Twenty European jurisdictions have now formally adopted the TIBER EU framework, according to the ECB’s own published list, spanning everywhere from Germany and France to Iceland and Malta. That’s not a framework sitting quietly in a policy drawer somewhere in Frankfurt. It’s become the default language European regulators use when they talk about testing whether a bank can actually withstand a real attack, not just pass a compliance checklist. And the list keeps growing, since new jurisdictions are still working through adoption as DORA’s testing obligations phase in.
The reason it carries this much weight ties directly to DORA. Under Articles 26 and 27, financial entities the ECB designates as significant, generally banks holding total assets above €30 billion under the ECB/SSM threshold, must run Threat-Led Penetration Testing at least once every three years. TIBER EU is the methodology the ECB built to make that testing consistent, defensible, and mutually recognized across borders. This guide breaks down what TIBER EU actually involves, who’s on the hook for it, how a test runs from start to finish, and how it connects to TIBER-DE, Germany’s national implementation of the framework.
What TIBER EU Actually Is?
TIBER EU stands for Threat Intelligence-Based Ethical Red Teaming, and TIBER Threat Intelligence sits at the center of the whole approach: every test is built around bespoke intelligence on adversaries who would realistically target that specific entity, not a generic threat list. It’s a framework, not a product or a single test type, developed jointly by the ECB and national central banks, approved by the ECB’s Governing Council, and published back in May 2018. It got a significant update in 2024 to bring it fully in line with DORA’s Regulatory Technical Standards on Threat-Led Penetration Testing.
Here’s the part that trips people up: a TIBER EU test doesn’t end with a score. There’s no pass or fail. The whole exercise is designed to surface how an organization’s people, processes, and technology actually hold up against a simulated version of a real attacker, using real threat intelligence about who would plausibly target that specific entity. What comes out the other end is a picture of where the resilience gaps are, not a certificate.
Recent update:
TIBER-EU is one of the most relevant cyber resilience frameworks in 2026, particularly for financial organisations getting ready for DORA-compliant threat-led penetration testing. It is developed by the ECB and the EU national central banks, and involves conducting realistic threat scenario tests of people, processes, and technology. TIBER-EU can now be applied and supports selected financial entities in proving their operational resilience through controlled, real-world attack simulations.
The Five Teams Behind Every TIBER EU Test
| Team | Role |
| Blue team | The entity’s own staff being tested, kept unaware a test is happening |
| Threat intelligence provider | Researches realistic threats and profiles the entity |
| Red team testers | Carries out the simulated attack, mimicking a real adversary |
| Control team | Small internal group that knows about the test and manages it |
| TIBER cyber team | The regulator’s oversight team, ensuring the test meets framework requirements |
This structure is what makes mutual recognition across jurisdictions possible. Because every national TIBER cyber team applies the same core requirements, a test run in one country can be recognized by regulators in another, which matters enormously for banks operating across multiple EU markets. That consistency is really the backbone of TIBER security as a discipline: the same five roles, the same standards, regardless of which country is running the test.
What Are the Steps of a TIBER-EU Assessment?

A TIBER-EU assessment is conducted in three phases, within 6 to 12 months. Every phase must be documented through official milestone documentation that shows compliance with DORA requirements in Articles 26 and 27.
A test moves through three broad stages, each with its own formal documentation.
| Stage | What Happens | Key Output |
| Preparation | Scope agreed, threat intelligence gathered | Initiation and scope specification documents |
| Testing | Red team attacks based on the threat intel; blue team defends without knowing | Red team test report, blue team report |
| Closure | Findings reviewed, gaps addressed, results formalized | Remediation plan, test summary report, attestation |
Step 1: Preparation
The Preparation stage involves setting up the governance of the assessment, scope, and testing team for the exercise. This stage also ensures that the assessment is done in complete confidentiality.
- Forming the Control Team: An internal control group, composed of just 2-3 senior members, can be assigned to oversee the process. The SOC and IT security staff remain unaware of the penetration test. It helps to calculate their effectiveness in detecting and responding to the threat posed by the simulation.
- Mapping Critical Functions: Instead of selecting a random block of IP addresses, scoping concentrates on your central business processes. It includes payment gateways, wire transfer clearing, and customer portals, along with cloud services and third-party APIs that support them.
- Selecting Accredited Testers: The qualified Threat Intelligence Provider (TIP) and Red Team Tester (RTT) will be responsible for carrying out the test. The providers should be capable and accredited within the industry, such as CREST, for conducting threat-led penetration testing.
Step 2: Testing
During this testing phase, live production systems are attacked by simulating an attack based on threat intelligence over several weeks.
- Gathering Threat Intelligence: The threat intelligence vendor conducts research on actual threat actors who target the financial industry. They create attack scenarios based on their tactics, techniques, and procedures (TTPs).
- Targeted Threat Intelligence Report (TTIR): It describes adversary profiles that apply to the situation. It shows possible entry points and an attack path for the specific organisation.
- Execution of the Red Team Attack: Professional hackers conduct a stealthy, multi-step attack on live systems within at least 12 weeks. They use digital, physical, and social approaches.
Step 3: Closure
The closure phase converts the attack findings into security improvements and compliance evidence.
- Mandatory Purple Teaming: The attacker and defender teams work together in collaborative sessions. This works through the SIEM and EDR log data step-by-step to see where alerts have been missed. They also adjust your detection rules accordingly.
- Running Scenario Replays (Leg-Ups): If the defender stops an attack by mistake in the live window, the control team grants the attacker team temporary access. Then the attacker team tests the downstream internal controls and lateral access.
The attestation at the end is what makes the whole thing worth doing from a regulatory standpoint. It’s the document that lets a competent authority in one country accept a test conducted under another jurisdiction’s TIBER programme, cutting down duplicate testing for entities that operate across borders.
What Common Challenages An Organization Can Face While Preparing for a TIBER-EU Assessment?
Preparation for TIBER-EU testing involves various challenges in terms of processes, organisation, and technology for financial institutions. It can be difficult for organisations performing threat-led red teaming for the first time.
- Defining Scope and Critical Functions: Identifying critical business services, such as clearing platforms and payment gateways, requires cross-department coordination.
Teams must also map the related IT resources, data flows, and third-party dependencies. - Maintaining Strict Secrecy: You have to conduct the test with a small internal team of Controllers. Ensure that the defenders are unaware of it by applying strict access control and isolated communication channels.
- Selecting and Onboarding Vendors: Locating and obtaining Threat Intelligence and Red Team service providers. Ensuring they are certified (like CREST certification) and comply with regulations takes a lot of time.
- Permission from Third Parties: If there are cloud providers or banks involved in the assessment process, then they might require approval prior to doing the assessment. This may lead to additional delays in assessing your business.
TIBER EU vs. Traditional Penetration Testing
| Dimension | TIBER EU / TLPT | Traditional Penetration Testing |
| Scope | Live production systems, full attack chain | Defined systems or applications |
| Awareness | Blue team doesn’t know a test is happening | Defenders typically know testing is scheduled |
| Basis | Bespoke threat intelligence on real adversaries | Standard methodology, less adversary-specific |
| Outcome | Resilience insight, no pass/fail score | Vulnerability list with severity ratings |
| Oversight | Regulator-supervised via TIBER cyber team | Internal or contractual only |
| Mutual recognition | Yes, across adopting jurisdictions | No |
This is really the core answer to how TIBER EU differs from a standard pentest: it’s testing whether your actual detection and response holds up under a real attack simulation, not just whether a vulnerability exists somewhere in your stack.
TIBER EU, DORA, and TIBER-DE
The TIBER DORA relationship is worth being precise about. DORA didn’t invent threat-led testing from scratch. It leaned on TIBER EU, which had already been running since 2018, and folded it into binding law for significant financial entities across the EU. If your institution gets designated for TLPT under DORA Articles 26-27, adopting TIBER EU (or your country’s national variant of it) is the ECB’s recommended path to satisfying that obligation cleanly.
Germany’s version is TIBER-DE, coordinated through the Bundesbank rather than run centrally by the ECB. The core methodology doesn’t change. What differs is national coordination, procurement guidance for local threat intelligence and red team providers, and how the German TIBER cyber team interfaces with entities operating in that market specifically. An institution operating in both Germany and, say, France would go through TIBER-DE for its German operations and the French national implementation for its operations there, with both recognized under the same overarching TIBER EU structure.
Which Organizations Need to Implement TIBER EU
Developers built the framework primarily for core financial infrastructure, banks, payment systems, and market infrastructure providers, but it’s also usable across other critical sectors, and several jurisdictions have adopted it accordingly. In practice, three groups end up implementing it:
- DORA-designated significant entities. Banks and other financial institutions above the ECB/SSM asset threshold, formally notified by their competent authority.
- Entities operating across multiple EU jurisdictions. Mutual recognition makes TIBER EU the practical choice even where it’s not strictly mandatory yet.
- Organizations preparing ahead of designation. Given a full cycle can take the better part of a year from provider selection to attestation, waiting for the formal notification before starting isn’t a great strategy. By the time the letter arrives, the clock is already running, and provider procurement alone can eat months of that runway.
Best Practices for Preparing and Executing a TIBER-EU Test
Financial institutions can successfully navigate a TIBER-EU assessment by following proven operational strategies that minimize testing risks while satisfying European Central Bank regulatory expectations.
- Establish an internal management team for governance purposes and ensure total confidentiality.
- Ensure that the scope of the test is concentrated on critical business services. That includes payment gateways and wire clearing services, instead of IP address ranges.
- Choose external Threat Intelligence Providers (TIPs) and Red Team Testers (RTTs) with recognised industry credentials.
- Establish stringent testing guidelines and enable logging in real time with stop mechanisms in case of emergencies to safeguard the live production environment.
- Engage cloud providers and key banking software vendors at an early stage in order to ensure approvals for testing without causing any delays.
- Come together as an attacker-defender duo post-test to go through the telemetry logs, spot deficiencies, and prepare a Remediation Action Plan.
How Qualysec Helps With TIBER EU & DORA TLPT Readiness
Achieving success in a TIBER EU or DORA Threat-Led Penetration Test (TLPT) requires rigorous preparation long before live testing begins. As a CREST-accredited cybersecurity firm, Qualysec delivers the technical rigor, ethical frameworks, and supervisory assurance required by EU financial regulators.
Backed by 2,500+ completed security assessments across 38+ countries, Qualysec bridges the gap between complex regulatory mandates and real-world defense through a specialized readiness approach:
Threat Intelligence-Led Assessment Design:
Qualysec builds bespoke threat profiles tailored to an entity’s actual risk exposure, industry, and adversary landscape. In line with official TIBER EU threat intelligence (TI) guidance, organizations enter regulatory scoping conversations already knowing where their true exposure lies.
TIBER EU Red Team Simulation:
Utilizing a hybrid methodology – combining senior ethical hackers, AI testing agents, and deep manual analysis – Qualysec executes live-system, full-attack-chain simulations. This realistic dry run mimics advanced persistent threats (APTs) against critical functions rather than relying on standard vulnerability scans.
Control Team & Audit-Ready Documentation:
Setting up internal White/Control Teams and producing initiation, scoping, and remediation artifacts is unfamiliar territory for most institutions. Qualysec builds this internal capacity and generates audit-ready documentation to ensure complete compliance before a mandate is on the calendar.
Take the uncertainty out of regulatory testing. Schedule a TIBER EU and DORA TLPT readiness consultation with Qualysec’s CREST-certified experts!
Key Takeaways
- TIBER EU is the ECB’s framework for threat intelligence-based ethical red teaming, adopted across 20 European jurisdictions.
- It’s not pass/fail. The point is to reveal genuine strengths and weaknesses in an entity’s cyber resilience.
- Five distinct teams run every test: blue team, threat intelligence provider, red team, control team, and TIBER cyber team.
- TIBER EU is the ECB’s preferred route for satisfying DORA’s Threat-Led Penetration Testing requirement.
- Germany implements the framework nationally as TIBER-DE, coordinated through the Bundesbank.
Conclusion
TIBER EU isn’t a checkbox exercise, and that’s really the point of it. Twenty jurisdictions have adopted it precisely because it gives regulators and institutions alike a shared language for what cyber resilience actually means in practice, tested against real threat intelligence rather than a generic list of known vulnerabilities. With DORA now binding TLPT into law for significant entities, understanding how TIBER EU works, who’s involved, and how it connects to national implementations like TIBER-DE isn’t optional homework anymore. It’s the difference between walking into a mandatory test prepared or walking in cold.
Contact Qualysec to build TIBER EU readiness into your organization’s cybersecurity programme!
Frequently Asked Questions
1. How is TIBER-DE different from traditional penetration testing?
TIBER-DE, Germany’s national implementation of TIBER EU coordinated through the Bundesbank, tests live production systems using bespoke threat intelligence about real adversaries, without the defending team knowing a test is underway. Traditional penetration testing usually covers defined systems on a known schedule and produces a vulnerability list. TIBER-DE produces a resilience assessment instead, with no pass or fail outcome, and it’s supervised by a national TIBER cyber team rather than run purely as an internal or vendor engagement.
2. What are the key phases of a TIBER-DE assessment?
Like all TIBER EU implementations, TIBER-DE runs through preparation (scoping and threat intelligence gathering), testing (the red team attack and blue team defense), and closure (remediation planning and formal attestation). Each phase produces specific documentation, including a scope specification, a targeted threat intelligence report, red and blue team reports, and a final test summary report and attestation.
3. What are the benefits of implementing TIBER-DE?
Beyond satisfying DORA’s TLPT requirement, TIBER-DE gives institutions a genuine, evidence-based picture of their detection and response capabilities under realistic attack conditions. It also enables mutual recognition: a TIBER-DE test can be accepted by regulators in other TIBER EU jurisdictions, reducing duplicate testing for institutions operating across multiple European markets.
4. How can organizations prepare for a TIBER-DE red team assessment?
Preparation starts well before formal designation. Building an internal control team, developing baseline threat intelligence about likely adversaries, and running informal TIBER EU red team exercises against live systems all help an organization walk into a formal TIBER-DE test with fewer surprises. Given a full cycle typically takes many months from provider selection through attestation, early preparation matters more than most institutions initially expect.
5. Which organizations should implement TIBER-DE?
Financial institutions in Germany designated as significant under DORA’s ECB/SSM asset threshold are the primary group required to implement TIBER-DE. Beyond that mandatory group, institutions operating across multiple EU jurisdictions often adopt it voluntarily for the mutual recognition benefit, and other critical infrastructure operators in Germany can use the framework even outside the financial sector.






