← current version of this provision

DORA Article 27 — held text

This page is a held version, frozen at the capture below. It is a source for review. It is not advice, and it does not determine whether this provision applies to you.

Article 27 Requirements for testers for the carrying out of TLPT 1. Financial entities shall only use testers for the carrying out of TLPT, that: (a) are of the highest suitability and reputability; (b) possess technical and organisational capabilities and demonstrate specific expertise in threat intelligence, penetration testing and red team testing; (c) are certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks; (d) provide an independent assurance, or an audit report, in relation to the sound management of risks associated with the carrying out of TLPT, including the due protection of the financial entity's confidential information and redress for the business risks of the financial entity; (e) are duly and fully covered by relevant professional indemnity insurances, including against risks of misconduct and negligence. 2. When using internal testers, financial entities shall ensure that, in addition to the requirements in paragraph 1, the following conditions are met: (a) such use has been approved by the relevant competent authority or by the single public authority designated in accordance with Article 26(9) and (10); (b) the relevant competent authority has verified that the financial entity has sufficient dedicated resources and ensured that conflicts of interest are avoided throughout the design and execution phases of the test; and (c) the threat intelligence provider is external to the financial entity. 3. Financial entities shall ensure that contracts concluded with external testers require a sound management of the TLPT results and that any data processing thereof, including any generation, store, aggregation, draft, report, communication or destruction, do not create risks to the financial entity. CHAPTER V Managing of ICT third-party risk Section I Key principles for a sound management of ICT third-party risk
CELEX: 32022R2554 · provision: 27
Locator: Article 27; PDF page 48; derived-text line 1120
Held artifact: docs_evidence/eu-legislation/eurlex-full-text/20260823T093000Z/32022R2554.pdf
Artifact SHA-256: 85307f9e2a0409826dd0f54489645935816d16e929f0db4db3ef15badd11d38c
Captured: 20260823T093000Z
Extracted with: pdftotext version 4.00
Official source: EUR-Lex
This version: /celex/32022R2554/ART_27/20260823-85307f9e/
Corpus Merkle root: 581628a5b36518981241d2b51f048aa46384f30a74bf648ef542c652028cdeff
Membership proof: 10 hashes — see corpus-proof.json
Modal verbs, counted verbatim (not a legal characterisation): 'shall not': 0 · 'shall': 3 · 'must': 0 · 'may not': 0 · 'may': 0 · 'should': 0

To verify independently: fetch the official source above, extract it with the named tool, and confirm the artifact SHA-256 matches. Then check this provision's leaf against the published Merkle root using the proof in corpus-proof.json.