A DORA threat-led penetration test designation starts a legal clock, and the first document is due at three months. Under Article 9(2) of Commission Delegated Regulation (EU) 2025/1190, a designated financial entity must submit its TLPT initiation documentation within 3 months of receiving the notification from its TLPT authority (EUR-Lex). That single deadline, roughly 90 days, is why the first 90 days set the pace for a cycle that runs 9 to 14 months end to end. Miss it, or arrive at it without a control team and without providers engaged, and every later milestone slides.
This post is the execution playbook for the days immediately after the notification lands. It answers a narrow, high-stakes question for the security and risk leaders who just got the letter: what do we actually have to do, and by when. The companion Stingrai posts already cover what TLPT is and how long it takes, what it costs, and how DORA TLPT, TIBER-EU, CBEST, and STAR-FS relate. This one owns the post-notification execution: the documents, the windows, the article numbers, and the procurement that has to start now.
Every deadline and article number below was checked against the regulation text of Commission Delegated Regulation (EU) 2025/1190 on the EUR-Lex Official Journal and confirmed against the per-article breakdown on Springlex. RTS 2025/1190 was published in the Official Journal on 18 June 2025 and became applicable on 8 July 2025. Where a duration is an industry delivery estimate rather than a regulated window, it is labeled as such and attributed to a named source, so any figure here can be audited inline.
The short answer: what to do in the first 90 days, and by when
We just received a DORA TLPT designation. What do we have to do in the first 90 days, and by when?
In the first 90 days you must do four things in parallel. First, stand up your control team and appoint a control team lead, the organisational arrangement required under Article 4 before anything else moves. Second, prepare and submit your initiation documentation within 3 months of the notification, the first hard deadline under Article 9(2), which includes a project charter and high-level plan, a code name, control team contacts, and tester details. Third, begin procuring the two external providers you are required to engage, an external threat intelligence provider and an external red team, selected and kept separate under Article 7. Fourth, start the scoping work for the scope specification document, which is due at 6 months under Article 9(6) and cannot be produced from a standing start in month five. The notification is day zero. The 3-month initiation deadline is the checkpoint that tells you whether the other three are on track.
TL;DR: the deadlines that matter
First hard deadline, initiation documentation: within 3 months of notification (RTS 2025/1190, Article 9(2)).
Scope specification document: within 6 months of notification (Article 9(6)).
Control team and organisational arrangements: required from the start of the preparation phase (Article 4).
Two external providers, kept separate: threat intelligence provider and red team, selected under Article 7; external testers required at least every third test under DORA Article 26(8).
Active red team phase: at least 12 weeks (Article 11).
Closure phase, replay and purple teaming: no later than 10 weeks after the active phase ends (Article 12).
Remediation plan to the authority: within 8 weeks of the report being confirmed complete (Article 13).
Attestation: issued at cycle close (Article 14).
Full cycle, procurement to attestation: 9 to 14 months (regulation-dora.eu); the shorter 6 to 12 month figure measures a narrower window, reconciled below.
RTS applicable since: 8 July 2025, published in the Official Journal on 18 June 2025 (EUR-Lex).
Key takeaways
The 3-month initiation deadline is the real starting gun, not the notification. The notification tells you that you are in scope; Article 9(2) tells you that you have about 90 days to submit initiation documentation. Treat the notification date as the day the clock started, and work backward from the 3-month mark for everything that has to be true by then.
Provider procurement is the step that cannot wait, and it is a dual purchase. You need two separate external providers, a threat intelligence provider and a red team, under Article 7. The accredited pool for financial-grade threat-led testing is small, so calendar slots are the scarce resource. This is exactly why the demand versus supply math argues for booking early rather than at the deadline.
Scoping starts in the first 90 days even though it is due at six months. The scope specification document under Article 9(6) requires identifying critical and important functions and getting management-body approval. That approval cycle alone can consume weeks, so the work belongs inside the 90-day window.
The 6 to 12 versus 9 to 14 month cycle-length figures are not a contradiction. They measure different windows. The shorter figure brackets the testing engagement; the longer figure adds front-end procurement and back-end remediation and attestation. Knowing which one an advisor is quoting keeps your programme plan honest.
A clean application layer at the start saves red team weeks later. Every known application flaw the red team has to rediscover is a week not spent emulating a real adversary. Entities that keep the web-application layer continuously tested through the long runway hand the red team a harder, more realistic target.
The milestone and obligation map
The table below maps each RTS-mandated obligation to its window and its specific article in Commission Delegated Regulation (EU) 2025/1190. Windows are measured from the notification date unless noted. The first four rows are the first-90-days work; the remainder is the runway they set up.
Milestone / obligation | What it is | Window | RTS 2025/1190 article |
|---|---|---|---|
Designation notification | TLPT authority notifies the entity it must perform a TLPT | Day 0, the clock starts | Art 2 (identification), Art 3 (test managers) |
Control team stood up | Appoint a control team lead, put organisational arrangements and TLPT risk management in place | Days 1 to 30 | Art 4, Art 5 |
Initiation documentation | Project charter and high-level plan, code name, control team lead contact, tester details, communication channels | Within 3 months | Art 9(2) |
Provider procurement | Engage an external threat intelligence provider and an external red team, kept separate, meeting the experience thresholds | Start in the first 90 days | Art 7 (Art 15 internal testers; DORA Art 26(8)) |
Scope specification | Scope document covering critical and important functions, with management-body approval | Within 6 months | Art 9(6) |
Threat intelligence phase | Targeted threat intelligence report that drives the red team scenarios | Testing phase | Art 10 |
Active red team testing | Live red team attack against production systems | At least 12 weeks | Art 11 |
Closure phase | Red team report within 4 weeks, then blue team report, replay, and purple teaming | No later than 10 weeks after the active phase | Art 12 |
Remediation plan | Remediation plan submitted to the TLPT authority | Within 8 weeks of report completeness | Art 13 |
Attestation | TLPT authority issues the attestation | Cycle close | Art 14 |

Day 0: what the notification actually means
The clock starts when your TLPT authority notifies you that you are designated to perform a threat-led penetration test. Entities are identified for mandatory TLPT under Article 2 of RTS 2025/1190, using criteria tied to their systemic importance, financial impact, and ICT risk profile, and the authority side of the engagement is run by test managers defined under Article 3. The designation itself is confidential between the entity and the authority; there is no public register of who has been designated.
Two practical points follow. First, the notification date is the anchor for every window in the table above, so record it precisely and circulate it to everyone who owns a downstream deliverable. Second, the criteria in Article 2 mean designation is not a surprise for the systemically important firms most likely to receive it. If your institution is a significant bank, a large insurer, a major payment institution, a central securities depository, a central counterparty, or a trading venue, you should be preparing before the letter arrives, not after. Named advisories expect the first designation notifications to land from 2026 into 2027 as competent authorities finish standing up their designation processes (SureCloud), which makes this the right moment to build the muscle.
Days 1 to 30: stand up the control team
Before you produce a single document, you need the team that will own the engagement inside your organisation. Article 4 requires financial entities to put organisational arrangements in place and to appoint a control team lead responsible for the day-to-day management of the TLPT. The control team is deliberately small and senior. It is the group that will select and manage providers, control who inside the organisation knows the test is happening, make the risk decisions, and prepare the scoping and initiation documentation.
Alongside the control team, Article 5 requires TLPT-specific risk management. A live red team test against production systems carries operational risk, and the regulation expects that risk to be identified, owned, and mitigated before testing begins. In practice, the first 30 days are about three appointments and one sign-off: name the control team lead, assign the control team members, secure executive sponsorship, and get the risk-management approach documented. None of this is a deliverable to the authority yet, but all of it has to be true before the initiation documentation can be honest.
Days 1 to 90: the initiation documentation
The initiation documentation is the first hard deadline in the entire TLPT. Under Article 9(2), the financial entity must submit it within 3 months of receiving the notification. This is the deliverable that gives the "first 90 days" its shape. It is prepared during the preparation phase, which Article 9 governs end to end.
The initiation documentation is not a single form. It bundles the artefacts the authority needs to see that the engagement is real and well governed: a project charter with a high-level plan, a code name for the test, the control team lead's contact details, information on the internal and external testers you intend to use, and the communication channels for the engagement. The dependency chain is the reason this belongs to the first 90 days rather than the last week before the deadline. You cannot name your testers until you have started procurement. You cannot write a credible high-level plan until you know roughly who is delivering and when. The initiation documentation is where the first 30 days of team standup and the parallel work of provider procurement both have to show up on paper.
Provider procurement: the dual purchase that starts now
TLPT is delivered by two distinct external functions, and the regulation keeps them apart on purpose. Under Article 7, a designated entity selects an external threat intelligence provider and an external red team, and the two must be separated so that the people writing the threat intelligence are not the people executing the attack. The experience thresholds are specific: the threat intelligence provider must field a manager with at least five years of threat intelligence experience plus a further member with at least two years, and the red team must field a manager with at least five years of penetration testing and red team experience plus at least two more testers with at least two years each. These are not providers you can stand up internally at short notice.
There is an internal-tester route under Article 15, but it is narrow. Internal testers are subject to a policy and competence assessment, and even when an entity uses them, DORA Article 26(8) requires that external testers be used at least every third test, and the threat intelligence for an internal-tester TLPT must still come from an external provider. For most entities in their first cycle, the practical answer is two external providers.
This is the conversion point of the whole timeline. Procurement is the one first-90-days task that depends on a market outside your control, and that market is tight. As the TLPT demand versus supply analysis sets out, the accredited pool for financial-grade threat-led testing is measured in dozens of firms against a regulated population measured in the hundreds of systemic entities. Provider calendar slots, not budget, are usually the binding constraint. Two moves reduce the risk. Start provider conversations in the first few weeks, not after the initiation documentation is filed, and use a clear buyer checklist so you can move quickly once you shortlist. Stingrai's guides on how to choose a threat-led penetration testing provider and on red team rules of engagement are built for exactly this step.
Stingrai supports this procurement directly. As a CREST-accredited penetration testing service provider holding firm-level CREST accreditation, with a London office and a threat-led red teaming practice, Stingrai delivers the human-led red team side of a threat-led engagement and produces the evidence financial entities need for their DORA programmes. The engagement is run by senior human pentesters, which is what a live TLPT against production demands.
By 6 months: the scope specification
The second regulated deadline is the scope specification document, due within 6 months of notification under Article 9(6), and it is the reason scoping cannot wait until after the initiation documentation is filed. The scope document identifies the critical and important functions to be tested and the systems that underpin them, and it requires management-body approval. That approval is not a rubber stamp. Deciding which critical or important functions are in scope is a board-level risk conversation, and scheduling it, briefing it, and getting sign-off can consume weeks on its own.
The sequencing that works is to begin identifying critical and important functions during the first 90 days, in parallel with the initiation documentation, so that the scope document is a refinement of work already underway rather than a fresh start in month five. The threat intelligence you procure will sharpen the scope, because real adversary interest in your functions is part of what makes a scope defensible, which is another reason procurement and scoping run together rather than in sequence.
What the first 90 days set up: the runway to attestation
The first 90 days exist to make the rest of the cycle run cleanly. Once the initiation documentation and scope are accepted, the engagement moves through its testing and closure phases.
The threat intelligence phase under Article 10 produces a targeted threat intelligence report that models the adversaries most likely to target your in-scope functions and turns them into concrete attack scenarios. The active red team phase under Article 11 is the live attack, and it must run for at least 12 weeks, with the testers reporting to the control team at least weekly. The closure phase under Article 12 is where the defensive value concentrates: the red team submits its report within 4 weeks of the active phase ending, the blue team submits its own report, and the two sides replay the offensive and defensive actions and run purple teaming on jointly identified topics, no later than 10 weeks after the active phase ends. Closure is followed by the remediation plan under Article 13, submitted to the authority within 8 weeks of the report being confirmed complete, and finally the attestation under Article 14 that records the TLPT was conducted in line with the regulation.

Reconciling the cycle-length figures: 6 to 12 versus 9 to 14 months
Advisories quote different total durations for a TLPT, and the gap confuses planning. One widely cited figure is 6 to 12 months (Yogosha). Another is 9 to 14 months (regulation-dora.eu). Both are defensible, because they measure different things.
The shorter 6 to 12 month figure brackets the testing engagement: roughly from the point providers are engaged and scoping is settled, through the threat intelligence phase, the 12-week active red team phase, and closure. It is the window a red team delivery lead has in mind when they estimate "how long will the test take."
The longer 9 to 14 month figure measures the full regulatory cycle from provider procurement to attestation. It adds the front-end work the shorter figure assumes is already done, the procurement and preparation that fill the first 90 days, and the back-end obligations that follow closure, the 8-week remediation-plan submission under Article 13 and the attestation under Article 14. Some advisories stretch this further still, toward 18 months, once real-world scheduling and board approvals are added.
For your own programme plan, the safe reading is the longer one. Plan against 9 to 14 months from the day you begin procurement, treat the 6 to 12 month figure as the testing core inside it, and remember that the regulated windows, 3 months to initiation documentation, 6 months to scope, at least 12 weeks of active testing, are floors and checkpoints, not the whole schedule.
