • Separate threat intelligence from red teaming deliberately. Every framework treats intelligence-led scenario design as the load-bearing step; a generic red team without it will not satisfy a supervisor.

  • Keep the evidence audit-ready. Attack narratives, TTP-to-control mappings and detection timelines are what your supervisor and your board actually read.

Stingrai runs threat-led red team scenarios and adversary emulation that produce exactly this kind of evidence, and our work supports firms preparing DORA, CBEST-aligned and OSFI I-CRT engagements. As a CREST-accredited penetration testing firm based in Toronto and London, we build the attack narratives, TTP mappings and detection-and-response findings your compliance program needs. Our AI web-application agent, Snipe, handles the application-layer discovery, hunting complex flaws such as IDOR and broken authorization, while senior human testers drive the intelligence-led scenarios that these frameworks require. Explore our red teaming service, our web application penetration testing, and our PTaaS platform, or review packages on the pricing page.

Frequently Asked Questions

Which threat-led penetration testing framework applies in my country?

It depends on your regulator. EU financial entities fall under DORA TLPT delivered through TIBER-EU, UK financial firms under CBEST or STAR-FS, Canadian systemic banks and internationally active insurers under OSFI I-CRT, Hong Kong banks under HKMA iCAST, Saudi financial entities under SAMA FEER, Australian systemic firms under CORIE, and Singapore financial institutions under the ABS and MAS AASE guidelines. Your regulatory status in each market, not your preference, assigns the framework.

Can one threat-led penetration test satisfy multiple regulators?

Inside the EU, largely yes: TIBER-EU is explicitly designed to facilitate mutual recognition, so one DORA-aligned TIBER-EU test can serve several EU competent authorities for a cross-border group. Across regions it does not work automatically, because each regulator keeps its own oversight and provider rules. The practical saving comes from reusing threat-intelligence and red-team evidence from an anchor test across each regulator's template.

What is the difference between TLPT and a standard penetration test?

A standard penetration test checks a defined scope for vulnerabilities, often against a checklist. Threat-led penetration testing is intelligence-led: a dedicated provider first builds realistic scenarios from your actual adversaries, then a red team emulates them against live production systems to measure real detection and response. TLPT tests the organisation, not just the application.

Is DORA threat-led penetration testing mandatory?

Yes, for financial entities that competent authorities identify as significant. DORA Article 26 requires those entities to perform TLPT at least once every three years, adjustable for risk profile, with external testers and, on a recurring basis, an external red team. Our DORA TLPT guide covers the detail.

How often do these tests have to run?

Cadence varies by framework. DORA TLPT and OSFI I-CRT both work on roughly a three-year cycle for in-scope firms. Others, such as CBEST, STAR-FS and CORIE, are programme or regulator-driven rather than fixed to a published interval. Confirm the current cadence with your supervisor, as several frameworks were updated in 2024 and 2025.

Who can perform a threat-led penetration test?

Every framework requires competent, independent providers for both threat intelligence and red teaming, and most require formal recognition. The UK "BEST" family relies on CREST-accredited providers with specific consultant qualifications, while TIBER and DORA require providers that meet their own standards. Frameworks also expect the threat-intelligence and red-team roles to be delivered to a defined competence bar.

How do I choose a threat-led testing provider?

Match the provider to the framework you must satisfy, confirm they can deliver both intelligence-led scenario design and red team execution, and check they produce supervisor-ready evidence. Our guide to choosing a threat-led penetration testing provider walks through the criteria.

Does Stingrai run regulator-mandated threat-led tests?

Stingrai runs threat-led red team scenarios and adversary emulation, and our work supports firms preparing DORA, CBEST-aligned and OSFI I-CRT engagements by producing the attack narratives, TTP mappings and detection findings these frameworks call for. Stingrai is a CREST-accredited penetration testing firm; engagement of a specific regulator-recognised test panel is arranged per framework and jurisdiction.

References

  1. European Central Bank. TIBER-EU Framework: Threat Intelligence-Based Ethical Red-Teaming. 2018, updated 2024 and 2025. https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html. Defines TIBER-EU, its mandatory and optional requirements, mutual recognition, and alignment with DORA.

