2026-04-23

Added · Updated

MFSA Guidance on Codes of Conduct for Threat-Led Penetration Testing under DORA

The Malta Financial Services Authority (MFSA) published the TLPT Codes of Conduct Guidance Document to support Financial Entities and TLPT Providers in developing codes of conduct required under Article 27(1)(c) of Regulation (EU) 2022/2554 and Article 9(11) of Commission Delegated Regulation (EU) 2025/1190. This guidance outlines recommendations and best practices for establishing core principles of such codes, applying to both natural persons and legal bodies responsible for providing or staffing Testers and Threat Intelligence Providers. The MFSA strongly encourages licensed Financial Entities, Testers, and Threat Intelligence Providers to review the document to enhance suitability for carrying out Threat-Led Penetration Testing under the TIBER-EU framework.

Malta Financial Services Authority logo

Malta

Malta Financial Services Authority

Click to view full text

More like this from MFSA

MFSA published 5 documents in the last 30 days. We email you each new one the day it's published.

Share