Annex VIII Details of the attestation of the TLPT referred to in Article 26(7) of Regulation (EU) 2022/2554

LEU20251190EN110120250213EN0001.0008291291

The attestation shall contain at least all of the following information:

  1. (a)
    on the performed TLPT:

    1. (i)
      the starting and end dates of the TLPT;
    2. (ii)
      the critical or important functions in scope of the test;
    3. (iii)
      where relevant, information on critical or important functions in scope of the test in relation to which the TLPT was not performed;
    4. (iv)
      where relevant, other financial entities that were involved in the TLPT;
    5. (v)
      where relevant, the ICT third-party services providers that participated in the TLPT;
    6. (vi)
      in respect of testers:

      1. 1.
        whether internal testers were used;
      2. 2.
        whether Article 5(3), second subparagraph, was used by the financial entity;

    7. (vii)
      the duration, in calendar days, of the active red team testing phase;

  2. (b)
    where several TLPT authorities have been involved in the TLPT, the other TLPT authorities, and in which capacity;
  3. (c)
    list of the documents examined by the TLPT authority for the purposes of the attestation.