Updated 01/07/2025
Coming into force on 08/07/2025

Initial Legal Act
References (6)
18/06/2025
Delegated Regulation 2025/1190 published in OJ
17/07/2024
JC 2024 29
Final Draft published
17/07/2024
JC 2024 29
Final Draft published
17/07/2024
JC 2024 29
Final Draft published
27/11/2023
JC/2023/72
Consultation published
27/11/2023
JC/2023/72
Consultation published
27/11/2023
JC/2023/72
Consultation published
Search within this legal act

Delegated Regulation 2025/1190

Commission Delegated Regulation (EU) 2025/1190 of 13 February 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition

RecitalsArticle 1 - DefinitionsArticle 2 - Identification of financial entities required to perform TLPTArticle 3 - TCT and TLPT Test ManagersArticle 4 - Organisational arrangements for financial entitiesArticle 5 - Risk management for TLPTArticle 6 - Risk management for pooled or joint TLPTsArticle 7 - Selection of TLPT providersArticle 8 - Specificities for pooled or joint TLPTsArticle 9 - Preparation phaseArticle 10 - Testing phase: threat intelligenceArticle 11 - Testing phase: red team testArticle 12 - Closure phaseArticle 13 - Remediation planArticle 14 - AttestationArticle 15 - Use of internal testersArticle 16 - Cooperation and mutual recognitionArticle 17 - Entry into forceANNEX I - Content of the project charter (Article 9(2)(a))ANNEX II - Content of the scope specification document (Article 9(6))ANNEX III - Content of the targeted threat intelligence report (Article 10(5))ANNEX IV - Content of the red team test plan (Article 11(1))ANNEX V - Content of the red team test report (Article 12(2))ANNEX VI - Content of the blue team test report (Article 12(4))ANNEX VII - Details of the report summarizing the relevant findings of the TLPT referred to in Article 26(6) of Regulation (EU) 2022/2554ANNEX VIII - Details of the attestation of the TLPT referred to in Article 26(7) of Regulation (EU) 2022/2554