A go or no-go readiness check for the 90-day mark
Use the checklist below as a self-scored go or no-go at roughly the 60 to 75 day mark, while there is still time to correct course before the 3-month initiation deadline. Score each item green if it is done, amber if it is in progress with a credible finish date, and red if it has not started. Any red on the control team or on provider procurement is a programme risk that should escalate immediately, because those two items gate everything else.
Readiness item | RTS anchor | Green means |
|---|---|---|
Control team lead named and mandated | Art 4 | Named, with authority to make engagement decisions |
Executive sponsorship and TLPT risk sign-off | Art 5 | Documented risk approach, sponsor identified |
Threat intelligence provider engaged or shortlisted | Art 7 | Shortlist confirmed, slot conversation started |
Red team provider engaged or shortlisted | Art 7 | Shortlist confirmed, slot conversation started |
Provider separation confirmed | Art 7 | Threat intel and red team are distinct, non-conflicting |
Initiation documentation drafted | Art 9(2) | Charter, code name, contacts, tester details in draft |
Critical and important functions identified | Art 9(6) | Draft list ready for management-body approval |
Board approval slot booked for scope | Art 9(6) | Calendar date held inside the 6-month window |
Blue team briefed on closure and replay duties | Art 12 | Aware of report and purple-teaming obligations |
Remediation capacity and budget reserved | Art 13 | Owner and budget line identified |
Application layer already under continuous testing | Supports Art 11 efficiency | Known app flaws are being fixed, not left for the red team |
A programme that is mostly green here will hit the 3-month initiation deadline with room to spare and reach the 6-month scope deadline without a scramble. A programme with reds against control team standup or provider procurement is the one that ends up filing thin initiation documentation and paying for it in every later phase.
What this means for defenders
Anchor the whole plan to the notification date and the 3-month mark. The initiation documentation deadline under Article 9(2) is the first thing an authority sees. Build your first-90-days plan backward from it and treat the control team standup and provider procurement as the two items that make it achievable.
Buy the red team calendar slot before you buy anything else. With a small accredited provider pool, the binding constraint is availability, not budget. Starting provider conversations in the first weeks is a procurement strategy, not an administrative nicety. The cost drivers and global framework reference help you brief internal stakeholders quickly.
Keep the application layer clean during the long runway. A TLPT is a scarce, expensive, multi-month engagement, and the red team should spend it emulating a real adversary, not rediscovering the same web-application flaws a scanner would find. Continuous penetration testing as a service keeps that layer tested between and during regulated cycles. Stingrai's autonomous web-application pentest agent, Snipe, hunts the complex classes that generic scanners miss, including broken access control, insecure direct object references, and business-logic flaws, so the human red team meets a harder target.
Treat the whole engagement as DORA evidence from day one. Every artefact the RTS requires, the initiation documentation, the scope, the reports, the remediation plan, is evidence for your operational-resilience programme. Structuring the engagement so those artefacts are clean and traceable is what turns a mandatory test into usable assurance. Stingrai's offensive security services are built to produce that evidence.
Frequently asked questions
We just received a DORA TLPT designation. What do we have to do in the first 90 days, and by when?
In the first 90 days you must stand up your control team and appoint a control team lead under Article 4, submit your initiation documentation within 3 months of the notification under Article 9(2), begin procuring an external threat intelligence provider and an external red team under Article 7, and start the scoping work for the scope specification document that is due at 6 months under Article 9(6). The 3-month initiation deadline is the checkpoint that shows whether the rest is on track.
What is the first hard deadline after a TLPT notification?
The initiation documentation, due within 3 months of receiving the notification under Article 9(2) of Commission Delegated Regulation (EU) 2025/1190. It includes a project charter and high-level plan, a code name, control team contacts, tester details, and communication channels. It is the first artefact your TLPT authority sees, so it anchors the first 90 days.
What goes into the TLPT initiation documentation?
Under Article 9(2), the initiation documentation bundles a project charter with a high-level plan, a code name for the test, the control team lead's contact details, information on the internal and external testers you intend to use, and the communication channels for the engagement. Because it names your testers, it cannot be completed until provider procurement is underway.
When is the scope specification document due?
Within 6 months of the notification, under Article 9(6). The scope document identifies the critical and important functions to be tested and requires management-body approval. Because that board approval can take weeks to schedule and secure, the scoping work should begin inside the first 90 days rather than in month five.
Do we have to use external testers, or can we test in-house?
