RegTech

DORA Testing de Resiliència per a Asseguradores: TLPT i Avaluacions de Vulnerabilitats

Equip IgeraSolutions
June 26, 2026
11 min read
Equip de ciberseguretat fent penetration testing — DORA TLPT asseguradores

DORA Resilience Testing for Insurance: TLPT and Vulnerability Assessments Explained

The Digital Operational Resilience Act (DORA, Regulation EU 2022/2554) has applied to all EU financial entities since 17 January 2025 — including insurers, reinsurers and insurance distributors in scope under Solvency II. Among its most demanding requirements is the digital operational resilience testing framework set out in Articles 24 to 27, which establishes differentiated obligations depending on the entity's risk profile and systemic significance.

Legal basis: Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector (DORA). Articles 24-27: Digital operational resilience testing framework. Applicable from 17 January 2025. Supplemented by DORA RTS packages published by the ESAs (JC 2023 86) and EIOPA guidelines for insurers.

The two-tier DORA testing framework

DORA structures resilience testing obligations into two tiers. Every in-scope insurer must implement the basic tier. Only entities designated as significant by the competent authority must conduct the advanced tier (TLPT).

Tier Test type Frequency Applies to
Basic (Art. 25)Vulnerability assessments, network & performance tests, gap analyses, BCP/DRP testsAt least annuallyAll DORA in-scope financial entities
Advanced (Art. 26)TLPT (Threat-Led Penetration Testing)Every 3 years (minimum)Significant entities designated by competent authorities

Article 25 DORA: basic testing requirements for all insurers

Article 25 mandates a programme of basic resilience tests covering at minimum:

  • Vulnerability assessments (VA): systematic identification and quantification of vulnerabilities in critical ICT systems — policy administration platforms, claims management systems, cloud-hosted data warehouses, network infrastructure. Must cover both internal systems and key third-party ICT services.
  • Open-source penetration tests: controlled attack simulations against defined critical systems to identify exploitable entry points, conducted by internal or external security teams.
  • Network and performance tests: stress testing of systems under extreme load conditions, including distributed denial-of-service (DDoS) scenarios relevant to the insurer's threat profile.
  • Business continuity and disaster recovery tests: simulation of major disruption scenarios (ransomware, critical third-party outage, data centre failure) to verify that Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) defined under Art. 11 are achievable in practice.
  • Gap analysis: structured comparison of current ICT security and resilience posture against DORA requirements, with prioritised remediation roadmap.

Test results, identified vulnerabilities and remediation plans must be documented in the ICT risk register and made available to the competent authority on request.

Article 26 DORA: TLPT for significant insurers

TLPT (Threat-Led Penetration Testing) is the most rigorous form of resilience testing under DORA. It is not a standard penetration test: it is a full-scope, intelligence-driven red team exercise that simulates sophisticated attacks by real-world threat actors against the insurer's most critical functions.

Who must conduct TLPT?

National competent authorities (NCAs) — for insurers in most EU member states, the national insurance supervisor in coordination with EIOPA — designate which entities must conduct TLPT. The criteria for designation include:

  • Size and systemic importance of the insurer in the domestic or EU-wide market.
  • Complexity and interconnectedness of ICT systems.
  • The impact a major ICT disruption would have on policyholders and financial stability.
  • Prior incidents or supervisory findings indicating elevated ICT risk.

Large composite insurers, major life and non-life groups and systemically relevant reinsurers are most likely to be designated. However, the competent authority has broad discretion, and designation can also apply to mid-sized entities with concentrated market share in critical insurance lines.

TLPT methodology: TIBER-EU framework

DORA's TLPT requirements align with the TIBER-EU framework developed by the European Central Bank, which provides a standardised methodology for threat-led ethical red-teaming across the EU financial sector. The four main phases are:

  • Preparation (3-4 months): define scope (critical functions and supporting ICT systems in scope), procure a certified Threat Intelligence Provider (TIP) and a certified Red Team Provider (RTP), obtain NCA approval of the test plan. The insurer's blue team (defensive security) must not know the test is about to begin.
  • Threat intelligence phase (2-3 months): the TIP produces a Targeted Threat Intelligence (TTI) report — a detailed profile of the real-world threat actors most likely to target the insurer, including their tactics, techniques and procedures (TTPs). The TTI drives the attack scenarios used in the red team phase.
  • Red team phase (3-4 months): the certified RTP executes the attack using the TTPs from the TTI report, targeting the in-scope critical functions in a fully realistic manner. The test runs unannounced from the perspective of the blue team.
  • Closure and remediation: a purple team exercise brings together the red team and blue team to share findings. A remediation plan must be agreed and submitted to the NCA. The NCA issues a formal TLPT attestation upon successful completion.

