The CREST public register lists just 14 approved providers for STAR-FS threat-led penetration testing and 31 firms in the broader threat-led specialism, out of 541 accredited companies in total, counted on the register in July 2026 (CREST Marketplace). On the other side of the same market, the EU's Digital Operational Resilience Act (DORA) reaches more than 22,000 financial entities and ICT service providers (per PwC), and the European Central Bank alone directly supervises 110 significant banks as of 1 May 2026 (ECB Banking Supervision). Demand for regulated red teaming is measured in hundreds of systemic entities inside a 22,000-entity universe. Accredited supply is measured in dozens.
Three forces drive the squeeze in 2026. First, DORA made threat-led testing a legal obligation for designated financial entities, with the technical standard, Commission Delegated Regulation (EU) 2025/1190, applicable from 8 July 2025. Second, the mandated cadence is at least once every three years for in-scope entities, so demand recurs rather than clears. Third, the accredited provider pool grows slowly because TLPT-grade accreditation is hard to earn and each engagement is a multi-month, senior-team effort. This post is for the analysts, journalists, and buyers who need the hard numbers behind that tension.
This post is the Stingrai research team's canonical 2026 reference for the supply and demand of threat-led penetration testing. It carries a small set of load-bearing figures drawn from four named source families: the CREST public register for provider counts, the ECB for supervision and TIBER figures, PwC and EIOPA for DORA population scale, and EUR-Lex for the legal cadence. Lead provider data is counted live from the public register in July 2026, the freshest possible; the DORA population and cadence figures are the 2025 to 2026 regulatory record. Actual TLPT designations under DORA are confidential, so every demand-scale figure is a named public estimate or an official proxy, never a fabricated count, and every figure carries its source, year, and window so any claim can be audited inline.
The short answer, up front
How many organizations must run a threat-led penetration test under DORA, and are there enough accredited red team providers to serve them?
The precise number of entities designated for mandatory TLPT is not public. National competent authorities notify entities privately, and the identification criteria live inside Commission Delegated Regulation (EU) 2025/1190, not in a published list. What is public and countable points to a wide gap. DORA reaches more than 22,000 financial entities (PwC). The ECB alone directly supervises 110 significant banks (ECB, 1 May 2026), and those systemically important institutions sit alongside major insurers, payment institutions, investment firms, central securities depositories, central counterparties, and trading venues across the European Economic Area, all of which can be designated. Against that, the CREST register shows 14 STAR-FS threat-led penetration testing providers and 31 firms in the broader threat-led specialism (CREST Marketplace, July 2026). The mandated population is large. The accredited provider pool is small. On current numbers, in-scope entities that wait until the last quarter of their cycle should expect a queue.

TL;DR: the numbers that matter
STAR-FS threat-led testing providers on the CREST register (July 2026): 14 (CREST Marketplace).
Firms in the broader threat-led penetration testing specialism (July 2026): 31, formerly STAR ILPT (CREST Marketplace).
Total CREST-accredited companies on the register (July 2026): 541 (CREST Marketplace).
Financial entities and ICT providers in DORA scope: more than 22,000 (PwC).
Significant banks directly supervised by the ECB (1 May 2026): 110 (ECB Banking Supervision).
TLPT cadence for designated entities: at least once every three years (Commission Delegated Regulation (EU) 2025/1190).
TLPT technical standard applicable from: 8 July 2025 (EUR-Lex).
STAR-FS threat intelligence providers on the register (July 2026): 8, a separate accreditation from the red team (CREST Marketplace).
TIBER tests conducted across the EU, historical baseline: over 100 as of 27 April 2023 (ECB).
Types of financial entity DORA covers: around 20 (EIOPA).
Key takeaways
The demand is confidential, the supply is countable, and that asymmetry is the whole point. Regulators keep TLPT designations private, but anyone can open the CREST register today and count the accredited providers. When you can measure one side of a market precisely and the other only in ranges, the precise side sets the ceiling. The ceiling here is dozens of firms.
DORA's headline population is a distraction if you read it as demand. The 22,000-plus figure (PwC) is the entire DORA population, and most of those entities will never run a TLPT. The subset that will is a fraction, anchored by systemic institutions such as the 110 significant banks the ECB directly supervises (ECB, 1 May 2026). The real demand sits between "a fraction of 22,000" and "more than the largest banks alone."