You must engage an external threat intelligence provider and an external red team under Article 7, kept separate from each other. There is a narrow internal-tester route under Article 15, but DORA Article 26(8) requires external testers at least every third test, and the threat intelligence for an internal-tester TLPT must still be external. For most first-cycle entities, the practical answer is two external providers.
How long does the active red team phase last?
The active red team testing phase must run for at least 12 weeks under Article 11, with the testers reporting to the control team at least weekly. That 12-week minimum is a regulated floor, so it should be treated as the start of your planning range, not an upper bound.
Why do sources disagree on whether a TLPT takes 6 to 12 or 9 to 14 months?
They measure different windows. The 6 to 12 month figure (Yogosha) brackets the testing engagement from provider engagement through closure. The 9 to 14 month figure (regulation-dora.eu) measures the full cycle from provider procurement to attestation, adding the front-end preparation of the first 90 days and the back-end remediation and attestation. Plan against the longer figure and treat the shorter one as the testing core inside it.
When are the first DORA TLPT designations expected?
Named advisories expect the first designation notifications from 2026 into 2027 as competent authorities finish standing up their designation processes, with one guide noting that first notifications are expected in 2026 (SureCloud). Because designations are confidential, there is no public list, so systemically important entities should prepare ahead of the letter rather than wait for it.
When did RTS 2025/1190 take effect?
Commission Delegated Regulation (EU) 2025/1190 was published in the Official Journal on 18 June 2025 and became applicable on 8 July 2025, the twentieth day after publication under Article 17. It supplements Article 26 of DORA, Regulation (EU) 2022/2554, which has applied since 17 January 2025.
Does Stingrai deliver DORA TLPT red teaming?
Yes. Stingrai is a CREST-accredited penetration testing service provider, holding firm-level CREST accreditation, with a London office and a threat-led red teaming practice run by senior human pentesters. Stingrai delivers the red team side of a threat-led engagement and produces evidence that supports a financial entity's DORA programme. Between regulated cycles, Stingrai's PTaaS and its autonomous web-application pentest agent, Snipe, keep the application layer under continuous testing so the red team meets a harder target. Pricing is published at stingrai.io/pricing.
References
European Union. Commission Delegated Regulation (EU) 2025/1190 (RTS on threat-led penetration testing under DORA). Published in the Official Journal 18 June 2025, applicable 8 July 2025. https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj/eng. Primary text for every article number, document, and window cited here, including Article 9(2) initiation documentation, Article 9(6) scope, Article 11 active-phase minimum, and Article 12 closure.
European Union. Regulation (EU) 2022/2554 (DORA). Applicable from 17 January 2025. https://eur-lex.europa.eu/eli/reg/2022/2554/oj. Article 26 mandates threat-led penetration testing; Article 26(8) governs the use of internal and external testers.
Springlex. RTS on threat-led penetration testing, Article 9 (Preparation phase). Accessed July 2026. https://www.springlex.eu/en/packages/dora/rts-tlpt-regulation/article-9/. Per-article confirmation of the 3-month initiation and 6-month scope windows.
Springlex. RTS on threat-led penetration testing, Article 7 (Selection of TLPT providers). Accessed July 2026. https://www.springlex.eu/en/packages/dora/rts-tlpt-regulation/article-7/. Confirmation of the external threat intelligence and red team requirements, separation, and experience thresholds.
regulation-dora.eu. DORA TLPT: Threat-Led Penetration Testing Requirements. Accessed July 2026. https://www.regulation-dora.eu/tlpt. Source for the 9 to 14 month full-cycle duration from provider procurement to attestation and phase-by-phase delivery estimates.
Yogosha. DORA: Everything About Threat-Led Penetration Testing (TLPT). Accessed July 2026. https://yogosha.com/blog/tlpt-threat-led-penetration-testing/. Source for the 6 to 12 month engagement figure and the external-tester-every-third-test reading of DORA Article 26(8).
SureCloud. DORA Compliance Guide. Accessed July 2026. https://www.surecloud.com/resource-hub/dora-compliance-guide. Source for the expectation that first TLPT notifications arrive in 2026 and for the 12-week active-phase requirement.
European Central Bank. TIBER-EU Guide: How to implement the TIBER-EU framework for the DORA TLPT. 2025. https://www.bankingsupervision.europa.eu/ecb/pub/pdf/ssm.supervisory_guide202511.en.pdf. The implementation framework through which DORA TLPT is delivered, aligned to DORA in 2025.



