Commission Delegated Regulation (EU) 2025/1190 of 13 February 2025 supplementing Regulation (EU) 2022/2554
as it stood on 2025-02-13, permalink: /eu-eurlex/32025r1190/2025-02-13
Outline, 17 provisions
art_1 art_2 art_3 art_4 art_5 art_6 art_7 art_8 art_9 art_10 art_11 art_12 art_13 art_14 art_15 art_16 art_17
Article 1
For the purposes of this Regulation, the following definitions shall apply:
| (1) | ‘control team’ means the team composed of staff of the tested financial entity and, where relevant in consideration of the scope of the TLPT, staff of its third-party service providers and any other party, who manages the test; |
|---|
| (2) | ‘control team lead’ means the staff member of the financial entity responsible for the conduct of all TLPT-related activities for the financial entity in the context of a given test; |
|---|
| (3) | ‘blue team’ means the staff of the financial entity and, where relevant, staff of the financial entity’s third-party service providers and any other party deemed relevant in consideration of the scope of the TLPT, of the financial entity’s third-party service providers, that are defending a financial entity's use of network and information systems by maintaining its security posture against simulated or real attacks and that is not aware of the TLPT; |
|---|
| (4) | ‘blue team tasks’ means tasks that are typically carried out by the blue team such as security operation centre (SOC), ICT infrastructure services, helpdesk services, incident management services at operational level; |
|---|
| (5) | ‘red team’ means the testers, internal or external, contracted for, or assigned to, a TLPT; |
|---|
| (6) | ‘purple teaming’ means a collaborative testing activity that involves both the testers and the blue team; |
|---|
| (7) | ‘TLPT authority’ means any of the following:(a)the single public authority in the financial sector designated in accordance with Article 26(9) of Regulation (EU) 2022/2554;(b)the authority in the financial sector to which the exercise of some or all of the tasks in relation to TLPT is delegated in accordance with Article 26(10) of Regulation (EU) 2022/2554;(c)any of the competent authorities referred to in Article 46 of Regulation (EU) 2022/2554; |
|---|---|
| (a) | the single public authority in the financial sector designated in accordance with Article 26(9) of Regulation (EU) 2022/2554; |
| (b) | the authority in the financial sector to which the exercise of some or all of the tasks in relation to TLPT is delegated in accordance with Article 26(10) of Regulation (EU) 2022/2554; |
| (c) | any of the competent authorities referred to in Article 46 of Regulation (EU) 2022/2554; |
| (8) | ‘TLPT Cyber Team’ or ‘TCT’ means the staff within the TLPT authorities that is responsible for TLPT-related matters; |
|---|
| (9) | ‘test managers’ means staff designated to lead the activities of the TLPT authority for a specific TLPT to monitor compliance with this Regulation; |
|---|
| (10) | ‘threat intelligence provider’ means the experts, contracted by the financial entity for each TLPT, and external to the financial entity and to ICT intra-group service providers if any, who collect and analyse targeted threat intelligence relevant for the financial entities in scope of a specific TLPT exercise and develop matching relevant and realistic threat scenarios; |
|---|
| (11) | ‘TLPT providers’ means testers and threat intelligence providers; |
|---|
| (12) | ‘leg-up’ means the assistance or information provided by the control team to the testers to enable the testers to continue the execution of an attack path where they are not able to advance on their own, and where no other reasonable alternative exists, including for insufficient time or resources in a given TLPT; |
|---|
| (13) | ‘attack path’ means the route followed by testers during the active red team testing phase of the TLPT to reach the flags specified for that TLPT; |
|---|
| (14) | ‘flags’ are key objectives in the ICT systems supporting critical or important functions of a financial entity that the testers try to achieve through the test; |
|---|
| (15) | ‘sensitive information’ means information that can readily be leveraged to carry out attacks against the ICT systems of the financial entity, intellectual property, confidential business data, or personal data, that can directly or indirectly harm the financial entity and its ecosystem would it fall in the hands of malicious actors; |
|---|
| (16) | ‘pool’ means all the financial entities participating in a pooled TLPT pursuant to Article 26(4) of Regulation (EU) 2022/2554; |
|---|
| (17) | ‘host Member State’ means the host Member State in accordance with the Union sectoral law applicable to each financial entity; |
|---|
| (18) | ‘joint TLPT’ means a TLPT, other than a pooled TLPT as referred to in Article 26(4) of Regulation (EU) 2022/2554, involving several financial entities using the same ICT intra-group service provider, or belonging to the same group and sharing ICT systems. |
|---|
Article 2
- TLPT authorities shall assess whether any financial entity is required to perform TLPT, taking into account the impact of those financial entities, their systemic character and their ICT risk profile, on the basis of all of the following criteria:
| (a) | impact-related and systemic character related factors:(i)the size of the financial entity, determined on the basis of whether the financial entity provides financial services in one or more Member States and by comparing the activities of the financial entity to those of other financial entities providing similar services;(ii)the extent and nature of the interconnectedness of the financial entity with other financial entities in the financial sector in one or more Member States;(iii)the criticality or importance of the services that the financial entity provides to the financial sector;(iv)the substitutability of the services that the financial entity provides;(v)the complexity of the business model of the financial entity and the related services and processes;(vi)whether the financial entity is part of a group of systemic character at Union or national level in the financial sector and sharing ICT systems; |
|---|---|
| (i) | the size of the financial entity, determined on the basis of whether the financial entity provides financial services in one or more Member States and by comparing the activities of the financial entity to those of other financial entities providing similar services; |
| (ii) | the extent and nature of the interconnectedness of the financial entity with other financial entities in the financial sector in one or more Member States; |
| (iii) | the criticality or importance of the services that the financial entity provides to the financial sector; |
| (iv) | the substitutability of the services that the financial entity provides; |
| (v) | the complexity of the business model of the financial entity and the related services and processes; |
| (vi) | whether the financial entity is part of a group of systemic character at Union or national level in the financial sector and sharing ICT systems; |
| (b) | ICT risk-related factors:(i)the risk profile of the financial entity;(ii)the threat landscape of the financial entity;(iii)the degree of dependence of critical or important functions or their supporting functions of the financial entity on ICT systems and processes;(iv)the complexity of the ICT architecture of the financial entity;(v)the ICT services and functions supported by ICT third-party service providers, and the quantity and type of contractual arrangements with ICT third-party service providers or ICT intra-group service providers;(vi)the outcomes of any supervisory reviews relevant for the assessment of the ICT maturity of the financial entity;(vii)the maturity of ICT business continuity plans and ICT response and recovery plans;(viii)the maturity of the operational ICT security detection and mitigation measures, including the ability to:(1)monitor the financial entity’s ICT infrastructure on a permanent basis;(2)detect ICT-related events in real time;(3)analyse the events referred to in point (2);(4)respond to the events referred to in point (2) in a timely and effective manner;(ix)whether the financial entity is part of a group active in the financial sector at Union or national level that shares ICT systems. |
|---|---|
| (i) | the risk profile of the financial entity; |
| (ii) | the threat landscape of the financial entity; |
| (iii) | the degree of dependence of critical or important functions or their supporting functions of the financial entity on ICT systems and processes; |
| (iv) | the complexity of the ICT architecture of the financial entity; |
| (v) | the ICT services and functions supported by ICT third-party service providers, and the quantity and type of contractual arrangements with ICT third-party service providers or ICT intra-group service providers; |
| (vi) | the outcomes of any supervisory reviews relevant for the assessment of the ICT maturity of the financial entity; |
| (vii) | the maturity of ICT business continuity plans and ICT response and recovery plans; |
| (viii) | the maturity of the operational ICT security detection and mitigation measures, including the ability to:(1)monitor the financial entity’s ICT infrastructure on a permanent basis;(2)detect ICT-related events in real time;(3)analyse the events referred to in point (2);(4)respond to the events referred to in point (2) in a timely and effective manner; |
| (1) | monitor the financial entity’s ICT infrastructure on a permanent basis; |
| (2) | detect ICT-related events in real time; |
| (3) | analyse the events referred to in point (2); |
| (4) | respond to the events referred to in point (2) in a timely and effective manner; |
| (ix) | whether the financial entity is part of a group active in the financial sector at Union or national level that shares ICT systems. |
For the purposes of point (a)(i), the TLPT authority shall, where possible, consider:
| (a) | the market share position of the financial entity at Union and national level; |
|---|
| (b) | the range of activities offered by the financial entity; |
|---|
| (c) | the market share of the services provided by the financial entity or of the activities undertaken at Union and national level. |
|---|
For the purposes of point (a)(v), the TLPT authority shall, where possible, consider:
| (a) | whether the financial entity operates more than one business model; |
|---|
| (b) | the interconnectedness of different business processes and the related services. |
|---|
- TLPT authorities shall require all of the following financial entities to perform TLPT, unless the assessment referred to in paragraph 1 in respect of a financial entity indicates that its impact, the financial stability concerns relating to that financial entity, or its ICT risk profile, does not justify the performance of a TLPT:
| (a) | credit institutions that meet any of the following conditions:(i)they have been identified as global systemically important institutions (G-SIIs) in accordance with Article 131 of Directive 2013/36/EU of the European Parliament and of the Council (7);(ii)they have been identified as other systemically important institutions (O-SIIs) in accordance with Article 131 of Directive 2013/36/EU;(iii)they are part of a G-SIIs or O-SIIs; |
|---|---|
| (i) | they have been identified as global systemically important institutions (G-SIIs) in accordance with Article 131 of Directive 2013/36/EU of the European Parliament and of the Council (7); |
| (ii) | they have been identified as other systemically important institutions (O-SIIs) in accordance with Article 131 of Directive 2013/36/EU; |
| (iii) | they are part of a G-SIIs or O-SIIs; |
| (b) | payment institutions that exceeded in each of the 2 calendar years preceding the assessment by the TLPT authority EUR 150 billion of total value of payment transactions as defined in Article 4, point (5), of Directive (EU) 2015/2366 of the European Parliament and of the Council (8); |
|---|
| (c) | electronic money institutions that exceeded in each of the 2 calendar years preceding the assessment by the TLPT authority either EUR 150 billion of total value of payment transactions as defined in Article 4, point (5), of Directive (EU) 2015/2366 or EUR 40 billion of total value of the amount of outstanding electronic money; |
|---|
| (d) | central securities depositories; |
|---|
| (e) | central counterparties; |
|---|
| (f) | trading venues with an electronic trading system that meet any of the following criteria:(i)the trading venue has the highest market share in terms of turnover at national level in each of the 2 calendar years preceding the assessment by the TLPT authority in any of the following:(1)transferable securities as defined in Article 4(1), point (44)(a), of Directive 2014/65/EU of the European Parliament and of the Council (9);(2)transferable securities as defined in Article 4(1), point (44)(b), of Directive 2014/65/EU;(3)derivatives as defined in Article 2(1), point (29), of Regulation (EU) No 600/2014 of the European Parliament and of the Council (10);(4)structured finance products as defined in Article 2(1), point (28), of Regulation (EU) No 600/2014;(5)emission allowances as referred to in Section C, point (11), of Annex I to Directive 2014/65/EU;(ii)the trading venue has a market share in terms of turnover at Union level that exceeds 5 % in each of the 2 calendar years preceding the assessment by the TLPT authority in any of the following:(1)shares in companies and other securities equivalent to shares in companies, partnerships or other entities, and depositary receipts in respect of shares;(2)bonds or other forms of securitised debt, including depositary receipts in respect of such securities;(3)derivatives as defined in Article 2(1), point (29), of Regulation (EU) No 600/2014,(4)structured finance products as defined in Article 2(1), point (28), of Regulation (EU) No 600/2014;(5)emission allowances as referred to in Section C, point (11), of Annex I to Directive 2014/65/EU; |
|---|---|
| (i) | the trading venue has the highest market share in terms of turnover at national level in each of the 2 calendar years preceding the assessment by the TLPT authority in any of the following:(1)transferable securities as defined in Article 4(1), point (44)(a), of Directive 2014/65/EU of the European Parliament and of the Council (9);(2)transferable securities as defined in Article 4(1), point (44)(b), of Directive 2014/65/EU;(3)derivatives as defined in Article 2(1), point (29), of Regulation (EU) No 600/2014 of the European Parliament and of the Council (10);(4)structured finance products as defined in Article 2(1), point (28), of Regulation (EU) No 600/2014;(5)emission allowances as referred to in Section C, point (11), of Annex I to Directive 2014/65/EU; |
| (1) | transferable securities as defined in Article 4(1), point (44)(a), of Directive 2014/65/EU of the European Parliament and of the Council (9); |
| (2) | transferable securities as defined in Article 4(1), point (44)(b), of Directive 2014/65/EU; |
| (3) | derivatives as defined in Article 2(1), point (29), of Regulation (EU) No 600/2014 of the European Parliament and of the Council (10); |
| (4) | structured finance products as defined in Article 2(1), point (28), of Regulation (EU) No 600/2014; |
| (5) | emission allowances as referred to in Section C, point (11), of Annex I to Directive 2014/65/EU; |
| (ii) | the trading venue has a market share in terms of turnover at Union level that exceeds 5 % in each of the 2 calendar years preceding the assessment by the TLPT authority in any of the following:(1)shares in companies and other securities equivalent to shares in companies, partnerships or other entities, and depositary receipts in respect of shares;(2)bonds or other forms of securitised debt, including depositary receipts in respect of such securities;(3)derivatives as defined in Article 2(1), point (29), of Regulation (EU) No 600/2014,(4)structured finance products as defined in Article 2(1), point (28), of Regulation (EU) No 600/2014;(5)emission allowances as referred to in Section C, point (11), of Annex I to Directive 2014/65/EU; |
| (1) | shares in companies and other securities equivalent to shares in companies, partnerships or other entities, and depositary receipts in respect of shares; |
| (2) | bonds or other forms of securitised debt, including depositary receipts in respect of such securities; |
| (3) | derivatives as defined in Article 2(1), point (29), of Regulation (EU) No 600/2014, |
| (4) | structured finance products as defined in Article 2(1), point (28), of Regulation (EU) No 600/2014; |
| (5) | emission allowances as referred to in Section C, point (11), of Annex I to Directive 2014/65/EU; |
| (g) | insurance and reinsurance undertakings that meet all the following criteria:(i)they have a gross written premium (GWP) that exceeds EUR 1 500 000 000;(ii)they have technical provisions that exceed EUR 10 000 000 000;(iii)insurance undertakings that pursue only life activities or that pursue both life and non-life activities and that have total assets that exceed 3,5 % of the sum of the total assets valuated in accordance with Article 75 of Directive 2009/138/EC of the European Parliament and of the Council (11) of the insurance and reinsurance undertakings established in the Member State. |
|---|---|
| (i) | they have a gross written premium (GWP) that exceeds EUR 1 500 000 000; |
| (ii) | they have technical provisions that exceed EUR 10 000 000 000; |
| (iii) | insurance undertakings that pursue only life activities or that pursue both life and non-life activities and that have total assets that exceed 3,5 % of the sum of the total assets valuated in accordance with Article 75 of Directive 2009/138/EC of the European Parliament and of the Council (11) of the insurance and reinsurance undertakings established in the Member State. |
For the purposes of (f)(ii), where the trading venue is part of a group sharing ICT systems or the same ICT intra-group service provider, the turnover of the securities and derivatives contracts on all trading venues pertaining to the same group and established in the Union shall be considered.
For the purposes of point (g), TLPT authorities shall identify a subset of all insurance and reinsurance undertakings by applying the criteria laid down in points (g)(i), (ii), and (iii). Insurance and reinsurance undertakings included in that subset shall be required to perform TLPT where they also meet any of the following criteria:
| (a) | gross written premium (GWP) that exceeds EUR 3 000 000 000; |
|---|
| (b) | technical provisions that exceed EUR 30 000 000 000; |
|---|
| (c) | total assets that exceed 10 % of the sum of the total assets valuated in accordance with Article 75 of Directive 2009/138/EC of the insurance and reinsurance undertakings established in the Member State. |
|---|
- Where more than one financial entity belonging to the same group and sharing ICT systems, or where more than one financial entity using the same ICT intra-group service provider, meet the criteria set out in paragraph 2, the TLPT authorities of those financial entities shall, in accordance with Article 16(2), decide whether the requirement to perform TLPT on an individual basis is relevant for those financial entities.
Where the TLPT authority of the parent undertaking of a group of financial entities referred to in the first subparagraph is different from the TLPT authorities of the financial entities of the group, that authority shall be consulted by the TLPT authorities of the financial entities belonging to that group on whether it is appropriate to perform TLPT on an individual basis.
Article 3
A TLPT authority shall assign the responsibility for coordinating TLPT-related activities to a TCT. A TCT shall be composed of test managers that are assigned to oversee an individual TLPT.
For each test, the TLPT authority shall designate a test manager and at least one alternate.
The test managers shall monitor whether, and ensure that, the requirements laid down in this Regulation are complied with.
