2025-06-18
Added · Updated
The Malta Financial Services Authority issued this circular to announce the publication of Commission Delegated Regulation (EU) 2025/1190 in the EU Official Journal. This regulation supplements the Digital Operational Resilience Act by establishing regulatory technical standards for threat-led penetration testing, including criteria for identifying entities, requirements for internal testers, and methodologies for testing phases. The Authority notes that the remaining technical standard is expected to be adopted soon and provides specific contact emails for supervisory ICT risk and TLPT-related queries.
Circular Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt Commission Delegated Regulation under Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector Published in the EU Official Journal (Update 5) This circular is an update to Circular titled Regulation (EU) 2022/2554 and Amending Directive (EU) 2022/2556 on Digital Operational Resilience for the Financial Sector published on the EU Official Journal published by the Authority in January 2023. As detailed by the latter circular, Regulation (EU) 2022/2554 (“the Regulation”) is to be supplemented by, inter alia, a series of Technical Standards and Guidelines. Following an interinstitutional drafting process by the European Supervisory Authorities (”ESAs”) in agreement with the European Central Bank (“ECB”), the following was adopted and has now been published in the EU Official Journal: