Three regimes, one discipline

Threat-led penetration testing across CBEST, STAR-FS and DORA

TLPT is the same discipline wearing three regulatory uniforms. UK systemic firms meet it as CBEST, the rest of the UK market as STAR-FS, and groups with EU entities as DORA's TLPT obligation. This page puts the three side by side: who must test, on what cycle, who delivers, and how a dual-scoped firm avoids paying for the same test twice.

The essentials

What TLPT is

Threat-led penetration testing (TLPT) is security testing built on intelligence about the real adversaries most likely to target your firm: testers replicate those adversaries' methods against live production systems, under controlled conditions. In financial services it is a regulatory instrument, run under CBEST, STAR-FS or DORA's TLPT provisions rather than as an ordinary penetration test.

Two things separate it from the annual pentest your firm already buys. The scenarios come from threat intelligence about who would actually attack you, not from a generic methodology. And the target is production, because the question being answered is not whether an application has flaws but whether the firm, people and processes included, withstands a capable adversary.

Reviewed July 2026.

The comparison

CBEST, STAR-FS and DORA TLPT, side by side

All three descend from the same TIBER-EU family of frameworks, which is why the table's rows rhyme. The differences that matter sit in who is compelled, who initiates and who oversees.

Regime Who must test Cycle Who delivers Who runs and oversees it
CBEST The UK's systemic firms and financial market infrastructures On the supervisors' schedule; firms are invited, not enrolled Accredited threat intelligence and red team providers Bank of England, with the PRA and FCA
STAR-FS UK financial firms outside the systemic tier No fixed cycle; firms can initiate it themselves CREST-accredited providers CREST runs the scheme, aligned to the Bank of England's framework
DORA TLPT In-scope EU financial entities designated by their authorities At least every three years Testers meeting DORA's requirements EU authorities, under a TIBER-EU aligned framework

The CBEST and STAR-FS rows are unpacked fully, including how to prepare for either, in our CBEST preparation guide. DORA's scope question, whether it reaches your UK firm at all, lives on the DORA page.

One test, several masters

How the regimes interact for dual-scoped firms

A UK banking group with an EU subsidiary can find itself owing threat-led testing to two authorities on two clocks. Because the regimes share TIBER-EU ancestry, the same anatomy of threat intelligence, red team and remediation underlies each, so a single engagement can often be scoped to satisfy more than one, provided the scope covers the entities, systems and scenarios each authority cares about, and provided the conversation with each happens before the test rather than after it.

Get that scoping wrong and the group pays for two full tests, or worse, presents one authority with a test scoped for the other. Get it right and the marginal cost of the second regime is paperwork and negotiation rather than a second red team. That negotiation is preparation work, and it is precisely the layer we sell.

The readiness service

Scoping and preparation, at a fixed fee

Our TLPT readiness engagement covers three layers, for scoped to your regime and estate, confirmed in writing before work starts, alongside everything published on the pricing page.

Regime mapping

Which of the three frameworks applies to your firm, on what cycle, and whether a single test can be scoped to satisfy more than one authority. This is decided before any provider is approached, and it is the decision that sets the cost of everything after it.

Readiness build

Important business services mapped, impact tolerances evidenced, scenario history assembled, stakeholder and secrecy plans agreed. The same four assets serve every regime, so the work is done once.

Intelligent buying

Provider shortlists, scoping negotiation, and challenge on your side of the table when the test plan, rules of engagement and findings arrive. You buy one of these tests rarely; the people opposite you sell them for a living.

The readiness build leans on the same scenario testing discipline the FCA regime already asks of you, so nothing is done twice.

Who does what

The boundary, stated plainly

CBEST and STAR-FS testing is delivered by accredited providers, and we do not claim that chair. Our role is the one beside you: readiness, regime mapping, scoping negotiation and acting as your intelligent buyer from first shortlist to final findings meeting. Firms that arrive at a threat-led test with that layer in place get a test scoped to their reality and findings they can act on.

And if what you actually need is conventional penetration testing of applications and infrastructure, that is delivered by CyPro directly, outside any of these regimes. Start with the CBEST guide if the UK schemes are your question, or the DORA page if the EU one is.

Quick answers

TLPT questions, answered

What is TLPT?

Threat-led penetration testing is security testing scripted by intelligence about the adversaries most likely to target your firm, executed against live production systems under controlled conditions. In financial services it is a regulatory instrument rather than a hygiene exercise, run under CBEST, STAR-FS or DORA's TLPT provisions depending on who regulates you.

Does DORA require penetration testing?

DORA requires all in-scope financial entities to maintain a resilience testing programme, and it requires TLPT specifically from entities designated by their authorities, at least every three years, under a TIBER-EU aligned framework. A UK firm meets this through its EU entities: if the group has none, DORA's testing obligations do not reach it directly.

Does DORA apply to your UK firm?

Which regime applies to us?

Broadly: systemic UK firms should expect CBEST through their supervisors; other UK financial firms have STAR-FS available to initiate themselves; and groups with in-scope EU entities may owe DORA TLPT as well. Many firms sit under more than one, which is exactly when scoping a single test to serve several masters earns its keep.

Rocket above the Operational Resilience UK call to action

Know your regime first

Map your testing obligations in one call

A call establishes which regimes reach your group, what cycle you are on, and whether one well-scoped test can serve them all. The readiness fee is fixed and published.