supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition
COMCMT1R-EP1R-C2R-EPCNCADO
Updated 26d ago
This regulation sets out detailed rules for financial entities on how to conduct 'threat-led penetration testing' (TLPT). This is a type of cybersecurity test designed to simulate advanced cyberattacks.
It specifies which financial firms must perform these tests, the standards for internal testers, and the requirements for each stage of the testing process, including results and remediation.