EU RegulationsHome | DORA RTS on Threat-Led Penetration Testing

Browse Articles Full Text and PDF
Browse Articles Full Text and PDF

Table of Contents

Articles
⊞ ▼
  • Article 1 Definitions
  • Article 2 Identification of financial entities required to perform TLPT
  • Article 3 TCT and TLPT Test Managers
  • Article 4 Organisational arrangements for financial entities
  • Article 5 Risk management for TLPT
  • Article 6 Risk management for pooled or joint TLPTs
  • Article 7 Selection of TLPT providers
  • Article 8 Specificities for pooled or joint TLPTs
  • Article 9 Preparation phase
  • Article 10 Testing phase: threat intelligence
  • Article 11 Testing phase: red team test
  • Article 12 Closure phase
  • Article 13 Remediation plan
  • Article 14 Attestation
  • Article 15 Use of internal testers
  • Article 16 Cooperation and mutual recognition
  • Article 17 Entry into force
Annexes
▼
  • Annex I Content of the project charter (Article 9(2)(a))
  • Annex II Content of the scope specification document (Article 9(6))
  • Annex III Content of the targeted threat intelligence report (Article 10(5))
  • Annex IV Content of the red team test plan (Article 11(1))
  • Annex V Content of the red team test report (Article 12(2))
  • Annex VI Content of the blue team test report (Article 12(4))
  • Annex VII Details of the report summarizing the relevant findings of the TLPT referred to in Article 26(6) of Regulation (EU) 2022/2554
  • Annex VIII Details of the attestation of the TLPT referred to in Article 26(7) of Regulation (EU) 2022/2554
© 2026 digitalacts.eu. All rights reserved. This a free website that allows everyone to easily navigate through the various articles of EU regulations in the digital space. This website or its authors cannot be held liable for any misinterpretation of the regulations. Always refer to the official text published in the Official Journal of the European Union for legal purposes. For inquiries, questions or feedback, contact us at info@digitalacts.eu. This website is sponsored by RiskNow, a company that provides Governance, Risk and Compliance solutions for businesses.

Recently Viewed

No recent articles yet

Latest News

2026-06-29

Council adopts AI Act simplification regulation

The Council of the EU gave final approval to an AI Act simplification regulation that delays some high-risk AI application dates and introduces targeted changes to AI governance and compliance rules.

Read more

2026-06-24

EDPB launches form to support consistent GDPR interpretation across Europe

The European Data Protection Board launched a form for stakeholders to report possible inconsistencies in GDPR interpretation across Europe.

Read more

2026-06-03

EU supervisors publish first DORA report on major ICT incidents in finance

The European Supervisory Authorities published their first annual DORA overview of major ICT-related incidents, highlighting cross-border impact and third-party dependencies.

Read more

2026-01-20

EU cybersecurity package proposes targeted NIS2 simplification while strengthening ENISA

The European Commission proposed a cybersecurity package with targeted NIS2 amendments and changes to strengthen ENISA’s role in EU cyber resilience.

Read more

All News

Search results

We may use cookies to improve your experience and analyse site usage. You can accept all cookies or choose to allow only essential cookies.