A three-year cadence means demand never fully clears. Because designated entities must retest at least once every three years (Delegated Regulation (EU) 2025/1190), the pipeline refills continuously. A provider pool sized for a one-time wave is undersized for a recurring obligation.
Threat intelligence is a second, even scarcer bottleneck. A compliant engagement needs an accredited threat-intelligence provider as well as a red team. The register shows only 8 STAR-FS threat intelligence providers (CREST Marketplace, July 2026), so the constraint is not just red teamers.
Booking early is now a procurement strategy, not a nicety. With multi-month engagements and a small accredited pool serving a recurring, regulator-driven pipeline, calendar slots are the scarce resource. The entities that plan their cadence years ahead will not be the ones queuing.
Methodology and sources
This post uses only figures that are either counted live from a public register today, quoted from a named source, or presented as clearly labeled arithmetic. The retrieval pass ran on 22 July 2026.
Provider supply is counted from the CREST Marketplace supplier register at marketplace.crest.org/suppliers, using the register's own on-page filter counts. These were read directly from the live register on 22 July 2026 and are dated "as counted July 2026" wherever they appear, because register membership changes over time.
DORA population scale uses PwC's estimate of more than 22,000 financial entities and ICT providers, and EIOPA's statement that DORA covers around 20 types of financial entity. These describe the whole DORA population, not the TLPT subset, and are labeled as such.
The banking proxy is the European Central Bank's count of 110 significant banks under direct supervision as of 1 May 2026. Supervision under the Single Supervisory Mechanism is a different test from DORA TLPT designation, so this figure is used only as a public proxy for the scale of the largest banks, not as a TLPT count.
The historical baseline is the ECB's April 2023 statement that over 100 TIBER tests had been conducted across the EU. It is presented as a dated baseline from before DORA's obligation took hold, not a current-year figure.
Cadence and legal basis come from DORA Article 26 and Commission Delegated Regulation (EU) 2025/1190, retrieved from EUR-Lex.
Two honesty notes govern the whole post. First, actual DORA TLPT designations are confidential; where a precise in-scope count would be attractive, it does not exist publicly, so we do not assert one. Second, this post names no individual providers. It reports register totals only, because the story is the count, not the roster. Any figure that could not be traced to a named source or a live register was dropped rather than estimated. Every figure links back to its source so any claim can be audited against the register or regulator that published it. For framework-by-framework detail on how these schemes differ, see the companion threat-led penetration testing frameworks reference and the TIBER, CBEST and DORA TLPT comparison.
The demand side: a large, mostly hidden population
DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025 and reaches a very broad population. PwC estimates it touches more than 22,000 financial entities and ICT service providers across the EU, and EIOPA describes it as covering around 20 types of financial entity, from credit institutions and investment firms to payment institutions, electronic money institutions, crypto-asset service providers, central securities depositories, trading venues, and more.
That 22,000-plus number is the trap in most coverage of this topic. It is the DORA population, not the TLPT population. The vast majority of those entities will meet their DORA obligations through governance, incident reporting, ICT risk management, and ordinary security testing, and will never run a threat-led penetration test. Threat-led testing is reserved for entities that national competent authorities designate as significant, using the criteria in Commission Delegated Regulation (EU) 2025/1190, the regulatory technical standard for TLPT that became applicable on 8 July 2025.
How many entities does that leave? Publicly, the honest answer is that no one outside the regulators knows precisely, because designations are private. What we can do is bound the problem with a named, official figure. The ECB directly supervises 110 significant banks as of 1 May 2026. Those institutions are exactly the systemically important firms most likely to sit in scope for mandatory testing, and they are only the euro-area banking slice. Around them sit major insurers, payment and e-money institutions, investment firms, central securities depositories, central counterparties, and trading venues across all European Economic Area states, plus the United Kingdom's own separately regulated population under CBEST and STAR-FS. The mandated demand is therefore comfortably in the hundreds of systemic entities, even though it is a small fraction of the 22,000-plus headline. For a deeper read on who gets designated and what the first months look like, see DORA threat-led penetration testing explained and the first 90 days after a TLPT designation.
The supply side: what the register actually shows
Now the countable side. The CREST Marketplace is the public register of CREST-accredited providers, and it exposes filter counts that anyone can read without logging in. Here is what it showed when we counted it on 22 July 2026.
Register facet | Providers | What it covers |
|---|---|---|
Total companies on the register | 541 | All CREST-accredited companies across every specialism |
Penetration Testing accreditation | 508 | The broad CREST penetration testing accreditation |
Red Teaming category | 31 | Firms tagged for red teaming |
Threat Led Penetration Testing specialism (formerly STAR ILPT) | 31 | The broader intelligence-led testing specialism |
STAR-FS Threat Led Penetration Testing | 14 | The financial-sector threat-led red team accreditation |
STAR-FS Threat Intelligence | 8 | The financial-sector threat-intelligence accreditation |
Threat Intelligence for Simulated Attack (formerly STAR TI) | 8 | Threat-intelligence accreditation for simulated attack work |
Source: CREST Marketplace register, counted July 2026.
Read the table from the top down and the funnel is stark. There are 541 accredited companies in total. Around 508 hold the broad penetration testing accreditation. Only 31 are tagged for red teaming or sit in the broader threat-led specialism. And only 14 hold the STAR-FS threat-led penetration testing accreditation built specifically for the financial sector. The pool that regulators and financial firms can actually draw on for a mandated, financial-grade threat-led test is roughly one in forty of the accredited companies on the register.

A word on CBEST. CBEST is the Bank of England's scheme for the most systemic UK firms, and its provider accreditation is administered by the Bank of England rather than exposed as a countable filter on the CREST register. The Bank of England does not publish a public provider count, so this post does not assert one. The countable public numbers are the STAR-FS and threat-led specialism facets above, and they already make the point.
There is also a second accreditation hiding in that table. A compliant threat-led engagement is not one team. It needs an accredited threat-intelligence provider to build the adversary picture and an accredited red team to execute against it, and the two are often separate firms with separate accreditations. The register shows only 8 STAR-FS threat intelligence providers. So the bottleneck is not simply "how many red teams exist." It is "how many red teams and threat-intelligence providers exist, and can they be paired within your calendar window."
The cadence arithmetic, shown as arithmetic
The cleanest way to feel the squeeze is to do the division out loud, using one named input and being explicit that it is illustrative rather than a claim about actual designations.
Take the ECB's 110 significant banks as the input. DORA requires designated entities to run a threat-led test at least once every three years. If those 110 banks were all designated and spread evenly across the cycle, that is:
110 banks / 3-year cycle = about 37 bank tests per year, in the euro area alone.
That number is deliberately conservative. It counts only euro-area significant banks. It excludes every non-euro EEA state. It excludes insurers, payment and e-money institutions, investment firms, central securities depositories, central counterparties, and trading venues, all of which can be designated. And it excludes the United Kingdom's separate CBEST and STAR-FS pipeline entirely. The true annual demand for financial-grade threat-led engagements across the UK and EU is a multiple of 37, not a fraction of it.
Now hold that against supply. Fourteen STAR-FS threat-led providers. A broader threat-led specialism pool of 31. Each engagement runs for months, not days, because scoping, threat intelligence, red team execution against production, and closure are sequential phases staffed by senior people. A single provider can carry only a handful of these at once. The arithmetic does not need to be precise to land: a recurring pipeline of dozens of financial-grade tests per year, meeting a provider pool of dozens where each firm clears only a few engagements per year, is a market that runs hot.

The historical baseline: how we got here
Threat-led testing did not appear with DORA. It has a decade of lineage, and one dated figure anchors the "before" picture. As of 27 April 2023, the ECB reported that over 100 TIBER tests had been conducted across the EU. That milestone came from more than a decade of voluntary and regulator-led testing, long before DORA made it a legal obligation.
The timeline matters because it shows the demand curve bending upward at exactly the moment the supply curve cannot bend to match. The Bank of England launched CBEST in 2014 as the first regulator-driven, intelligence-led testing scheme. The ECB generalized the model into TIBER-EU in 2018. Both ran for years as voluntary or regulator-selected programmes, which is how the EU accumulated "over 100 tests" by 2023. Then DORA came into force in January 2025, its TLPT technical standard became applicable in July 2025, and the ECB updated the TIBER-EU framework to align with DORA in February 2025. Voluntary participation became a recurring legal obligation almost overnight, while the accredited provider pool kept growing at its own slow, accreditation-gated pace.

Why this becomes a capacity crunch
Put the pieces together and the crunch is structural, not cyclical.
The obligation recurs. A three-year cadence means the pipeline never empties. Every year a fresh cohort comes due, and the previous cohorts start their next round.
The engagements are long. A threat-led test is a multi-month campaign with distinct phases and senior staffing. Providers cannot batch them the way a scanner batches scans.
The accreditation gate is narrow. TLPT-grade accreditation is hard to earn, so the provider pool grows slowly. New entrants do not arrive in the numbers that would relieve the pressure quickly.
Two accreditations, not one. Threat intelligence and red team execution are separate, separately accredited functions. The scarcer of the two sets the pace, and with 8 STAR-FS threat intelligence providers on the register, that is a real constraint.
Demand and supply are on different clocks. Regulation added demand in a single step change. Accreditation adds supply one firm at a time. Those clocks do not synchronize.
None of this means the obligation is unmeetable. It means the scarce resource is calendar time with a qualified provider, and that resource goes to the buyers who plan first.
What this means for defenders and buyers
Security and resilience leaders at in-scope financial entities can turn the numbers above into a few concrete moves.
Treat your TLPT slot like a long-lead procurement. With a small accredited pool serving a recurring, regulator-driven pipeline, the binding constraint is provider calendar availability, not budget approval. Scope and book well ahead of your cycle deadline rather than in its final quarter. For help evaluating firms, see how to choose a threat-led penetration testing provider.
Budget for the real shape of the engagement. A threat-led test is a multi-month campaign with separate threat-intelligence and red team costs, not a fixed-price scan. The DORA TLPT cost breakdown walks through the drivers.
Do not let the web-app layer drift for three years between tests. A once-every-three-years campaign proves resilience at a point in time; it does not keep your applications tested in the twenty-something months in between. Continuous testing closes that gap. Stingrai's autonomous web application pentest agent, Snipe, hunts complex, high-impact classes such as broken access control, insecure direct object references, and business logic flaws on an ongoing basis, and Stingrai's PTaaS keeps that layer under continuous coverage between threat-led cycles. See also continuous red teaming versus the annual pentest.
Map your obligations across jurisdictions before you buy. If you operate in both the UK and the EU, or in Canada under OSFI's intelligence-led red team testing, one test rarely satisfies every regulator automatically. Plan the reuse of threat intelligence and evidence rather than assuming a single engagement clears all of them.
Stingrai runs threat-led red team engagements and adversary emulation as a CREST-accredited penetration testing service provider, holding firm-level CREST accreditation. Our red teaming service supports the evidence financial entities need for DORA, and our broader offensive security services and continuous PTaaS keep the application layer tested between regulated cycles. Pricing is published at stingrai.io/pricing.
Frequently asked questions
How many organizations must run a TLPT under DORA, and are there enough accredited red team providers to serve them?
The exact number of entities designated for mandatory TLPT is not public, because national competent authorities notify entities privately and the identification criteria live in Commission Delegated Regulation (EU) 2025/1190 rather than in a published list. What is countable points to a wide gap. DORA reaches more than 22,000 financial entities (PwC), the ECB alone directly supervises 110 significant banks (ECB, 1 May 2026), and the CREST public register lists just 14 STAR-FS threat-led penetration testing providers and 31 firms in the broader threat-led specialism (CREST Marketplace, July 2026). The mandated population is measured in hundreds of systemic entities; the accredited provider pool is measured in dozens.
How many CBEST or STAR-FS accredited providers are there in 2026?
The CREST public register showed 14 providers accredited for STAR-FS threat-led penetration testing and 8 for STAR-FS threat intelligence when counted in July 2026, within a broader threat-led specialism of 31 firms and 541 accredited companies in total. CBEST provider accreditation is administered by the Bank of England rather than exposed as a countable filter on the CREST register, and the Bank of England does not publish a public provider count, so no CBEST figure is asserted here.
How often must a DORA TLPT be run?
