2025-02-13

Added · Updated

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing standards

The European Commission adopts regulatory technical standards supplementing Regulation (EU) 2022/2554 to specify criteria for identifying financial entities required to perform threat-led penetration testing (TLPT). The regulation mandates that TLPT authorities assess entities based on ICT risk profiles and financial stability impacts, restricting testing to justified cases and allowing exclusions for certain core subsectors. It establishes detailed requirements for testing methodology, including the composition of control and blue teams, the role of TLPT cyber teams, and specific timelines such as a minimum 12-week active red team testing phase. The document further defines obligations for risk management, confidentiality, and the qualifications of testers and threat intelligence providers to ensure realistic and secure assessments.

European Commission logo

European Union

European Commission

Click to view full text