EU Delegated Regulation on threat-led penetration testing published in OJ

A&O Shearman
Contact

A&O Shearman

Commission Delegated Regulation (EU) 2025/1190 of 13 February has been published in the Official Journal of the European Union. The Delegated Regulation supplements the Digital Operational Resilience Act (DORA) with regard to regulatory technical standards (RTS) related to threat-led penetration testing (TLPT). The RTS specify the criteria for identifying financial entities required to carry out TLPT, and establish detailed requirements regarding the scope of testing, the methodologies to be used and the handling and reporting of results. Further, the RTS also sets out the requirements and standards governing the use of internal testers, ensuring their independence and competence, and outlines the framework for supervisory and other forms of cooperation necessary for implementation of TLPT and the mutual recognition testing. The Delegated Regulation will enter into force on the twentieth day following its publication in the Official Journal of the European Union, which is 8 July.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© A&O Shearman

Written by:

A&O Shearman
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

A&O Shearman on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide