EstoniaFinantsinspektsioon
Estonia adopts TIBER-EE framework for threat-led penetration tests
Finantsinspektsioon's recommended TIBER-EE guide in force since 15 September 2026 sets the national playbook for DORA threat-led penetration testing, with voluntary use subject to prior coordination.
By Taxxa AI OyPublished 24 September 2026
Finantsinspektsioon has issued a recommended guide, the TIBER-EE national implementation documentFI, which sets how the European threat intelligence-based ethical red-teaming framework (TIBER-EU) is applied in Estonia
FI. The guide was established by the Finantsinspektsioon board decision no. 1.1-7/143 of 15 September 2026
FI and entered into force the same day
FI; the framework itself had been adopted for the Estonian financial sector by a board decision of 5 May 2025. It is published in Estonian and English alongside the board decision.
The guide explains the use of TIBER-EE for threat-led penetration testing (TLPT) under Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA). Under DORA Article 26, financial entities identified by the competent authority must periodically carry out TLPT; in Estonia Finantsinspektsioon is the competent authority for the entities under its supervisionFI and acts as the TLPT authority for them
FI, issuing an attestation when a test is completed in line with the applicable requirements
FI. Finantsinspektsioon does not take part in the operational conduct of a test
FI: the tested entity carries it out together with its appointed providers
FI, while the authority supervises, assures quality and coordinates cross-border, joint or pooled tests
FI under the TLPT regulatory technical standards (Commission Delegated Regulation (EU) 2025/1190).
The guide is addressed to entities Finantsinspektsioon has identified as TLPT-obliged by supervisory decisionFI, to other Estonian financial entities wishing to run a TIBER-EE test voluntarily
FI, and to the third-party providers and others involved
FI. Obliged entities use TIBER-EE as the national framework for these tests
FI; others may use it voluntarily provided this is coordinated with Finantsinspektsioon beforehand
FI. Tests by significant credit institutions under direct European Central Bank supervision stay with the ECB as the TLPT authority under its TIBER-EU SSM implementation guide, which also issues their attestations; where the ECB assigns the Estonian cyber team a supervisory role in such a test, it acts under that guide.
National arrangements include a dedicated TLPT cyber team (TCT-EE) inside Finantsinspektsioon's IT supervision department for day-to-day programme managementFI, an optional generic threat landscape (GTL) input that does not replace the per-test threat-intelligence requirement, confidentiality and information-security rules including secure channels and need-to-know handling, and cooperation with the Information System Authority (RIA) on threat intelligence and technical expertise. The guide is recommendatory rather than law
FI and is applied on a comply-or-explain basis
FI: an entity must be able to justify not applying a point
FI, while departures that break mandatory requirements can affect the attestation
FI.
Legal basis: Finantsinspektsiooni seadus § 57 lõike 1 ja lõike 3, Finantsinspektsiooni juhatuse 15.09.2026 otsus nr 1.1-7/143FI, Regulation (EU) 2022/2554 (DORA) artikkel 26, and Commission Delegated Regulation (EU) 2025/1190 on TLPT.
Entities identified as TLPT-obliged should run their tests under the TIBER-EE national framework; others wishing to use TIBER-EE voluntarily should coordinate with Finantsinspektsioon (TLPT@fi.ee) first.