main logo icon

Published on

July 8, 2026

|

10 min read

TIBER-EU vs CBEST vs DORA TLPT: Which Threat-Led Test Your Regulator Actually Requires

A side-by-side comparison of the three threat-led penetration testing frameworks for financial firms (TIBER-EU, CBEST, DORA TLPT), plus OSFI I-CRT for Canada, with a decision guide for which one your regulator actually requires.

Arafat Afzalzada

Arafat Afzalzada

Founder

Advisories

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

TIBER-EU, CBEST and DORA TLPT are three flavours of the same idea: intelligence-led red teaming against the systems that keep a financial firm running. They differ on who runs them and whether they are optional. - DORA TLPT is mandatory EU law. In-scope financial entities identified by their competent authority must run a threat-led test at least every 3 years (Regulation (EU) 2022/2554, Article 26; RTS (EU) 2025/1190, applicable 8 July 2025). - CBEST is the Bank of England's regulator-selected programme for systemically important UK firms. Voluntary on paper, effectively mandatory once the regulators pick you. - TIBER-EU is the ECB's shared blueprint. It is voluntary, and it is the delivery methodology many EU authorities use to run their DORA TLPT tests. - OSFI I-CRT is Canada's equivalent for D-SIBs and internationally active insurance groups. - You almost never choose between them: your regulator and your legal jurisdiction decide which one applies.

Since 8 July 2025, threat-led penetration testing has been a binding legal requirement for in-scope EU financial entities, under the regulatory technical standards that supplement the Digital Operational Resilience Act (Commission Delegated Regulation (EU) 2025/1190). That single date is why buyers keep asking the same question: TIBER-EU vs CBEST vs DORA TLPT, which one does my firm actually have to run?

The short answer is that you rarely choose. Your legal jurisdiction and your regulator decide. DORA TLPT is mandatory for identified EU financial entities. CBEST is the Bank of England's programme for systemically important UK firms. TIBER-EU is the European Central Bank's voluntary blueprint that most EU authorities use to deliver their DORA tests. And in Canada, OSFI's I-CRT framework covers the same ground for domestic systemically important banks and large insurers. All four are the same core exercise, an intelligence-led red team against your live production systems, wrapped in different governance.

This guide compares the three European frameworks head to head, adds the Canadian context, and gives you a decision path for which threat-led test applies to you.

TL;DR

  • DORA TLPT (mandatory, EU): Financial entities identified by their competent authority must perform advanced testing by means of TLPT "at least every 3 years" on live production systems (Regulation (EU) 2022/2554, Article 26).

  • CBEST (regulator-selected, UK): The Bank of England, PRA and FCA use CBEST to assess the cyber resilience of the firms and financial market infrastructures they deem systemically important (Bank of England, CBEST Implementation Guide).

  • TIBER-EU (voluntary, EU): "Threat Intelligence-Based Ethical Red-teaming," published by the ECB in 2018 and updated in 2024 to align with the DORA TLPT standards (ECB, TIBER-EU framework).

  • OSFI I-CRT (mandatory for qualifying firms, Canada): Intelligence-led cyber resilience testing for Systemically Important Banks and Internationally Active Insurance Groups, on a three-year cycle (OSFI, I-CRT framework).

  • The common thread: All four require an external threat intelligence provider and a red team that emulates the real tactics, techniques and procedures of a sophisticated adversary.

Key takeaways

  • Only DORA TLPT is a hard legal obligation. CBEST and TIBER-EU are frameworks, not statutes. DORA is directly applicable across all 27 EU member states, and its TLPT standards became applicable on 8 July 2025 (RTS (EU) 2025/1190).

  • TIBER-EU is the method, not a separate test. Many EU national authorities run their mandatory DORA tests through their existing TIBER-XX programmes, so an in-scope firm does not run "TIBER-EU and DORA TLPT" as two exercises. TIBER-EU is often how the DORA obligation gets delivered.

  • CBEST predates both. The Bank of England built the first intelligence-led testing framework in 2014, and OSFI notes the concept was later leveraged globally, including by TIBER.

  • Provider requirements are strict and specific. DORA requires external testers with proven threat intelligence, penetration testing and red team expertise, certification by an accreditation body or adherence to a formal ethical framework, and professional indemnity insurance (Article 27). CBEST requires CREST-accredited providers.

  • Multi-jurisdiction groups can face more than one. A banking group with EU and UK entities may be in scope for both DORA TLPT and CBEST, though DORA provides for mutual recognition of tests between EU competent authorities.

The three frameworks at a glance

Every threat-led test shares the same skeleton: a scoping phase, a threat intelligence phase that builds realistic attack scenarios, a red team phase that executes them against live systems, and a closure phase that feeds findings into remediation. What changes between frameworks is the governance layer around that skeleton.

Tlpt Frameworks Matrix

Figure 1: The three European threat-led frameworks compared across authority, jurisdiction, legal status, scope and cadence. Sources: ECB TIBER-EU framework; Bank of England CBEST Implementation Guide; Regulation (EU) 2022/2554 and RTS (EU) 2025/1190.

Dimension

TIBER-EU

CBEST

DORA TLPT

Authority

European Central Bank plus EU national central banks

Bank of England, with the PRA and FCA

EU competent authorities under Regulation (EU) 2022/2554

Jurisdiction

Euro area and EU, via national TIBER-XX programmes

United Kingdom

All 27 EU member states

Legal status

Voluntary framework

Voluntary, but regulator-selected

Mandatory regulation, directly applicable

Who is in scope

Entities providing core financial infrastructure, as adopted per country

Systemically important UK banks, insurers and FMIs the regulators choose

Financial entities identified by their competent authority; microenterprises excluded

Cadence

Set by the national authority or adopting entity

Regulator-driven; engagements typically run 9 to 12 months

At least every 3 years

Threat intelligence provider

Required, external

Required, CREST-accredited

Required, external; cannot be internal

Red team provider

Required, external, with procurement due diligence

Required, CREST-accredited

External testers; internal allowed with limits, external mandatory every third test

Relationship to the others

The shared blueprint

UK forerunner that influenced TIBER

Built on TIBER-EU; specified by RTS (EU) 2025/1190

TIBER-EU: the ECB blueprint

TIBER-EU stands for Threat Intelligence-Based Ethical Red-teaming. The European Central Bank developed it jointly with EU national central banks and published it in May 2018, then updated it in 2024 to align fully with the DORA regulatory technical standards on TLPT (ECB, TIBER-EU framework).

Two things make TIBER-EU distinctive. First, it is voluntary. No entity is forced to adopt it, and each EU country decides whether and how to implement its own national version, following the TIBER-XX naming pattern such as TIBER-NL, TIBER-BE or TIBER-DE. National cyber teams run the tests with entities in their jurisdiction, with provisions for cross-border participation.

Second, TIBER-EU is a methodology rather than a target list. It defines the roles, the phases and the procurement standards for a credible intelligence-led red team, including the requirement to engage an external threat intelligence provider and an external red team, with due diligence performed against the ECB's service provider procurement guidance. Because the 2024 update aligned TIBER-EU with DORA, many national authorities now use TIBER-XX as the vehicle for delivering the mandatory DORA test. In practice, TIBER-EU is the how, and DORA TLPT is the must.

CBEST: the UK's regulator-driven test

CBEST is the oldest of the three. The Bank of England introduced it in 2014, and since then it has been part of the collective supervisory toolkit of the Bank, the Prudential Regulation Authority and the Financial Conduct Authority for assessing the cyber resilience of systemically important firms and financial market infrastructures (Bank of England, CBEST Implementation Guide).

CBEST is technically voluntary, but in practice it is regulator-selected. The Bank chooses which firms undergo an assessment based on systemic importance, so for the largest UK institutions it functions as a de facto requirement. These are heavyweight engagements: the regulators indicate an average project duration of roughly 9 to 12 months, spanning an initiation phase, a threat intelligence phase, a penetration testing phase and a closure phase.

Provider requirements are prescriptive. CBEST service providers must be CREST members, with threat intelligence providers holding the relevant CREST threat intelligence certification and penetration testing providers holding the CREST simulated attack certification. For firms below the systemic tier, the Bank introduced STAR-FS (Simulated Targeted Attack and Response for the Finance Sector) in 2024 as a firm-led, lighter-touch alternative that delivers the same threat emulation with less regulatory overhead (Bank of England, STAR-FS Implementation Guide).

DORA TLPT: the one that is now law

DORA TLPT is the framework that changed the conversation, because it is not a framework in the optional sense. It is an obligation written into Regulation (EU) 2022/2554, and its detailed rules were set by Commission Delegated Regulation (EU) 2025/1190, which became directly applicable across the EU on 8 July 2025.

Article 26 of DORA requires in-scope financial entities to perform "at least every 3 years advanced testing by means of TLPT," carried out on live production systems that support critical or important functions (Regulation (EU) 2022/2554, Article 26). Competent authorities identify which entities must test, using criteria that include impact-related factors, financial stability concerns and the entity's specific ICT risk profile. Microenterprises are excluded.

Who is in scope for DORA TLPT

The RTS narrows the field to larger and systemically important entities, which can include credit institutions, payment and electronic money institutions, central securities depositories, central counterparties, trading venues, and insurance and reinsurance undertakings, with certain crypto-asset service providers captured in specific cases. The competent authority makes the final identification.

Tester requirements under DORA

Article 27 sets a high bar for who may run the test. External testers must demonstrate the highest suitability and reputability, possess specific expertise in threat intelligence, penetration testing and red team testing, be certified by an accreditation body or adhere to formal codes of conduct or ethical frameworks, and carry professional indemnity insurance, including against misconduct and negligence. Internal testers are permitted only with competent authority approval and safeguards against conflicts of interest, and even then the threat intelligence provider must be external. Financial entities may use internal testers, but must contract external testers for every third test, and significant credit institutions must use external testers only.

DORA also builds in mutual recognition: a competent authority issues an attestation confirming a test met the requirements, so that other EU authorities can recognise it rather than forcing a duplicate exercise.

How the three relate to each other

These frameworks are not competitors so much as a family tree.

Tlpt Frameworks Lineage

Figure 2: The lineage of intelligence-led testing. CBEST (2014) pioneered the model, the ECB generalised it into TIBER-EU (2018), and DORA made it a binding obligation (2025). Sources: Bank of England; ECB; Regulation (EU) 2022/2554; OSFI I-CRT guidance.

The Bank of England pioneered intelligence-led testing with CBEST in 2014. The ECB generalised that model into a pan-European blueprint with TIBER-EU in 2018. DORA then took the TIBER-EU methodology and made a version of it legally binding, which is why the 2024 TIBER-EU update was specifically about alignment with the DORA standards. OSFI's guidance is explicit that the concept was developed by the Bank of England with CBEST and leveraged globally by regulators, including through TIBER.

The practical consequence: if your EU competent authority runs a national TIBER-XX programme, your mandatory DORA TLPT is very likely to be delivered through it. You are not doing two tests. You are doing one test, governed by DORA, executed via the TIBER-EU methodology.

Which one applies to me

Work from your regulator outward, not from the framework inward.

Tlpt Frameworks Decision

Figure 3: A decision path from your legal jurisdiction and regulator to the threat-led framework that applies. Sources: Regulation (EU) 2022/2554; Bank of England; ECB; OSFI.

  • You are an EU-regulated financial entity. DORA TLPT is your reference point. If your competent authority identifies you as in scope, you must run a threat-led test at least every three years. Check whether your national authority uses a TIBER-XX programme, because that will likely be the delivery vehicle.

  • You are a systemically important UK firm or FMI. CBEST is the programme to expect, and the Bank of England will engage you directly. If you are a UK financial firm below the systemic tier, STAR-FS is the firm-led route to the same style of assessment.

  • You are a Canadian D-SIB or internationally active insurance group. OSFI's I-CRT applies. OSFI formally engages selected federally regulated financial institutions and runs assessments on a three-year cycle, with other institutions able to request one case by case.

  • You operate across the EU and UK. You may be in scope for both DORA TLPT and CBEST. Plan a single, well-scoped threat-led capability that can satisfy both, and use DORA's mutual recognition within the EU to avoid duplicating tests across member states.

  • You are outside all of these regimes. No framework compels you, but the same intelligence-led red team is still the strongest way to test whether your detection and response actually hold up against a targeted adversary. Many firms adopt the TIBER-EU structure voluntarily as best practice.

For a deeper walk through the EU obligation, our guide to DORA threat-led penetration testing covers scoping and timelines, and the Canadian I-CRT breakdown does the same for OSFI.

What this means for defenders

The frameworks differ on governance, but they converge on the same operational demand: a credible external red team, driven by real threat intelligence, tested against your live environment, with the results feeding a genuine remediation cycle. A few things follow from that.

  • Budget for a programme, not a project. A three-year DORA cadence, or a multi-month CBEST engagement, is not a one-off scan. Plan threat intelligence, execution, purple-teaming and remediation as a recurring capability. Our breakdown of what a DORA TLPT costs sets realistic expectations.

  • Vet your provider against the framework's own bar. DORA demands certified or code-of-conduct-bound testers with specific red team expertise and professional indemnity cover; CBEST and STAR-FS demand CREST accreditation. Our checklist on how to choose a threat-led testing provider maps the requirements to the questions you should ask.

  • Separate threat intelligence from red teaming. Every one of these frameworks requires the threat intelligence to come from an external source, so your red team should not be marking its own homework.

  • Treat the test as detection validation. The point is not a report full of findings, it is proof of whether your blue team sees and stops a real adversary path.

Stingrai is a CREST-accredited offensive security firm with teams in Toronto and London, and threat-led red teaming is core to what we do. Our senior pentesters run intelligence-led adversary emulation that maps to the testing requirements behind DORA TLPT, CBEST and OSFI I-CRT, and our red teaming service is built to produce the evidence your operational resilience programme needs. Where continuous coverage matters, our PTaaS platform keeps testing live between the formal cycles, and Snipe, our autonomous web application testing agent, hunts the complex authorization and business logic flaws that scenario-based tests often turn into objectives. You can see engagement options on our pricing page.

Frequently asked questions

Does my firm need TIBER-EU, CBEST or DORA TLPT?

It depends on where you are regulated. EU financial entities identified as in scope must run DORA TLPT at least every three years (Regulation (EU) 2022/2554). Systemically important UK firms are selected for CBEST by the Bank of England. TIBER-EU itself is voluntary and is most often the methodology used to deliver the mandatory DORA test in a given EU country. You do not usually choose between them; your jurisdiction and regulator decide.

Is TIBER-EU mandatory?

No. TIBER-EU is a voluntary framework published by the ECB. However, because it was updated in 2024 to align with the DORA TLPT standards, many EU national authorities use their TIBER-XX programmes to run the mandatory DORA test, which makes it feel obligatory in practice for in-scope entities.

What is the difference between CBEST and TIBER-EU?

CBEST is the Bank of England's UK programme, introduced in 2014 and run directly by the regulators for systemically important firms. TIBER-EU is the ECB's pan-European framework from 2018, adopted country by country as TIBER-XX. CBEST predates TIBER-EU and influenced it; both simulate a real adversary using external threat intelligence and an external red team.

How often is DORA TLPT required?

At least every three years, per Article 26 of DORA. Competent authorities can adjust the frequency based on an entity's risk profile and circumstances, and the test must be run on live production systems supporting critical or important functions.

Who is in scope for DORA TLPT?

Financial entities identified by their competent authority using criteria such as impact-related factors, financial stability concerns and ICT risk profile. This typically captures larger and systemically important entities, including credit institutions, payment institutions, central securities depositories, central counterparties, trading venues and insurers. Microenterprises are excluded.

Can we use our internal team for these tests?

Partly. Under DORA, internal testers are allowed only with competent authority approval and conflict-of-interest safeguards, the external threat intelligence provider is always required, and external testers must be used for every third test. Significant credit institutions must use external testers only. CBEST requires CREST-accredited external providers.

What framework applies to financial firms in Canada?

OSFI's Intelligence-led Cyber Resilience Testing (I-CRT) framework applies to Systemically Important Banks and Internationally Active Insurance Groups, on a three-year cycle. OSFI notes I-CRT is influenced by CBEST and TIBER. Other federally regulated institutions can request an assessment case by case.

Do TIBER-EU and DORA TLPT overlap?

Yes, by design. TIBER-EU is the methodology, and DORA TLPT is the legal obligation that adopts it. An in-scope EU entity generally runs one test, governed by DORA and executed through the TIBER-XX programme its national authority operates, rather than two separate exercises.

Where can I get the source documents?

The primary sources are the ECB's TIBER-EU framework page, the Bank of England's CBEST Implementation Guide, Regulation (EU) 2022/2554 and Commission Delegated Regulation (EU) 2025/1190 on EUR-Lex, and OSFI's I-CRT guidance. All are linked in the references below.

References

  1. European Central Bank. TIBER-EU Framework (Threat Intelligence-Based Ethical Red-teaming). Published May 2018, updated 2024. https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html. Defines the roles, phases and procurement standards for intelligence-led red teaming across the EU.

  2. Bank of England. CBEST Threat Intelligence-Led Assessments: Implementation Guide. https://www.bankofengland.co.uk/financial-stability/operational-resilience-of-the-financial-sector/cbest-threat-intelligence-led-assessments-implementation-guide. Sets out how the Bank, PRA and FCA run intelligence-led assessments of systemically important UK firms.

  3. Bank of England. STAR-FS Implementation Guide (March 2024). https://www.bankofengland.co.uk/-/media/boe/files/financial-stability/star-fs-implementation-guide-march-2024.pdf. The firm-led, scaled alternative to CBEST for the wider UK finance sector.

  4. European Union. Regulation (EU) 2022/2554 (Digital Operational Resilience Act), Articles 26 and 27. https://eur-lex.europa.eu/eli/reg/2022/2554/oj. Establishes the TLPT obligation, the three-year cadence and the tester requirements.

  5. European Commission. Commission Delegated Regulation (EU) 2025/1190 (RTS on threat-led penetration testing). Applicable 8 July 2025. https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj/eng. Specifies scope criteria, tester rules, methodology and supervisory cooperation for DORA TLPT.

  6. Office of the Superintendent of Financial Institutions (Canada). OSFI's Intelligence-led Cyber Resilience Testing (I-CRT) Framework. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/osfis-intelligence-led-cyber-resilience-testing-crt-framework. Canada's intelligence-led testing regime for D-SIBs and internationally active insurance groups.

0 views

0

X

Related reading

Red Team Objectives and Crown Jewels: How to Scope by Outcome Before Your RFP
Advisories

Red Team Objectives and Crown Jewels: How to Scope by Outcome Before Your RFP

Scope a red team by objectives and crown jewels before you write the RFP. A buyer's step-by-step guide with an objectives worksheet and sector examples.

10 min read

Autonomous Pentest Contracts: The Clauses That Make an SLA Enforceable
Advisories

Autonomous Pentest Contracts: The Clauses That Make an SLA Enforceable

Paste-ready SOW clauses for a continuous autonomous pentest SLA: validated-PoC acceptance, human sign-off, retest windows, audit rights, service credits.

10 min read

What a DORA Threat-Led Penetration Test Costs in 2026 (and What Drives the Price)
Advisories

What a DORA Threat-Led Penetration Test Costs in 2026 (and What Drives the Price)

A DORA threat-led penetration test is a multi-month, dual-provider program. See the 2026 TLPT cost drivers and how to budget before your RFP.

12 min read

Contents

X