Commission Delegated Regulation (EU) 2025/1190 of 13 February 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition
Proposed act with possible EEA relevance
Act under scrutiny by EEA EFTA
Draft Joint Committee Decision (JCD) under consideration
Entry into force of Joint Committee Decision (JCD) pending
Incorporated into the EEA Agreement and in force
Incorporated into the EEA Agreement but no longer in force
Legal status
EU legal act incorporated into the EEA Agreement by a Joint Committee Decision (JCD)
Area (EEA Agreement)
IX Financial Services
Joint committee decision (JCD)
299/2025
In force in the EEA
Yes
Legal Documents
Commission Delegated Regulation (EU) 2025/1190 of 13 February 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition
Framseld reglugerð framkvæmdastjórnarinnar (ESB) 2025/1190 frá 13. febrúar 2025 um viðbætur við reglugerð Evrópuþingsins og ráðsins (ESB) 2022/2554 að því er varðar tæknilega eftirlitsstaðla þar sem tilgreind eru viðmið sem notuð eru til að auðkenna aðila á fjármálamarkaði sem skylt er að framkvæma ógnamiðaðar innbrotsprófanir, kröfur og staðlar sem gilda um notkun á innri prófunaraðilum, kröfur í tengslum við umfang, prófunaraðferðir og nálgun fyrir hvern fasa í prófunum, niðurstöður, lokunar- og úrbótastig prófunar og tegund eftirlitssamvinnu og annarrar viðeigandi samvinnu sem þörf er á við innleiðingu ógnamiðaðra innbrotsprófana og til að greiða fyrir gagnkvæmri viðurkenningu
Delegierte Verordnung (EU) 2025/1190 der Kommission vom 13. Februar 2025 zur Ergänzung der Verordnung (EU) 2022/2554 des Europäischen Parlaments und des Rates durch technische Regulierungsstandards zur Festlegung der Kriterien für die Bestimmung der Finanzunternehmen, die zur Durchführung von bedrohungsorientierten Penetrationstests verpflichtet sind, der Anforderungen und Standards für den Einsatz interner Tester, der Anforderungen hinsichtlich des Testumfangs, der Testmethodik und des Testkonzepts für jede einzelne Phase des Testverfahrens sowie der Ergebnisse, des Abschlusses und der Behebungsphasen der Tests sowie der Art der aufsichtlichen und sonstigen relevanten Zusammenarbeit, die für die Umsetzung von bedrohungsorientierten Penetrationstests und die Erleichterung der gegenseitigen Anerkennung dieser Tests erforderlich ist
History
Disclaimer: EEA-Lex is provided for information purposes only. The information is not guaranteed or promised to be current or complete and is not intended to replace any applicable legal sources.