Audit methodology · Last verified
TIBER-EU
TIBER-EU is the ECB-coordinated, EU-wide framework for threat intelligence-based ethical red-teaming, aligned with DORA's threat-led penetration testing. Applying it is mandatory only for financial entities that DORA Article 26 designates for threat-led penetration testing at least every three years, not the whole financial sector.
- Class
- Audit methodology
- Owner
- European Central Bank (ECB), designed with EU national central banks and implemented by each member state's national TIBER cyber team
- Last verified
What it is
"TIBER-EU is a European framework for threat intelligence-based ethical red-teaming." It was developed by the ECB with EU national central banks and approved by the ECB Governing Council in May 2018.
The ECB does not run assessments centrally: each EU member state implements the framework through its own national TIBER cyber team, while the ECB hosts the TIBER-EU Knowledge Centre as a coordination forum.
"The TIBER-EU framework can also assist competent authorities and financial entities in meeting the requirements for threat-led penetration tests under the Digital Operational Resilience Act (DORA)."
DORA's own text is explicit on the underlying legal obligation: "Financial entities... shall carry out at least every 3 years advanced testing by means of TLPT... the competent authority may, where necessary, request the financial entity to reduce or increase this frequency," and "Each threat-led penetration test shall cover several or all critical or important functions of a financial entity, and shall be performed on live production systems."
"The Eurosystem updated its European framework for threat intelligence-based ethical red-teaming (TIBER-EU framework), to align with the regulatory technical standards (RTS) of the Digital Operational Resilience Act (DORA) on threat-led penetration testing (TLPT)" (11 February 2025 update; it also made purple-teaming mandatory and renamed the "White Team" to the "Control Team").
TIBER-EU is EU-wide and coordinated by the ECB with implementation running through each member state's own national TIBER cyber team. This is a different jurisdiction and coordination model from the UK's CBEST, which the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority run directly for firms they supervise in the UK. Both frameworks use intelligence-led red-team testing on live production systems for financial entities judged critical, but the ECB's own TIBER-EU pages state no formal relationship between the two frameworks, and none is asserted here.
Who owns it
The ECB designed TIBER-EU with EU national central banks and coordinates it EU-wide through the TIBER-EU Knowledge Centre; each member state's national TIBER cyber team carries out implementation on its own territory.
Who asks for it
Statutory (scoped). DORA Article 26 requires threat-led penetration testing (TLPT) at least every three years, but only from financial entities the competent authority has identified as in scope — the article's own carve-outs exclude microenterprises and entities covered by Article 16(1). TIBER-EU is the framework national authorities and entities use to run that testing; it is not a requirement on the whole financial sector.
"The TIBER-EU framework can also assist competent authorities and financial entities in meeting the requirements for threat-led penetration tests under the Digital Operational Resilience Act (DORA)" — the entities in scope are the ones DORA Article 26 designates, decided by the competent authority, not every financial firm.
Sources
- European Central Bank — TIBER-EU ↗ — accessed
- ECB — TIBER-EU Framework updated to align with DORA (11 February 2025) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.