2024-07-17

Added

Draft Regulatory Technical Standards specifying elements related to threat led penetration tests under Article 26(11) of Regulation (EU) 2022/2554

The European Supervisory Authorities draft Regulatory Technical Standards to specify criteria for identifying financial entities required to perform threat-led penetration tests, including revised selection criteria for insurance and reinsurance undertakings and increased quantitative thresholds for payment and electronic money institutions. The standards mandate testing methodologies aligned with the TIBER-EU framework, requiring mandatory purple teaming during the closure phase and permitting the use of internal testers under specific conditions. It establishes requirements for testers, threat intelligence providers, and supervisory cooperation, with an expected application date of 17 January 2025 following European Commission adoption.

European Banking Authority logo

European Union

European Banking Authority

Scan of the document's first page
Share

EBA published 1 document in the last 30 days — get each new one by email the day it lands.

Read the rest free, and get an email when EBA publishes again

Lineage: In force

amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: European Banking Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from EBA

EBA published 1 document in the last 30 days. We email you each new one the day it's published.

Topics