DORA · CELEX 32022R2554
Article 27
Verbatim text of the current consolidated version · status: in force. Check it on EUR-Lex ↗
DORA, Article 27(1) — Requirements for testers for the carrying out of TLPT
Financial entities shall only use testers for the carrying out of TLPT, that: (a) are of the highest suitability and reputability; (b) possess technical and organisational capabilities and demonstrate specific expertise in threat intelligence, penetration testing and red team testing; (c) are certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks; (d) provide an independent assurance, or an audit report, in relation to the sound management of risks associated with the carrying out of TLPT, including the due protection of the financial entity’s confidential information and redress for the business risks of the financial entity; (e) are duly and fully covered by relevant professional indemnity insurances, including against risks of misconduct and negligence.
DORA, Article 27(2) — Requirements for testers for the carrying out of TLPT
When using internal testers, financial entities shall ensure that, in addition to the requirements in paragraph 1, the following conditions are met: (a) such use has been approved by the relevant competent authority or by the single public authority designated in accordance with Article 26(9) and (10); (b) the relevant competent authority has verified that the financial entity has sufficient dedicated resources and ensured that conflicts of interest are avoided throughout the design and execution phases of the test; and (c) the threat intelligence provider is external to the financial entity.
DORA, Article 27(3) — Requirements for testers for the carrying out of TLPT
Financial entities shall ensure that contracts concluded with external testers require a sound management of the TLPT results and that any data processing thereof, including any generation, store, aggregation, draft, report, communication or destruction, do not create risks to the financial entity.
This text is not written by an AI. It is rendered from a corpus built from the official EUR-Lex source, where every fragment is content-hashed and signed at ingestion — which is what lets you cite it and defend the citation. Ask a question about this article →
Other articles of the DORA
Art. 1Art. 2Art. 3Art. 4Art. 5Art. 6Art. 7Art. 8Art. 9Art. 10Art. 11Art. 12Art. 13Art. 14Art. 15Art. 16Art. 17Art. 18Art. 19Art. 20Art. 21Art. 22Art. 23Art. 24Art. 25Art. 26Art. 27Art. 28Art. 29Art. 30Art. 31Art. 32Art. 33Art. 34Art. 35Art. 36Art. 37Art. 38Art. 39Art. 40Art. 41Art. 42Art. 43Art. 44Art. 45Art. 46Art. 47Art. 48Art. 49Art. 50Art. 51Art. 52Art. 53Art. 54Art. 55Art. 56Art. 57Art. 58Art. 59Art. 60Art. 61Art. 62Art. 63Art. 64
Acquis returns official sources verbatim with citations; it is not legal advice. Texts © European Union, reuse permitted (Decision 2011/833/EU) — only the EUR-Lex original is authentic. Why legal AI fails · Coverage