2025-02-13
Added · Updated
The European Commission adopts regulatory technical standards supplementing Regulation (EU) 2022/2554 to specify criteria for identifying financial entities required to perform threat-led penetration testing (TLPT). The regulation mandates that TLPT authorities assess entities based on ICT risk profiles and financial stability impacts, restricting testing to justified cases and allowing exclusions for certain core subsectors. It establishes detailed requirements for testing methodology, including the composition of control and blue teams, the role of TLPT cyber teams, and specific timelines such as a minimum 12-week active red team testing phase. The document further defines obligations for risk management, confidentiality, and the qualifications of testers and threat intelligence providers to ensure realistic and secure assessments.
Get EC alerts — same-day email on every new publication.
Skip to main content
EUR-Lex
Access to European Union law
This document is an excerpt from the EUR-Lex website
You are here
EUROPA
EUR-Lex home
Delegated regulation - EU - 2025/1190 - EN - EUR-Lex
Help
Quick search
Use quotation marks to search for an "exact phrase". Append an asterisk ( * ) to a search term to find variations of it (transp * , 32019R * ). Use a question mark ( ? ) instead of a single character in your search term to find variations of it (ca ? e finds case, cane, care).
Read the rest free, and get an email when EC publishes again
Source: European Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from EC
We email you every new EC publication the day it's published.