Article 27 DORA: involving third-party ICT providers in TLPT

For insurers that rely on critical third-party ICT providers (cloud platforms, outsourced claims management systems, premium payment processors), Article 27 allows — and in some cases requires — those third parties to be included in the TLPT scope. The practical implications:

  • The insurer must obtain the third party's consent to include them in the TLPT.
  • Where inclusion is not feasible, the third party may present recent TLPT certificates (issued within the prior 3 years) covering the relevant functions, which the insurer can use as evidence for its own DORA compliance.
  • The insurer retains ultimate responsibility for ensuring that third-party systems supporting critical functions meet DORA resilience standards — a TLPT certificate from a provider does not transfer liability.

Try IgeraRegTech Free

Index your compliance docs. Answer queries in seconds.

Start free →

Managing DORA testing documentation with IgeraRegTech

DORA's testing framework generates a significant volume of compliance documentation: test programmes, vulnerability assessment reports, TTI reports, purple team minutes, remediation plans, NCA attestations. Keeping this documentation organised, up-to-date and instantly accessible to compliance and audit teams is one of the key operational challenges for insurer compliance functions in 2025-2026.

IgeraRegTech indexes all DORA compliance documentation — the Regulation itself, DORA RTS packages (JC 2023 86), EIOPA guidelines, internal testing procedures, vendor contracts — and responds in seconds to queries such as:

  • "How often must we conduct a TLPT under Art. 26?" (Every 3 years, or when the NCA specifically requires it).
  • "Which ICT functions must be in-scope for our annual VA programme?" (Critical and important functions per the ICT asset register).
  • "Can we rely on our cloud provider's TLPT attestation rather than including them in our own test?" (Yes, if the certificate is less than 3 years old and covers the relevant functions — Art. 27.2).
  • "What must be included in the TLPT closure report submitted to the NCA?" (Defined in the DORA RTS on TLPT, Art. 26.3 and EIOPA technical guidance).

Every answer cites the exact DORA article, the applicable RTS section or the relevant EIOPA guideline — enabling compliance teams to give regulators precise, documented responses in audit or supervisory review situations.

For more information and a reference guide about this vertical, visit our Igera pillar page.

Frequently asked questions: DORA testing for insurance entities

Do captive insurers need to comply with DORA's testing requirements?

Yes, if they meet the size thresholds that bring them within DORA's scope. DORA applies to all financial entities as defined in Article 2, which includes insurance and reinsurance undertakings as defined in Solvency II (Directive 2009/138/EC), including captives. However, Article 4 of DORA includes proportionality provisions: micro enterprises (fewer than 10 employees and annual turnover under €2 million) benefit from simplified requirements, including less burdensome testing obligations.

What is the difference between a TLPT and a standard penetration test?

A standard penetration test identifies known technical vulnerabilities in defined systems, typically within a fixed timeframe and scope agreed in advance with the tested entity. A TLPT is more sophisticated: it is driven by real-world threat intelligence specific to the entity, uses the actual TTPs of known threat actors, targets the most critical business functions (not just technical systems) and is conducted without the defensive team's advance knowledge of timing or scope. The TLPT is designed to test whether real attackers could actually compromise critical functions — not just whether technical vulnerabilities exist.

How long does a full TLPT cycle take for an insurer?

Based on TIBER-EU experience, a full TLPT cycle typically takes 9 to 12 months from initial scoping to NCA attestation, split roughly as: 3-4 months preparation, 2-3 months threat intelligence, 3-4 months red team execution, and 1-2 months for closure, purple team and remediation plan submission. Insurers should begin planning well in advance of the 3-year cycle deadline — particularly given the limited pool of TIBER-EU certified providers in most EU jurisdictions.

Reviewed by: IgeraSolutions Compliance Team

How does IgeraRegTech help with regulatory compliance?

IgeraRegTech indexes complex regulations like DORA, NIS2, or the AI Act and answers compliance questions in seconds, citing the exact article and paragraph of the legal text.

Does the system hallucinate or invent regulatory articles?

No. Thanks to the RAG architecture, IgeraRegTech only answers based on the official texts of the directives and regulations loaded into the knowledge base.

#DORA resilience testing asseguradores#TLPT TIBER-EU DORA#vulnerability assessment DORA seguros#IgeraRegTech DORA#DORA Art 24-27

COMPARTIR

Comparte el conocimiento con tu red