Designated financial entities must carry out a threat-led penetration test at least once every three years, unless their national competent authority specifies otherwise. The requirement sits in DORA Article 26 and its technical standard, Commission Delegated Regulation (EU) 2025/1190, which became applicable on 8 July 2025.
What is the difference between DORA TLPT, TIBER-EU, CBEST and STAR-FS?
DORA TLPT is the EU-wide legal obligation, delivered through the ECB's TIBER-EU framework. CBEST is the Bank of England's scheme for the most systemic UK firms, and STAR-FS is a more scalable UK scheme for a broader population of financial firms. They share a common lineage and a four-phase engagement model, but each has its own regulator and accreditation. The TIBER, CBEST and DORA TLPT comparison sets them side by side.
How many TIBER tests have been conducted?
As of 27 April 2023, the ECB reported that over 100 TIBER tests had been conducted across the EU. That figure is a historical baseline from before DORA made threat-led testing a recurring legal obligation, so current annual volumes are higher, and the ECB updated the TIBER-EU framework to align with DORA in February 2025.
Why is there a capacity crunch for threat-led testing providers?
Demand and supply move on different clocks. DORA added a recurring, three-year testing obligation in a single step change, while the accredited provider pool grows one firm at a time behind a narrow accreditation gate. Each engagement is a multi-month campaign that needs both a threat-intelligence provider and a red team, and the register shows only 8 STAR-FS threat intelligence providers and 14 STAR-FS red team providers (CREST Marketplace, July 2026). A recurring pipeline of dozens of tests per year meeting a provider pool of dozens is a market that runs hot.
How much does a DORA TLPT cost?
A threat-led test is a multi-month engagement with separate threat-intelligence and red team costs, so it is priced as a campaign rather than a fixed-price scan. The DORA TLPT cost breakdown walks through the drivers, and Stingrai's own pricing is published at stingrai.io/pricing.
Does Stingrai provide threat-led penetration testing and red teaming?
Yes. Stingrai is a CREST-accredited penetration testing service provider, holding firm-level CREST accreditation, and runs threat-led red team engagements and adversary emulation that support the evidence financial entities need for DORA. Between regulated cycles, Stingrai's PTaaS and its autonomous web application pentest agent, Snipe, keep the application layer under continuous testing. See the red teaming service for scope.
When should an in-scope entity book its TLPT provider?
As early in the cycle as the scoping allows. With a small accredited pool, multi-month engagements, and a recurring obligation, provider calendar slots are the scarce resource, so booking early is a procurement strategy rather than a nicety. Entities that plan their cadence years ahead avoid the queue that builds toward each cycle deadline.
References
CREST. CREST Marketplace supplier register. Counted 22 July 2026. https://marketplace.crest.org/suppliers/. Public register of CREST-accredited providers with on-page filter counts by accreditation and specialism, including STAR-FS threat-led penetration testing and STAR-FS threat intelligence.
PwC. DORA and its impact on UK financial entities and ICT service providers. Retrieved 22 July 2026. https://www.pwc.co.uk/industries/financial-services/insights/dora-and-its-impact-on-uk-financial-entities-and-ict-service-providers.html. Source for the estimate that DORA applies to more than 22,000 financial entities and ICT service providers.
European Central Bank, Banking Supervision. List of supervised entities. Data as of 1 May 2026, published 26 June 2026. https://www.bankingsupervision.europa.eu/banking/list/who/html/index.en.html. Source for the count of 110 significant banks directly supervised by the ECB.
European Central Bank. More than 100 TIBER tests conducted. 27 April 2023. https://www.ecb.europa.eu/press/intro/news/html/ecb.mipnews230427.en.html. Historical baseline for the number of TIBER tests conducted across the EU.
European Central Bank. TIBER-EU framework updated to align with DORA. 11 February 2025. https://www.ecb.europa.eu/press/intro/news/html/ecb.mipnews250211.en.html. Confirms alignment of the TIBER-EU delivery framework with DORA.
European Union. Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing. Adopted 13 February 2025, applicable 8 July 2025. https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj/eng. The regulatory technical standard specifying criteria for identifying entities required to carry out TLPT, testing scope and methodology, and results handling.
EIOPA. Digital Operational Resilience Act (DORA). Retrieved 22 July 2026. https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en. Source for DORA covering around 20 types of financial entity.