  2. European Supervisory Authorities and ECB. Digital Operational Resilience Act (DORA), Article 26, and the Regulatory Technical Standards on Threat-Led Penetration Testing. 2024 to 2025. https://www.crest-approved.org/threat-led-penetration-testing-tlpt-under-dora-what-financial-institutions-need-to-know/. Sets who is in scope, the three-year cadence and provider requirements.

  3. Bank of England. CBEST Threat Intelligence-Led Assessments Implementation Guide. https://www.bankofengland.co.uk/financial-stability/operational-resilience-of-the-financial-sector/cbest-threat-intelligence-led-assessments-implementation-guide. Describes CBEST scope, governance and provider accreditation.

  4. CREST and Bank of England. STAR-FS Intelligence-Led Penetration Testing. https://www.crest-approved.org/membership/star-fs/. Documents STAR-FS scope, phases and CREST-accredited provider pool.

  5. UK Government Security Red Team. GBEST Intelligence-Led Simulated Attack. https://www.crest-approved.org/membership/gbest/. Government-sector framework derived from CBEST.

  6. Security Alliance and DCMS. TBEST Framework for Telecoms. https://www.secalliance.com/consulting/tbest. Telecoms-sector threat-intelligence-led testing with Ofcom.

  7. De Nederlandsche Bank. Threat Intelligence-Based Ethical Red-teaming (TIBER-NL). https://www.dnb.nl/en/sector-information/cash-and-payment-systems/dnb-oversees-cyber-resilience-tests/threat-intelligence-based-ethical-red-teaming-tiber/. National TIBER implementation and DORA TLPT delivery.

  8. Hong Kong Monetary Authority. Intelligence-led Cyber Attack Simulation Testing (iCAST), within the Cyber Resilience Assessment Framework (C-RAF). https://www.lrqa.com/en/insights/articles/icast-global-regulatory-frameworks-compared/. iCAST scope for high and medium risk-tier authorised institutions.

  9. Association of Banks in Singapore with MAS. Adversarial Attack Simulation Exercises (AASE) Guidelines. September 2024. https://www.abs.org.sg/docs/library/abs-red-team-adversarial-attack-simulation-exercises-guidelines----september-2024.pdf. Red-teaming guidance for Singapore financial institutions.

  10. Saudi Central Bank (SAMA). Financial Entities Ethical Red-Teaming (FEER) Framework. https://rulebook.sama.gov.sa/en/financial-entities-ethical-red-teaming-0. Scope for SAMA-regulated member organisations.

  11. Council of Financial Regulators, Australia. Cyber Operational Resilience Intelligence-led Exercises (CORIE) Framework. 2022, v2.0. https://www.cfr.gov.au/publications/policy-statements-and-other-reports/2022/revised-corie-framework-rollout/cyber-operational-resilience-intelligence-led-exercises-corie-framework.html. Australian systemic-firm framework adapted from CBEST and TIBER.

  12. Office of the Superintendent of Financial Institutions (Canada). Intelligence-led Cyber Resilience Testing (I-CRT) Framework. April 1, 2023. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/osfis-intelligence-led-cyber-resilience-testing-crt-framework. Scope, three-year cadence and OSFI oversight for D-SIBs and IAIGs.

0 views

0

X

Related reading

How to Read ATT&CK Coverage in a Red Team Proposal: Spotting Padding Before You Sign
Advisories

How to Read ATT&CK Coverage in a Red Team Proposal: Spotting Padding Before You Sign

How to evaluate red team ATT&CK mapping: a buyer's rubric to grade ATT&CK coverage, spot technique-count padding, and score a proposal before you sign.

10 min read

Autonomous Pentest Contracts: The Clauses That Make an SLA Enforceable
Advisories

Autonomous Pentest Contracts: The Clauses That Make an SLA Enforceable

Paste-ready SOW clauses for a continuous autonomous pentest SLA: validated-PoC acceptance, human sign-off, retest windows, audit rights, service credits.

10 min read

Red Team Objectives and Crown Jewels: How to Scope by Outcome Before Your RFP
Advisories

Red Team Objectives and Crown Jewels: How to Scope by Outcome Before Your RFP

Scope a red team by objectives and crown jewels before you write the RFP. A buyer's step-by-step guide with an objectives worksheet and sector examples.

10 min read

Contents

X