The test manager shall communicate the contact details of the TCT to the financial entity through the notification referred to in Article 9(1).
The TLPT authority shall participate to all the phases of the TLPT.
Article 4
Financial entities shall appoint a control team lead which shall be responsible for the day-to-day management of the TLPT and the decisions and actions of the control team.
Financial entities shall establish organisational and procedural measures to ensure that:
| (a) | access to information pertaining to any planned or ongoing TLPT is limited on a need-to-know basis to the control team, the management body, the testers, the threat intelligence provider and the TLPT authority; |
|---|
| (b) | the control team consults the test managers prior to involving any member of the blue team in a TLPT; |
|---|
| (c) | the control team is informed of any detection of the TLPT by staff members of the financial entity or of its third-party service providers; in case of escalation of the resulting incident response, where needed, the control team contains such escalation; |
|---|
| (d) | arrangements relating to the secrecy of the TLPT, applicable to staff of the financial entity, to the staff of the ICT third party service providers concerned, to testers and to the threat intelligence provider are in place; |
|---|
| (e) | the control team provides any information pertaining to the TLPT to the test managers upon request; |
|---|
| (f) | where possible, parties involved in the TLPT refer to it by code name only. |
|---|
Article 5
- During the preparation phase referred to in Article 9, the control team shall assess the risks associated with the testing of live production systems of critical or important functions of the financial entity, including potential impacts on:
| (a) | the financial sector; |
|---|
| (b) | the financial stability at Union or national level. |
|---|
The control team shall review those impacts throughout the testing.
- For the purposes of the risk assessment and management, the control team shall take into account at least the following types of risks related to:
| (a) | granting access to the threat intelligence provider and external testers, where applicable, to sensitive information on the financial entity; |
|---|
| (b) | lack of compliance of the TLPT with Regulation (EU) 2022/2554 and with this Regulation where such lack of compliance results in a lack of the attestation referred to in Article 26(7) of Regulation (EU) 2022/2554, including where such lack of compliance is due to breaches of confidentiality on the TLPT or to a lack of ethical conduct; |
|---|
| (c) | crisis and incident escalation; |
|---|
| (d) | the active red team phase, including risks related to the interruption of critical activities and the corruption of data due to the activities of the testers, and its potential impacts on third parties; |
|---|
| (e) | the blue team activity, including risks related to the interruption of critical activities and the corruption of data due to the activities of the blue team, and its potential impacts on third parties; |
|---|
| (f) | the incomplete restoration of systems affected by the TLPT. |
|---|
Article 6
In the case of a joint TLPT or a pooled TLPT, the control team of each financial entity shall conduct its own risk assessment and establish its own risk management measures.
The control team of the designated financial entity referred to in Article 16(3), point (b), of this Regulation, or the financial entity designated in accordance with Article 26(4) of Regulation (EU) 2022/2554, shall assess the risks relating to the involvement in the TLPT of multiple financial entities. The control teams of the involved financial entities shall cooperate with the control team of the designated financial entity to identify potential joint risks.
Article 7
- The control team shall take measures to manage the risks relating to the TLPT and shall in particular ensure that, for each TLPT:
| (a) | the threat intelligence provider and external testers provide the control team with a detailed curriculum vitae and copies of certifications that, according to recognised market standards, are appropriate for the performance of their activities; |
|---|
| (b) | the threat intelligence provider and external tester are duly and fully covered by proper professional indemnity insurances including against risks of misconduct and negligence; |
|---|
| (c) | the threat intelligence provider provides at least three references from previous assignments in the context of penetration testing and red team testing; |
|---|
| (d) | the external testers provide at least five references from previous assignments related to penetration testing and red team testing; |
|---|
| (e) | the staff of the threat intelligence provider assigned to the TLPT:(i)is composed of at least a manager with at least 5 years’ experience in threat intelligence and at least one additional member with at least 2 years’ experience in threat intelligence;(ii)display a broad range and appropriate level of professional knowledge and skills, including:(1)intelligence gathering tactics, techniques and procedures;(2)geopolitical, technical and sectorial knowledge;(3)adequate communication skills to clearly present and report on the result of the engagement;(iii)has a combined participation in at least three previous assignments in threat intelligence in the context of penetration testing and red team testing;(iv)does not simultaneously perform any blue team tasks or other services that may present a conflict of interest with respect to the financial entity, ICT third-party service provider or an ICT intra-group service provider involved in TLPT to which they are assigned;(v)is separated from and not reporting to staff of the same TLPT provider providing external testers for the same TLPT; |
|---|---|
| (i) | is composed of at least a manager with at least 5 years’ experience in threat intelligence and at least one additional member with at least 2 years’ experience in threat intelligence; |
| (ii) | display a broad range and appropriate level of professional knowledge and skills, including:(1)intelligence gathering tactics, techniques and procedures;(2)geopolitical, technical and sectorial knowledge;(3)adequate communication skills to clearly present and report on the result of the engagement; |
| (1) | intelligence gathering tactics, techniques and procedures; |
| (2) | geopolitical, technical and sectorial knowledge; |
| (3) | adequate communication skills to clearly present and report on the result of the engagement; |
| (iii) | has a combined participation in at least three previous assignments in threat intelligence in the context of penetration testing and red team testing; |
| (iv) | does not simultaneously perform any blue team tasks or other services that may present a conflict of interest with respect to the financial entity, ICT third-party service provider or an ICT intra-group service provider involved in TLPT to which they are assigned; |
| (v) | is separated from and not reporting to staff of the same TLPT provider providing external testers for the same TLPT; |
| (f) | for external testers, the red team assigned to the TLPT:(i)is composed of at least a manager, with at least 5 years of experience in penetration testing and red team testing as well as at least two additional testers, each with penetration testing and red team testing of at least 2 years;(ii)displays a broad range and appropriate level of professional knowledge and skills, including knowledge about the business of the financial entity, reconnaissance, risk management, exploit development, physical penetration, social engineering, vulnerability analysis, as well as adequate communication skills to clearly present and report on the result of the engagement;(iii)has a combined participation in at least five previous assignments related to penetration testing and red team testing;(iv)is not employed by, nor provides services to, a threat intelligence provider that simultaneously performs blue team tasks for either a financial entity, an ICT third-party service provider, or an ICT intra-group service provider that is involved in the TLPT;(v)is separated from any staff of the same TLPT provider that simultaneously provides threat-intelligence services for the same TLPT; |
|---|---|
| (i) | is composed of at least a manager, with at least 5 years of experience in penetration testing and red team testing as well as at least two additional testers, each with penetration testing and red team testing of at least 2 years; |
| (ii) | displays a broad range and appropriate level of professional knowledge and skills, including knowledge about the business of the financial entity, reconnaissance, risk management, exploit development, physical penetration, social engineering, vulnerability analysis, as well as adequate communication skills to clearly present and report on the result of the engagement; |
| (iii) | has a combined participation in at least five previous assignments related to penetration testing and red team testing; |
| (iv) | is not employed by, nor provides services to, a threat intelligence provider that simultaneously performs blue team tasks for either a financial entity, an ICT third-party service provider, or an ICT intra-group service provider that is involved in the TLPT; |
| (v) | is separated from any staff of the same TLPT provider that simultaneously provides threat-intelligence services for the same TLPT; |
| (g) | the testers and the threat intelligence provider carry out restoration procedures at the end of testing, including secure deletion of information related to passwords, credentials, and other secret keys compromised during the TLPT, secure communication to the financial entities of the accounts compromised, secure collection, storage, management, and disposal of other data collected during testing; |
|---|
| (h) | testers, in addition to the restoration procedures at the end of testing as referred to in point (g), carry out the following restoration procedures:(i)command and control deactivation;(ii)scope and date kill switches;(iii)removal of backdoors and other malware;(iv)potential breach notification;(v)procedures for future back-up restoration which may concern malware or tools installed during the test;(vi)monitoring of the blue team activities and informing the control team of any possible detections; |
|---|---|
| (i) | command and control deactivation; |
| (ii) | scope and date kill switches; |
| (iii) | removal of backdoors and other malware; |
| (iv) | potential breach notification; |
| (v) | procedures for future back-up restoration which may concern malware or tools installed during the test; |
| (vi) | monitoring of the blue team activities and informing the control team of any possible detections; |
| (i) | testers and the threat intelligence provider do not perform, or participate in, any of the following activities:(i)unauthorised destruction of equipment of the financial entity and of its ICT third-party service providers, if any;(ii)uncontrolled modification of information and ICT assets of the financial entity and of its ICT third-party service providers, if any;(iii)intentionally compromising the continuity of critical or important functions of the financial entity;(iv)unauthorised inclusion of out-of-scope systems;(v)unauthorised disclosure of test results. |
|---|---|
| (i) | unauthorised destruction of equipment of the financial entity and of its ICT third-party service providers, if any; |
| (ii) | uncontrolled modification of information and ICT assets of the financial entity and of its ICT third-party service providers, if any; |
| (iii) | intentionally compromising the continuity of critical or important functions of the financial entity; |
| (iv) | unauthorised inclusion of out-of-scope systems; |
| (v) | unauthorised disclosure of test results. |
- The control team shall keep record of the documentation provided by the testers and the threat intelligence providers to evidence compliance with paragraph 1, points (a) to (f).
In exceptional circumstances, financial entities may contract external testers and threat intelligence providers that do not meet one or more of the requirements set out in paragraph 1, points (a) to (f), provided that those financial entities adopt measures that are appropriate to mitigate the risks relating to the lack of compliance with such points and record those measures.
Article 8
Unless otherwise decided by the lead TLPT authority, where several financial entities, identified in accordance with Article 16(2) or (4), are involved in a pooled or joint TLPT, each financial entity shall follow each of the steps set out in Articles 9 to 15.
Unless otherwise provided in this Regulation, where several TLPT authorities are involved in a joint TLPT or in a pooled TLPT, as referred to in Article 16(3) or 16(5), references in Articles 9 to 15 to the ‘TLPT authority’ shall be understood as a reference to the lead TLPT authority for such pooled or joint TLPT.
Article 9
A financial entity identified pursuant to Article 26, paragraph 8, third subparagraph of Regulation (EU) 2022/2554 shall initiate a TLPT following a notification from the TLPT authority that a TLPT is to be carried out.
A financial entity shall, within 3 months from having received the notification referred to in paragraph 1, submit to the test managers all of the following TLPT initiation information:
| (a) | a project charter including a high-level project plan, containing the information set out in Annex I; |
|---|
| (b) | the contact details of the control team lead; |
|---|
| (c) | information on the intended use of internal or external testers or both, where relevant as detailed in Article 15; |
|---|
| (d) | information on the communication channels to be used during the TLPT; |
|---|
| (e) | the code name for the TLPT. |
|---|
Where the information referred to in paragraph 2, points (a) to (e), is complete and ensures the suitability and effective performance of the TLPT, the TLPT authority shall validate the TLPT initiation information of the financial entity and notify the financial entity thereof.
Following the validation of the TLPT initiation information by the TLPT authority, the financial entity shall set up a control team to support the control team lead in its tasks of:
| (a) | specifying communications channels and processes within the control team, with the testers and the threat intelligence providers in all matters related to the TLPT; |
|---|
| (b) | informing the management body of the financial entity about the progress of the TLPT and the associated risks; |
|---|
| (c) | taking decisions based on subject matter expertise throughout the TLPT; |
|---|
| (d) | executing the TLPT in compliance with this Regulation; |
|---|
| (e) | selecting the threat intelligence provider for the TLPT; |
|---|
| (f) | selecting the external testers, the internal testers or both; |
|---|
| (g) | preparing the scope specification document. |
|---|
Where the TLPT authority considers that the initial composition of the control team and any subsequent changes to it are adequate for the performance of the tasks referred to in paragraph 4, the TLPT authority shall validate the control team and notify the control team lead thereof.
The financial entity shall submit a scope specification document containing all information set out in Annex II to the test managers within 6 months from the receipt of the notification from the TLPT authority referred to in paragraph 1. The management body of the financial entity shall approve the scope specification document.
Financial entities shall consider the following criteria for the inclusion of critical or important functions into the scope of the TLPT:
| (a) | the criticality or importance of the function and its possible impact on the financial sector and on financial stability at Union and national level; |
|---|
| (b) | the importance of the function for the day-to-day business operations of the financial entity; |
|---|
| (c) | the exchangeability of the function; |
|---|
| (d) | the interconnectedness with other functions; |
|---|
| (e) | the geographical location of the function; |
|---|
| (f) | the sectoral dependence of other entities on the function; |
|---|
| (g) | where available, threat intelligence concerning the function. |
|---|
The control team shall share the TLPT initiation information and the scope specification document with the testers and threat intelligence providers once those are contracted. The control team shall inform the testers and threat intelligence providers about the testing process to be followed.
The financial entity shall ensure that the procurement or assignment of testers and threat intelligence providers is completed prior to the initiation of the testing phase.
Prior to the initiation of the testing phase, the control team shall consult the test managers on the TLPT risk assessment and on the risk management measures. The control team shall review the risk assessment or the risk management measures where the TLPT authority is of the opinion that they do not adequately address the risks of the TLPT.
The control team shall assess the compliance of threat intelligence providers and testers they consider involving in the TLPT with the requirements laid down in Article 27 of Regulation (EU) 2022/2554 and with Article 7(1) of this Regulation, and document the outcome of that assessment. The control team shall select threat intelligence providers in accordance with that assessment and with its risk management practices. Prior to contracting the selected threat intelligence providers and external testers, the control team shall provide to the test managers evidence of compliance of those threat intelligence providers and testers with the requirements laid down in Article 27 of Regulation (EU) 2022/2554 and with Article 7(1) of this Regulation. The control team shall not proceed with contracting the selected threat intelligence providers and external testers where the TLPT authority is of the opinion that the selected threat intelligence providers and external testers do not comply with the requirements laid down in Article 27 of Regulation (EU) 2022/2554, or with the requirements laid down in Article 7(1) of this Regulation or with additional requirements stemming from national security legislations in accordance with Union law, or where the financial entity does not comply with Article 7(2), first subparagraph, of this Regulation, or where the circumstances referred to in Article 7(2), second subparagraph, of this Regulation are not met.
Where the scope specification document is complete and ensures the performance of an appropriate and effective TLPT, the TLPT authority shall approve that document and inform the control team lead thereof.
Article 10
Following the approval of the scope specification document by the TLPT authority, the threat intelligence provider shall analyse generic and sector-specific threat intelligence relevant for the financial entity. Where a generic threat landscape has been provided by the TLPT authority for the financial sector of a Member State, the threat intelligence provider may use that landscape as a baseline for the national threat landscape. The threat intelligence provider shall identify cyber threats and existing or potential vulnerabilities concerning the financial entity. Furthermore, the threat intelligence provider shall gather information on, and analyse concrete, actionable, and contextualised target and threat intelligence concerning the financial entity, including through consulting the control team and the test managers.
The threat intelligence provider shall present the relevant threats and targeted threat intelligence, and propose requisite scenarios to the control team, testers and test managers. The proposed scenarios shall differ with reference to the identified threat actors and associated tactics, techniques and procedures and shall target each critical or important function in the scope of the TLPT.
The control team lead shall select at least three scenarios to conduct the TLPT on the basis of all of the following elements:
| (a) | the recommendation by the threat intelligence provider and the threat-led nature of each scenario; |
|---|
| (b) | the input provided by the test managers; |
|---|
| (c) | the feasibility of the proposed scenarios for execution, based on the expert judgement of the testers; |
|---|
| (d) | the size, complexity and overall risk profile of the financial entity and the nature, scale, and complexity of its services, activities, and operations. |
|---|
- No more than one of the selected scenarios may be non-threat-led and may be based on a forward-looking and potentially fictive threat with high predictive, anticipative, opportunistic, or prospective value given the anticipated developments of the threat landscape concerning the financial entity.
For pooled TLPTs, without prejudice to the scenarios targeting directly the critical or important functions of the financial entities involved in the testing, at least one scenario shall include the ICT third-party services provider’s relevant underlying ICT systems, processes, and technologies supporting the critical or important functions of the financial entities in scope.
Where the test is a joint TLPT involving an ICT intra-group service provider, without prejudice to the scenarios targeting directly the critical or important functions of the financial entities involved in the test, at least one scenario shall include the ICT intragroup services provider’s relevant underlying ICT systems, processes and technologies supporting the critical or important functions of the financial entities in scope.
The threat intelligence provider shall provide the targeted threat intelligence report to the control team, including the scenarios selected in accordance with paragraphs 3 and 4. The threat intelligence report shall contain the information set out in Annex III.
The control team shall submit the targeted threat intelligence report to the test manager for approval. Where the targeted threat intelligence report is complete and ensures the performance of an effective TLPT, the TLPT authority shall approve the targeted threat intelligence report and inform the control team lead thereof.
Article 11
Following approval of the targeted threat intelligence report by the TLPT authority, the testers shall prepare the red team test plan that shall contain the information set out in Annex IV. The testers shall use the scope specification document and the targeted threat intelligence report as a basis for producing the attack scenarios.
The testers shall consult the control team, the threat intelligence provider, and the test managers on the red team test plan, including the communication, procedural and project management arrangement, the preparation and use-cases for leg-up activation, and the reporting agreements to the control team and test managers.
Where the red team test plan is complete and ensures the performance of an effective TLPT, the control team and the TLPT authority shall approve the red team test plan and the TLPT shall inform the control team lead thereof.
Upon approval of the red team test plan in accordance with paragraph 3, the testers shall carry out the TLPT during the active red team testing phase.
The duration of the active red team testing phase shall be proportionate to the TLPT scope, to the scale, activity, complexity and number of the financial entities and ICT third-party or ICT intragroup service providers involved in the TLPT, and in any case shall last for at least 12 weeks. Attack scenarios may be executed in sequence or at the same time. The control team, the threat intelligence provider, the testers and the test managers shall agree on the end of the active red team testing phase.
Subject to ensuring that the red team test plan remains complete and allows for the performance of an effective TLPT, the control team lead and the test managers shall approve any changes to the red team test plan subsequent to its approval, including to the timeline, scope, target systems or flags.
During the entire active red team testing phase, testers shall report at least weekly to the control team and test managers on the progress made in the TLPT, and the threat intelligence provider shall remain available for consultation and additional threat intelligence when requested by the control team.
The control team shall timely provide leg-ups designed on the basis of the red team test plan. Leg-ups may be added or adapted upon approval by the control team and the test managers.
In the case of detection of the testing activities by any staff member of the financial entity or of its ICT third-party service providers or ICT intragroup service provider, where relevant, the control team, in consultation with the testers and without prejudice to paragraph 10, shall propose and submit measures allowing to continue the TLPT while ensuring its secrecy to the test managers for validation.
Under exceptional circumstances triggering risks of impact on data, damage to assets, and disruption to critical or important functions, services or operations of the financial entity itself, of its ICT third-party service providers or ICT intragroup services providers, or disruptions to its counterparts or to the financial sector, the control team lead may suspend the TLPT, or, as a last resort, where the continuation of the TLPT is not otherwise possible and subject to prior validation by the TLPT authority, continue the TLPT using a limited purple teaming exercise. The duration of the limited purple teaming exercise shall be counted for the purpose of the 12-week minimum duration of the active red team testing phase referred to in paragraph 5.
Article 12
Following the end of the active red team testing phase, the control team lead shall inform the blue team that a TLPT took place.
Within 4 weeks from the end of the active red team testing phase, the testers shall submit to the control team a red team test report containing the information set out in Annex V.
The control team shall provide the red team test report to the blue team and test managers without undue delay.
At the request of the test managers, the report referred to in the first subparagraph shall not contain sensitive information.
- Upon receipt of the red team test report, and no later than 10 weeks after the end of the active red team testing phase, the blue team shall submit to the control team a blue team test report containing the information set out in Annex VI. The control team shall provide the blue team test report to the testers and the test managers without undue delay.
At the request of the test managers, the report referred to in the first subparagraph shall not contain sensitive information.
No later than 10 weeks after the end of the active red team testing phase, the blue team and the testers shall replay the offensive and defensive actions performed during the TLPT. The control team shall also conduct a purple teaming exercise on topics jointly identified by the blue team and the testers, based on vulnerabilities identified during the test and, where relevant, on issues that could not be tested during the active red team testing phase.
After completion of the replay and purple teaming exercises, the control team, the blue team, the testers, and threat intelligence providers shall provide feedback to each other on the TLPT process. The test managers may provide feedback.
Once the TLPT authority has notified the control team lead that it has assessed that the blue team test report and the red team test report contain the information set out in Annexes V and VI, the financial entity shall within 8 weeks submit the report summarising the relevant findings of the TLPT to the TLPT authority, as referred to in Article 26(6) of Regulation (EU) 2022/2554, containing the elements set out in Annex VII for approval.
At the request of the TLPT authority, the report referred to in the first subparagraph shall not contain sensitive information.
Article 13
Within 8 weeks from the notification referred to in Article 12(7) of this Regulation, the financial entity shall provide the remediation plans and the documentation referred to in Article 26(6) of Regulation (EU) 2022/2554 to the TLPT authority and, where different, to the financial entity’s competent authority.
The remediation plan referred in paragraph 1 shall include, for each finding occurred in the framework of the TLPT:
| (a) | a description of the identified shortcomings; |
|---|
| (b) | a description of the proposed remediation measures and of their prioritisation and expected completion, including, where relevant, measures to improve the identification, protection, detection and response capabilities; |
|---|
| (c) | a root cause analysis; |
|---|
| (d) | the financial entity’s staff or functions responsible for the implementation of the proposed remediation measures or improvements; |
|---|
| (e) | the risks associated to not implementing the measures referred to in point (b) and, where relevant, risks associated to the implementation of such measures. |
|---|
Article 14
The attestation referred to in Article 26(7) of Regulation (EU) 2022/2554 shall contain the information set out in Annex VIII.
Where several TLPT authorities have been involved in a TLPT, the lead TLPT authority shall provide the attestation referred to in Article 26(7) of Regulation (EU) 2022/2554 to the tested financial entities.
Article 15
- Financial entities shall establish all of the following arrangements for the use of internal testers:
| (a) | the establishment and implementation of a policy for the management of internal testers in a TLPT; |
|---|
| (b) | measures to ensure that the use of internal testers to perform a TLPT does not negatively impact the financial entity’s general defensive or resilience capabilities regarding ICT-related incidents or significantly impacts the availability of resources devoted to ICT-related tasks during a TLPT; |
|---|
| (c) | measures to ensure that internal testers have sufficient resources and capabilities to perform a TLPT. |
|---|
The policy referred to in point (a) shall:
| (a) | contain criteria to assess suitability, competence, potential conflicts of interest of the internal testers and specify management responsibilities in the testing process; |
|---|
| (b) | be documented and periodically reviewed; |
|---|
| (c) | provide that the internal testing team includes a test lead, and at least two additional members; |
|---|
| (d) | require that all members of the test team have been employed by the financial entity or by an ICT intra-group service provider for the preceding 12 months; |
|---|
| (e) | include provisions on training on how to perform penetration testing and red team testing of the internal testers. |
|---|
Where a TLPT authority approves the use of internal testers in accordance with Article 27(2), point (a), of Regulation (EU) 2022/2554, the TLPT authority shall consider the requirements laid down in Article 7(1) of this Regulation.
When using internal testers, the financial entity shall ensure that such use is mentioned in the following documents:
| (a) | the test initiation information referred to in Article 9; |
|---|
| (b) | the red team test report referred to in Article 12(2); |
|---|
| (c) | the report summarising the relevant findings of the TLPT referred to in Article 26(6) of Regulation (EU) 2022/2554. |
|---|
- Testers employed by an ICT intra-group service provider shall be considered as internal testers of the financial entity.
Article 16
- For the purposes of conducting a TLPT in relation to a financial entity providing services in more than one Member State, including through a branch, its TLPT authority shall:
| (a) | determine which TLPT authorities in host Member States shall be involved, taking into account whether one or more critical or important functions are operated in, or shared across, host Member States; |
|---|
| (b) | inform the TLPT authorities identified in accordance with point (a) of the decision to carry out a TLPT test on the financial entity; |
|---|
| (c) | unless otherwise agreed by the TLPT authorities, the TLPT authority of the financial entity shall lead the TLPT. |
|---|
The TLPT authorities of the host Member States may, within 20 working days from the receipt of the information on a future conduct of a TLPT, either express their interest in following the TLPT as observers or assign a test manager to participate in the TLPT. The lead TLPT authority shall provide all TLPT authorities acting as observers in TLPT with the scope specification document, the test summary report, remediation plan and attestation.
The lead TLPT authority shall coordinate all participating TLPT authorities throughout the test and adopt all the decisions necessary to carry out the TLPT appropriately and effectively. The lead TLPT authority may set a maximum number of participating TLPT authorities, where the efficient conduct of the TLPT might otherwise be compromised.
Where a financial entity uses the same ICT intra-group service provider as financial entities established in other Member States, or belongs to a group and shares ICT systems with financial entities of the same group established in other Member States, the TLPT authority of the financial entity shall contact the TLPT authorities of the other financial entities using the same ICT intra-group service provider or sharing ICT systems as part of the group and assess with them the feasibility and suitability of conducting a joint TLPT in their respect. A joint TLPT shall be preferred to an individual TLPT where it may result in reduction of costs and resources for the financial entities and for the TLPT authorities, provided that the soundness and efficacy of the testing is not prejudiced.
For the purposes of conducting a joint TLPT:
| (a) | the TLPT authorities of the financial entities shall agree on which financial entity shall be designated to conduct the TLPT, considering the group structure and the efficiency of the test; |
|---|
| (b) | the TLPT authority of the financial entity designated in accordance with point (a) shall lead the TLPT, unless otherwise agreed by the TLPT authorities of the financial entities participating in the joint TLPT; |
|---|
| (c) | the TLPT authorities of the financial entities other than the designated financial entity to lead the joint TLPT may either express their interest in following the TLPT as observers or assign a test manager for that TLPT. |
|---|
The lead TLPT authority shall coordinate all TLPT authorities involved in the joint TLPT and adopt all the decisions necessary to carry out the joint TLPT in a sound and effective way.
Where a financial entity intends to conduct a pooled TLPT as referred to in Article 26(4) of Regulation (EU) 2022/2554 possibly involving financial entities established in other Member States, its TLPT authority shall contact the TLPT authorities of the other financial entities and assess with them the feasibility and suitability of conducting a pooled TLPT in their respect in accordance with Article 26(4) of Regulation (EU) 2022/2554.
For the purposes of conducting a pooled TLPT as referred to in Article 26(4) of Regulation (EU) 2022/2554:
| (a) | the TLPT authorities of the financial entities shall agree on which financial entity shall be designated to conduct of the pooled TLPT, considering the ICT services provided by the ICT third-party service provider to the financial entities and the efficiency of the test; |
|---|
| (b) | the TLPT authority of the financial entity designated in accordance with point (a) shall lead the TLPT, unless otherwise agreed by the TLPT authorities of the financial entities participating in the pooled TLPT; |
|---|
| (c) | the TLPT authorities of the financial entities other than the designated financial entity to lead the pooled TLPT may either express their interest in following the TLPT as observers or assign a test manager to that TLPT. |
|---|
The lead TLPT authority shall coordinate all TLPT authorities involved in the pooled TLPT and adopt all the decisions necessary to carry out the pooled TLPT in a sound and effective way.
- Where, in relation to a financial entity required to perform a TLPT, its TLPT authority differs from its competent authority as referred to in Article 46 of Regulation (EU) 2022/2554, those authorities shall share any relevant information in respect of all TLPT-related matters for the purposes of carrying out the TLPT or to carry out their duties in accordance with that Regulation.
Article 17
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2025-02-13 → this version applied |
| valid | 2025-02-13 → open publisher-asserted |
| type | REG_DEL Commission Delegated Regulation (EU) 2025/1190 of 13 February 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition |
| language | en |
| published | 2025-02-13 |
| lex_id | eu-eurlex:32025r1190:2025-02-13 |
| record sha256 | 103714016960b0f7227b14fa6e9f4826ee9f895be9788d7dd2c72e871d19334a |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2025-02-13) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |