Source: OJ L, 2025/1190, 18.6.2025

Current language: DE

Artikel 8 Besondere Anforderungen bei gebündelten oder gemeinsamen TLPT


Summary What does Article 8 of the RTS on threat-led penetration testing say?

This article serves as a bridging provision that connects the general TLPT procedural steps (laid out in Articles 9 to 15) to the specific scenarios where multiple financial entities are involved in a joint or pooled TLPT.

It establishes two default rules: first, that each participating financial entity must individually follow the full procedural sequence, and second, that where multiple TLPT authorities are involved, any reference to "the TLPT authority" throughout Articles 9 to 15 should be read as referring to the lead TLPT authority.

Both rules can be displaced — the first by a decision of the lead TLPT authority, and the second by other provisions within the regulation itself.

Important points:

  • Follow each procedural step in Articles 9 to 15 individually, even when participating in a joint or pooled TLPT, unless the lead TLPT authority decides otherwise.
  • In joint or pooled TLPTs involving multiple TLPT authorities, the lead TLPT authority assumes the role of "the TLPT authority" for the purposes of Articles 9 to 15.
  • This article directly links to Article 16, which governs how joint and pooled TLPTs are organised and how a lead TLPT authority is determined.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Sofern die federführende TLPT-Behörde nichts anderes beschließt, führt jedes Finanzunternehmen für den Fall, dass mehrere gemäß Artikel 16 Absätze 2 oder 4 ermittelte Finanzunternehmen an einem gebündelten oder gemeinsamen TLPT beteiligt sind, jeden der in den Artikeln 9 bis 15 genannten Schritte aus.

    1. Sofern in dieser Verordnung nichts anderes bestimmt ist, sind für den Fall, dass mehrere TLPT-Behörden an einem gemeinsamen TLPT oder einem gebündelten TLPT gemäß Artikel 16 Absatz 3 oder Artikel 16 Absatz 5 beteiligt sind, Bezugnahmen auf „TLPT-Behörde“ in den Artikeln 9 bis 15 als Bezugnahme auf die federführende TLPT-Behörde für einen solchen gebündelten oder gemeinsamen TLPT zu verstehen.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod