Rättskällor med officiella primärkällor

Utskrivet ·

Hopp til innhold
Hopp til svaret

Agent · dora-2022-2554-26

DORA artikel 26: Advanced testing of ICT tools, systems and processes based on TLPT

Strukturelt tre: artikkelens egne punkter, ordrett.

CELEX 32022R2554 · 2026-08-18 · Vekt 86 · minimal-risk

ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.

DORAOffisiell kilde

Hva siden er
Agent, DORA artikel 26
Lest mot offisiell kilde
2026-08-18Fersk
Ansvarlig utgiver
ExploreWorld Legal, redaksjonenAnsvarsposisjon

Jurisdiksjon

Samme agent, lest med ett lands øyne.

Inndata

  • in_scopeThe article applies to the situationboolean
  • punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)

Regeltre

  1. Hvis: alla(in_scope = true, punkt = 1)

    Paragraph 1 applies

    1. Financial entities, other than entities referred to in Article 16(1), first subparagraph, and other than microenterprises, which are identified in accordance with paragraph 8, third subparagraph, of this Article, shall carry out at least every 3 years advanced testing by means of TLPT. Based on the risk profile of the financial entity and taking into account operational circumstances, the competent authority may,…

    Punkt 1

  2. Hvis: alla(in_scope = true, punkt = 2)

    Paragraph 2 applies

    2. Each threat-led penetration test shall cover several or all critical or important functions of a financial entity, and shall be performed on live production systems supporting such functions.

    Punkt 2

  3. Hvis: alla(in_scope = true, punkt = 3)

    Paragraph 3 applies

    Financial entities shall identify all relevant underlying ICT systems, processes and technologies supporting critical or important functions and ICT services, including those supporting the critical or important functions which have been outsourced or contracted to ICT third-party service providers.

    Punkt 3

  4. Hvis: alla(in_scope = true, punkt = 4)

    Paragraph 4 applies

    Financial entities shall assess which critical or important functions need to be covered by the TLPT. The result of this assessment shall determine the precise scope of TLPT and shall be validated by the competent authorities.

    Punkt 4

  5. Hvis: alla(in_scope = true, punkt = 5)

    Paragraph 5 applies

    3. Where ICT third-party service providers are included in the scope of TLPT, the financial entity shall take the necessary measures and safeguards to ensure the participation of such ICT third-party service providers in the TLPT and shall retain at all times full responsibility for ensuring compliance with this Regulation.

    Punkt 5

  6. Hvis: alla(in_scope = true, punkt = 6)

    Paragraph 6 applies

    4. Without prejudice to paragraph 2, first and second subparagraphs, where the participation of an ICT third-party service provider in the TLPT, referred to in paragraph 3, is reasonably expected to have an adverse impact on the quality or security of services delivered by the ICT third-party service provider to customers that are entities falling outside the scope of this Regulation, or on the confidentiality of the…

    Punkt 6

  7. Hvis: alla(in_scope = true, punkt = 7)

    Paragraph 7 applies

    That pooled testing shall cover the relevant range of ICT services supporting critical or important functions contracted to the respective ICT third-party service provider by the financial entities. The pooled testing shall be considered TLPT carried out by the financial entities participating in the pooled testing.

    Punkt 7

  8. Hvis: alla(in_scope = true, punkt = 8)

    Paragraph 8 applies

    The number of financial entities participating in the pooled testing shall be duly calibrated taking into account the complexity and types of services involved.

    Punkt 8

  9. Hvis: alla(in_scope = true, punkt = 9)

    Paragraph 9 applies

    5. Financial entities shall, with the cooperation of ICT third-party service providers and other parties involved, including the testers but excluding the competent authorities, apply effective risk management controls to mitigate the risks of any potential impact on data, damage to assets, and disruption to critical or important functions, services or operations at the financial entity itself, its counterparts or to…

    Punkt 9

  10. Hvis: alla(in_scope = true, punkt = 10)

    Paragraph 10 applies

    6. At the end of the testing, after reports and remediation plans have been agreed, the financial entity and, where applicable, the external testers shall provide to the authority, designated in accordance with paragraph 9 or 10, a summary of the relevant findings, the remediation plans and the documentation demonstrating that the TLPT has been conducted in accordance with the requirements.

    Punkt 10

  11. Hvis: alla(in_scope = true, punkt = 11)

    Paragraph 11 applies

    7. Authorities shall provide financial entities with an attestation confirming that the test was performed in accordance with the requirements as evidenced in the documentation in order to allow for mutual recognition of threat led penetration tests between competent authorities. The financial entity shall notify the relevant competent authority of the attestation, the summary of the relevant findings and the remedia…

    Punkt 11

  12. Hvis: alla(in_scope = true, punkt = 12)

    Paragraph 12 applies

    Without prejudice to such attestation, financial entities shall remain at all times fully responsible for the impact of the tests referred to in paragraph 4.

    Punkt 12

  13. Hvis: alla(in_scope = true, punkt = 13)

    Paragraph 13 applies

    8. Financial entities shall contract testers for the purposes of undertaking TLPT in accordance with Article 27. When financial entities use internal testers for the purposes of undertaking TLPT, they shall contract external testers every three tests.

    Punkt 13

  14. Hvis: alla(in_scope = true, punkt = 14)

    Paragraph 14 applies

    Credit institutions that are classified as significant in accordance with Article 6(4) of Regulation (EU) No 1024/2013, shall only use external testers in accordance with Article 27(1), points (a) to (e).

    Punkt 14

Hvis ingen regel treffer: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.

Artikkelteksten som ble lest

  1. 11. Financial entities, other than entities referred to in Article 16(1), first subparagraph, and other than microenterprises, which are identified in accordance with paragraph 8, third subparagraph, of this Article, shall carry out at least every 3 years advanced testing by means of TLPT. Based on the risk profile of the financial entity and taking into account operational circumstances, the competent authority may, where necessary, request the financial entity to reduce or increase this frequency.
  2. 22. Each threat-led penetration test shall cover several or all critical or important functions of a financial entity, and shall be performed on live production systems supporting such functions.
  3. 3Financial entities shall identify all relevant underlying ICT systems, processes and technologies supporting critical or important functions and ICT services, including those supporting the critical or important functions which have been outsourced or contracted to ICT third-party service providers.
  4. 4Financial entities shall assess which critical or important functions need to be covered by the TLPT. The result of this assessment shall determine the precise scope of TLPT and shall be validated by the competent authorities.
  5. 53. Where ICT third-party service providers are included in the scope of TLPT, the financial entity shall take the necessary measures and safeguards to ensure the participation of such ICT third-party service providers in the TLPT and shall retain at all times full responsibility for ensuring compliance with this Regulation.
  6. 64. Without prejudice to paragraph 2, first and second subparagraphs, where the participation of an ICT third-party service provider in the TLPT, referred to in paragraph 3, is reasonably expected to have an adverse impact on the quality or security of services delivered by the ICT third-party service provider to customers that are entities falling outside the scope of this Regulation, or on the confidentiality of the data related to such services, the financial entity and the ICT third-party service provider may agree in writing that the ICT third-party service provider directly enters into contractual arrangements with an external tester, for the purpose of conducting, under the direction of one designated financial entity, a pooled TLPT involving several financial entities (pooled testing) to which the ICT third-party service provider provides ICT services.
  7. 7That pooled testing shall cover the relevant range of ICT services supporting critical or important functions contracted to the respective ICT third-party service provider by the financial entities. The pooled testing shall be considered TLPT carried out by the financial entities participating in the pooled testing.
  8. 8The number of financial entities participating in the pooled testing shall be duly calibrated taking into account the complexity and types of services involved.
  9. 95. Financial entities shall, with the cooperation of ICT third-party service providers and other parties involved, including the testers but excluding the competent authorities, apply effective risk management controls to mitigate the risks of any potential impact on data, damage to assets, and disruption to critical or important functions, services or operations at the financial entity itself, its counterparts or to the financial sector.
  10. 106. At the end of the testing, after reports and remediation plans have been agreed, the financial entity and, where applicable, the external testers shall provide to the authority, designated in accordance with paragraph 9 or 10, a summary of the relevant findings, the remediation plans and the documentation demonstrating that the TLPT has been conducted in accordance with the requirements.
  11. 117. Authorities shall provide financial entities with an attestation confirming that the test was performed in accordance with the requirements as evidenced in the documentation in order to allow for mutual recognition of threat led penetration tests between competent authorities. The financial entity shall notify the relevant competent authority of the attestation, the summary of the relevant findings and the remediation plans.
  12. 12Without prejudice to such attestation, financial entities shall remain at all times fully responsible for the impact of the tests referred to in paragraph 4.
  13. 138. Financial entities shall contract testers for the purposes of undertaking TLPT in accordance with Article 27. When financial entities use internal testers for the purposes of undertaking TLPT, they shall contract external testers every three tests.
  14. 14Credit institutions that are classified as significant in accordance with Article 6(4) of Regulation (EU) No 1024/2013, shall only use external testers in accordance with Article 27(1), points (a) to (e).

Opphav

treatyTFEU art. 288 (förordning)
act32022R2554
chapter
article26
paragraphs14
jurisdictionEuropean Union (EU)
supervisorFinansinspektionen — Sweden
national

Grensesnitt

callhttps://legal.exploreworldai.com/api/public/v1/agents/dora-2022-2554-26/run
methodGET
outputmatched, outcome, trace, missing, hash
Kvote60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hasher

textsha256:f96eb3003ca5456226b9041ec5c3d9145de685ff1eb5f9e131b2f5ccdda873c6
scriptsha256:4128b568108a214d976bf59aec1f552f350346249fa3177977620fc4db74b514
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:06b118693789d18168410430ce944e0a61d2aeb55812cfc29a19cb572d4f947d
versionagent-engine-1+legal-2026-08-25 / 06b118693789d181

Artefakter

Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Sitering: 32022R2554 art. 26, Advanced testing of ICT tools, systems and processes based on TLPT. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-26 (hämtad 2026-08-18, bevis sha256:facaafc8d1ed8519, bygge legal-2026-08-25).