Source: OJ L, 2025/1190, 18.6.2025

Current language: EN

Article 3 TCT and TLPT Test Managers


Summary What does Article 3 of the RTS on threat-led penetration testing say?

This article establishes the internal structure that TLPT authorities must put in place to oversee and coordinate threat-led penetration testing.

It sets out the requirement for a dedicated TLPT Cyber Team (TCT), composed of test managers, to take responsibility for coordinating TLPT-related activities.

The article also makes clear that TLPT authority involvement is not merely administrative — it extends across all phases of a given test.

Important points:

  • TLPT authorities are required to establish a TCT and designate a test manager, plus at least one alternate, for each individual TLPT.
  • Test managers are responsible for monitoring and ensuring compliance with this Regulation throughout the testing process.
  • TLPT authorities must participate in all phases of the TLPT, not just at the initiation or sign-off stage.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. A TLPT authority shall assign the responsibility for coordinating TLPT-related activities to a TCT. A TCT shall be composed of test managers that are assigned to oversee an individual TLPT.

    1. For each test, the TLPT authority shall designate a test manager and at least one alternate.

    1. The test managers shall monitor whether, and ensure that, the requirements laid down in this Regulation are complied with.

    1. The test manager shall communicate the contact details of the TCT to the financial entity through the notification referred to in Article 9(1).

    1. The TLPT authority shall participate to all the phases of the TLPT.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod