Updated 01/07/2025
Coming into force on 08/07/2025

Initial Legal Act
Amendments
Search within this legal act

ANNEX V - Delegated Regulation 2025/1190

ANNEX V

Content of the red team test report (Article 12(2))

The red team test report shall contain information on at least all of the following:

(a)

information on the performed attack, including:

(i)

the targeted critical or important functions and identified ICT systems, processes and technologies supporting the critical or important function, as identified in the red team test plan;

(ii)

summary of each scenario;

(iii)

flags reached and not reached;

(iv)

attack paths followed successfully and unsuccessfully;

(v)

tactics, techniques and procedures used successfully and unsuccessfully;

(vi)

deviations from the red team test plan, if any;

(vii)

leg-ups granted, if any;

(b)

all actions that the testers are aware of that were performed by the blue team to reconstruct the attack and to mitigate its effects;

(c)

discovered vulnerabilities and other findings, including:

(i)

vulnerability and other finding description including their criticality;

(ii)

root cause analysis of successful attacks;

(iii)

recommendations for remediation including indication of the remediation priority.