Since 8 July 2025, threat-led penetration testing has been a binding legal requirement for in-scope EU financial entities, under the regulatory technical standards that supplement the Digital Operational Resilience Act (Commission Delegated Regulation (EU) 2025/1190). That single date is why buyers keep asking the same question: TIBER-EU vs CBEST vs DORA TLPT, which one does my firm actually have to run?
The short answer is that you rarely choose. Your legal jurisdiction and your regulator decide. DORA TLPT is mandatory for identified EU financial entities. CBEST is the Bank of England's programme for systemically important UK firms. TIBER-EU is the European Central Bank's voluntary blueprint that most EU authorities use to deliver their DORA tests. And in Canada, OSFI's I-CRT framework covers the same ground for domestic systemically important banks and large insurers. All four are the same core exercise, an intelligence-led red team against your live production systems, wrapped in different governance.
This guide compares the three European frameworks head to head, adds the Canadian context, and gives you a decision path for which threat-led test applies to you.
TL;DR
DORA TLPT (mandatory, EU): Financial entities identified by their competent authority must perform advanced testing by means of TLPT "at least every 3 years" on live production systems (Regulation (EU) 2022/2554, Article 26).
CBEST (regulator-selected, UK): The Bank of England, PRA and FCA use CBEST to assess the cyber resilience of the firms and financial market infrastructures they deem systemically important (Bank of England, CBEST Implementation Guide).
TIBER-EU (voluntary, EU): "Threat Intelligence-Based Ethical Red-teaming," published by the ECB in 2018 and updated in 2024 to align with the DORA TLPT standards (ECB, TIBER-EU framework).
OSFI I-CRT (mandatory for qualifying firms, Canada): Intelligence-led cyber resilience testing for Systemically Important Banks and Internationally Active Insurance Groups, on a three-year cycle (OSFI, I-CRT framework).
The common thread: All four require an external threat intelligence provider and a red team that emulates the real tactics, techniques and procedures of a sophisticated adversary.
Key takeaways
Only DORA TLPT is a hard legal obligation. CBEST and TIBER-EU are frameworks, not statutes. DORA is directly applicable across all 27 EU member states, and its TLPT standards became applicable on 8 July 2025 (RTS (EU) 2025/1190).
TIBER-EU is the method, not a separate test. Many EU national authorities run their mandatory DORA tests through their existing TIBER-XX programmes, so an in-scope firm does not run "TIBER-EU and DORA TLPT" as two exercises. TIBER-EU is often how the DORA obligation gets delivered.
CBEST predates both. The Bank of England built the first intelligence-led testing framework in 2014, and OSFI notes the concept was later leveraged globally, including by TIBER.
Provider requirements are strict and specific. DORA requires external testers with proven threat intelligence, penetration testing and red team expertise, certification by an accreditation body or adherence to a formal ethical framework, and professional indemnity insurance (Article 27). CBEST requires CREST-accredited providers.
Multi-jurisdiction groups can face more than one. A banking group with EU and UK entities may be in scope for both DORA TLPT and CBEST, though DORA provides for mutual recognition of tests between EU competent authorities.
The three frameworks at a glance
Every threat-led test shares the same skeleton: a scoping phase, a threat intelligence phase that builds realistic attack scenarios, a red team phase that executes them against live systems, and a closure phase that feeds findings into remediation. What changes between frameworks is the governance layer around that skeleton.

Figure 1: The three European threat-led frameworks compared across authority, jurisdiction, legal status, scope and cadence. Sources: ECB TIBER-EU framework; Bank of England CBEST Implementation Guide; Regulation (EU) 2022/2554 and RTS (EU) 2025/1190.
Dimension | TIBER-EU | CBEST | DORA TLPT |
|---|---|---|---|
Authority | European Central Bank plus EU national central banks | Bank of England, with the PRA and FCA | EU competent authorities under Regulation (EU) 2022/2554 |
Jurisdiction | Euro area and EU, via national TIBER-XX programmes | United Kingdom | All 27 EU member states |
Legal status | Voluntary framework | Voluntary, but regulator-selected | Mandatory regulation, directly applicable |
Who is in scope | Entities providing core financial infrastructure, as adopted per country | Systemically important UK banks, insurers and FMIs the regulators choose | Financial entities identified by their competent authority; microenterprises excluded |
Cadence | Set by the national authority or adopting entity | Regulator-driven; engagements typically run 9 to 12 months | At least every 3 years |
Threat intelligence provider | Required, external | Required, CREST-accredited | Required, external; cannot be internal |
Red team provider | Required, external, with procurement due diligence | Required, CREST-accredited | External testers; internal allowed with limits, external mandatory every third test |
Relationship to the others | The shared blueprint | UK forerunner that influenced TIBER | Built on TIBER-EU; specified by RTS (EU) 2025/1190 |
TIBER-EU: the ECB blueprint
TIBER-EU stands for Threat Intelligence-Based Ethical Red-teaming. The European Central Bank developed it jointly with EU national central banks and published it in May 2018, then updated it in 2024 to align fully with the DORA regulatory technical standards on TLPT (ECB, TIBER-EU framework).
Two things make TIBER-EU distinctive. First, it is voluntary. No entity is forced to adopt it, and each EU country decides whether and how to implement its own national version, following the TIBER-XX naming pattern such as TIBER-NL, TIBER-BE or TIBER-DE. National cyber teams run the tests with entities in their jurisdiction, with provisions for cross-border participation.
Second, TIBER-EU is a methodology rather than a target list. It defines the roles, the phases and the procurement standards for a credible intelligence-led red team, including the requirement to engage an external threat intelligence provider and an external red team, with due diligence performed against the ECB's service provider procurement guidance. Because the 2024 update aligned TIBER-EU with DORA, many national authorities now use TIBER-XX as the vehicle for delivering the mandatory DORA test. In practice, TIBER-EU is the how, and DORA TLPT is the must.
CBEST: the UK's regulator-driven test
CBEST is the oldest of the three. The Bank of England introduced it in 2014, and since then it has been part of the collective supervisory toolkit of the Bank, the Prudential Regulation Authority and the Financial Conduct Authority for assessing the cyber resilience of systemically important firms and financial market infrastructures (Bank of England, CBEST Implementation Guide).
CBEST is technically voluntary, but in practice it is regulator-selected. The Bank chooses which firms undergo an assessment based on systemic importance, so for the largest UK institutions it functions as a de facto requirement. These are heavyweight engagements: the regulators indicate an average project duration of roughly 9 to 12 months, spanning an initiation phase, a threat intelligence phase, a penetration testing phase and a closure phase.
Provider requirements are prescriptive. CBEST service providers must be CREST members, with threat intelligence providers holding the relevant CREST threat intelligence certification and penetration testing providers holding the CREST simulated attack certification. For firms below the systemic tier, the Bank introduced STAR-FS (Simulated Targeted Attack and Response for the Finance Sector) in 2024 as a firm-led, lighter-touch alternative that delivers the same threat emulation with less regulatory overhead (Bank of England, STAR-FS Implementation Guide).
DORA TLPT: the one that is now law
DORA TLPT is the framework that changed the conversation, because it is not a framework in the optional sense. It is an obligation written into Regulation (EU) 2022/2554, and its detailed rules were set by Commission Delegated Regulation (EU) 2025/1190, which became directly applicable across the EU on 8 July 2025.
Article 26 of DORA requires in-scope financial entities to perform "at least every 3 years advanced testing by means of TLPT," carried out on live production systems that support critical or important functions (Regulation (EU) 2022/2554, Article 26). Competent authorities identify which entities must test, using criteria that include impact-related factors, financial stability concerns and the entity's specific ICT risk profile. Microenterprises are excluded.
Who is in scope for DORA TLPT
The RTS narrows the field to larger and systemically important entities, which can include credit institutions, payment and electronic money institutions, central securities depositories, central counterparties, trading venues, and insurance and reinsurance undertakings, with certain crypto-asset service providers captured in specific cases. The competent authority makes the final identification.
Tester requirements under DORA
Article 27 sets a high bar for who may run the test. External testers must demonstrate the highest suitability and reputability, possess specific expertise in threat intelligence, penetration testing and red team testing, be certified by an accreditation body or adhere to formal codes of conduct or ethical frameworks, and carry professional indemnity insurance, including against misconduct and negligence. Internal testers are permitted only with competent authority approval and safeguards against conflicts of interest, and even then the threat intelligence provider must be external. Financial entities may use internal testers, but must contract external testers for every third test, and significant credit institutions must use external testers only.
DORA also builds in mutual recognition: a competent authority issues an attestation confirming a test met the requirements, so that other EU authorities can recognise it rather than forcing a duplicate exercise.
How the three relate to each other
These frameworks are not competitors so much as a family tree.

Figure 2: The lineage of intelligence-led testing. CBEST (2014) pioneered the model, the ECB generalised it into TIBER-EU (2018), and DORA made it a binding obligation (2025). Sources: Bank of England; ECB; Regulation (EU) 2022/2554; OSFI I-CRT guidance.
The Bank of England pioneered intelligence-led testing with CBEST in 2014. The ECB generalised that model into a pan-European blueprint with TIBER-EU in 2018. DORA then took the TIBER-EU methodology and made a version of it legally binding, which is why the 2024 TIBER-EU update was specifically about alignment with the DORA standards. OSFI's guidance is explicit that the concept was developed by the Bank of England with CBEST and leveraged globally by regulators, including through TIBER.
The practical consequence: if your EU competent authority runs a national TIBER-XX programme, your mandatory DORA TLPT is very likely to be delivered through it. You are not doing two tests. You are doing one test, governed by DORA, executed via the TIBER-EU methodology.
Which one applies to me
Work from your regulator outward, not from the framework inward.

Figure 3: A decision path from your legal jurisdiction and regulator to the threat-led framework that applies. Sources: Regulation (EU) 2022/2554; Bank of England; ECB; OSFI.
You are an EU-regulated financial entity. DORA TLPT is your reference point. If your competent authority identifies you as in scope, you must run a threat-led test at least every three years. Check whether your national authority uses a TIBER-XX programme, because that will likely be the delivery vehicle.
You are a systemically important UK firm or FMI. CBEST is the programme to expect, and the Bank of England will engage you directly. If you are a UK financial firm below the systemic tier, STAR-FS is the firm-led route to the same style of assessment.
You are a Canadian D-SIB or internationally active insurance group. OSFI's I-CRT applies. OSFI formally engages selected federally regulated financial institutions and runs assessments on a three-year cycle, with other institutions able to request one case by case.
You operate across the EU and UK. You may be in scope for both DORA TLPT and CBEST. Plan a single, well-scoped threat-led capability that can satisfy both, and use DORA's mutual recognition within the EU to avoid duplicating tests across member states.
You are outside all of these regimes. No framework compels you, but the same intelligence-led red team is still the strongest way to test whether your detection and response actually hold up against a targeted adversary. Many firms adopt the TIBER-EU structure voluntarily as best practice.
For a deeper walk through the EU obligation, our guide to DORA threat-led penetration testing covers scoping and timelines, and the Canadian I-CRT breakdown does the same for OSFI.
What this means for defenders
The frameworks differ on governance, but they converge on the same operational demand: a credible external red team, driven by real threat intelligence, tested against your live environment, with the results feeding a genuine remediation cycle. A few things follow from that.
Budget for a programme, not a project. A three-year DORA cadence, or a multi-month CBEST engagement, is not a one-off scan. Plan threat intelligence, execution, purple-teaming and remediation as a recurring capability. Our breakdown of what a DORA TLPT costs sets realistic expectations.
Vet your provider against the framework's own bar. DORA demands certified or code-of-conduct-bound testers with specific red team expertise and professional indemnity cover; CBEST and STAR-FS demand CREST accreditation. Our checklist on how to choose a threat-led testing provider maps the requirements to the questions you should ask.
Separate threat intelligence from red teaming. Every one of these frameworks requires the threat intelligence to come from an external source, so your red team should not be marking its own homework.
Treat the test as detection validation. The point is not a report full of findings, it is proof of whether your blue team sees and stops a real adversary path.
Stingrai is a CREST-accredited offensive security firm with teams in Toronto and London, and threat-led red teaming is core to what we do. Our senior pentesters run intelligence-led adversary emulation that maps to the testing requirements behind DORA TLPT, CBEST and OSFI I-CRT, and our red teaming service is built to produce the evidence your operational resilience programme needs. Where continuous coverage matters, our PTaaS platform keeps testing live between the formal cycles, and Snipe, our autonomous web application testing agent, hunts the complex authorization and business logic flaws that scenario-based tests often turn into objectives. You can see engagement options on our pricing page.
Frequently asked questions
Does my firm need TIBER-EU, CBEST or DORA TLPT?
It depends on where you are regulated. EU financial entities identified as in scope must run DORA TLPT at least every three years (Regulation (EU) 2022/2554). Systemically important UK firms are selected for CBEST by the Bank of England. TIBER-EU itself is voluntary and is most often the methodology used to deliver the mandatory DORA test in a given EU country. You do not usually choose between them; your jurisdiction and regulator decide.
Is TIBER-EU mandatory?
No. TIBER-EU is a voluntary framework published by the ECB. However, because it was updated in 2024 to align with the DORA TLPT standards, many EU national authorities use their TIBER-XX programmes to run the mandatory DORA test, which makes it feel obligatory in practice for in-scope entities.
What is the difference between CBEST and TIBER-EU?
CBEST is the Bank of England's UK programme, introduced in 2014 and run directly by the regulators for systemically important firms. TIBER-EU is the ECB's pan-European framework from 2018, adopted country by country as TIBER-XX. CBEST predates TIBER-EU and influenced it; both simulate a real adversary using external threat intelligence and an external red team.
How often is DORA TLPT required?
At least every three years, per Article 26 of DORA. Competent authorities can adjust the frequency based on an entity's risk profile and circumstances, and the test must be run on live production systems supporting critical or important functions.
Who is in scope for DORA TLPT?
Financial entities identified by their competent authority using criteria such as impact-related factors, financial stability concerns and ICT risk profile. This typically captures larger and systemically important entities, including credit institutions, payment institutions, central securities depositories, central counterparties, trading venues and insurers. Microenterprises are excluded.
Can we use our internal team for these tests?
Partly. Under DORA, internal testers are allowed only with competent authority approval and conflict-of-interest safeguards, the external threat intelligence provider is always required, and external testers must be used for every third test. Significant credit institutions must use external testers only. CBEST requires CREST-accredited external providers.
What framework applies to financial firms in Canada?
OSFI's Intelligence-led Cyber Resilience Testing (I-CRT) framework applies to Systemically Important Banks and Internationally Active Insurance Groups, on a three-year cycle. OSFI notes I-CRT is influenced by CBEST and TIBER. Other federally regulated institutions can request an assessment case by case.
Do TIBER-EU and DORA TLPT overlap?
Yes, by design. TIBER-EU is the methodology, and DORA TLPT is the legal obligation that adopts it. An in-scope EU entity generally runs one test, governed by DORA and executed through the TIBER-XX programme its national authority operates, rather than two separate exercises.
Where can I get the source documents?
The primary sources are the ECB's TIBER-EU framework page, the Bank of England's CBEST Implementation Guide, Regulation (EU) 2022/2554 and Commission Delegated Regulation (EU) 2025/1190 on EUR-Lex, and OSFI's I-CRT guidance. All are linked in the references below.
References
European Central Bank. TIBER-EU Framework (Threat Intelligence-Based Ethical Red-teaming). Published May 2018, updated 2024. https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html. Defines the roles, phases and procurement standards for intelligence-led red teaming across the EU.
Bank of England. CBEST Threat Intelligence-Led Assessments: Implementation Guide. https://www.bankofengland.co.uk/financial-stability/operational-resilience-of-the-financial-sector/cbest-threat-intelligence-led-assessments-implementation-guide. Sets out how the Bank, PRA and FCA run intelligence-led assessments of systemically important UK firms.
Bank of England. STAR-FS Implementation Guide (March 2024). https://www.bankofengland.co.uk/-/media/boe/files/financial-stability/star-fs-implementation-guide-march-2024.pdf. The firm-led, scaled alternative to CBEST for the wider UK finance sector.
European Union. Regulation (EU) 2022/2554 (Digital Operational Resilience Act), Articles 26 and 27. https://eur-lex.europa.eu/eli/reg/2022/2554/oj. Establishes the TLPT obligation, the three-year cadence and the tester requirements.
European Commission. Commission Delegated Regulation (EU) 2025/1190 (RTS on threat-led penetration testing). Applicable 8 July 2025. https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj/eng. Specifies scope criteria, tester rules, methodology and supervisory cooperation for DORA TLPT.
Office of the Superintendent of Financial Institutions (Canada). OSFI's Intelligence-led Cyber Resilience Testing (I-CRT) Framework. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/osfis-intelligence-led-cyber-resilience-testing-crt-framework. Canada's intelligence-led testing regime for D-SIBs and internationally active insurance groups.



