
On the 13th of February 2025, the European Commission adopted the Commission Delegated Regulation supplementing DORA with regard to RTS specifying the criteria used for identifying financial entities required to perform threat-led penetration testing (TLPT), the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition (the RTS specifying elements related to threat-led penetration tests under Art. 26(11) of DORA).
However, that RTS has not yet been published in the EU Official Journal, as the act will be published in the EU Official Journal of the EU and enter into force if the European Parliament or the Council of the EU do not object to it. The scrutiny period lasts generally 2 months following the adoption of the act.
The Commission Delegated Regulation 2025/295 of 24 October 2024 supplementing DORA with regard to RTS on harmonisation of conditions enabling the conduct of the oversight activities was published in the EU Official Journal on 13 Feb 2025.