EU regulatory register · DORA
Article 27Requirements for testers for the carrying out of TLPT
CELEX 32022R2554 · Read on 2026-08-18
Official text
Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.
1. Financial entities shall only use testers for the carrying out of TLPT, that:
(a)
are of the highest suitability and reputability;
(b)
possess technical and organisational capabilities and demonstrate specific expertise in threat intelligence, penetration testing and red team testing;
(c)
are certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks;
(d)
provide an independent assurance, or an audit report, in relation to the sound management of risks associated with the carrying out of TLPT, including the due protection of the financial entity’s confidential information and redress for the business risks of the financial entity;
(e)
are duly and fully covered by relevant professional indemnity insurances, including against risks of misconduct and negligence.
2. When using internal testers, financial entities shall ensure that, in addition to the requirements in paragraph 1, the following conditions are met:
(a)
such use has been approved by the relevant competent authority or by the single public authority designated in accordance with Article 26(9) and (10);
The article continues in the official text.
The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act