Source: OJ L, 2025/1190, 18.6.2025
- Digital operational resilience in the financial sector
Digital operational resilience testing
- RTS on threat-led penetration testing
Annex VIII Details of the attestation of the TLPT referred to in Article 26(7) of Regulation (EU) 2022/2554
The attestation shall contain at least all of the following information:
on the performed TLPT:
the starting and end dates of the TLPT;
the critical or important functionsmeans a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; in scope of the test;
where relevant, information on critical or important functionsmeans a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; in scope of the test in relation to which the TLPT was not performed;
where relevant, other financial entities that were involved in the TLPT;
where relevant, the ICT third-party services providersmeans an undertaking providing ICT services; that participated in the TLPT;
in respect of testers:
whether internal testers were used;
whether Article 5(3), second subparagraph, was used by the financial entity;
the duration, in calendar days, of the active red team testing phase;
where several TLPT authorities have been involved in the TLPT, the other TLPT authorities, and in which capacity;
list of the documents examined by the TLPT authority for the purposes of the attestation.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.