Only financial entities that their competent authority has identified for TLPT (under Article 26(8), third subparagraph, on impact, financial stability and ICT risk profile, applying Article 4(2)) must carry out threat-led penetration testing; Article 16(1) entities and microenterprises are excluded. Identified entities test at least every 3 years, a frequency the authority may shorten or extend for the entity's risk profile. Each test covers some or all of the critical or important functions on live production systems, including outsourced ones; the entity's scoping assessment is validated by the authority; ICT third-party providers in scope take part, or join pooled testing where their participation would harm other customers; risk management controls limit impact on data, assets and services; after testing, a summary of findings, remediation plans and documentation go to the TLPT authority, which issues an attestation. Testers meet Article 27; entities using internal testers contract external testers every third test, and significant credit institutions use only external testers.
This control maps to 15 controls across 9 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
DORA DORA-Art.26 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.
The graph holds this control, the 15 it maps to, and the evidence behind each claim, over MCP and REST.