Financial entitiesas defined in Article 2, points (a) to (t) should ensure that, as required by Article 26(8), first subparagraph, of Regulation (EU) 2022/2554, every three tests they contract external testers. Where financial entitiesas defined in Article 2, points (a) to (t) include in the team of testers both internal and external testers, this should be considered as a TLPT(threat-led penetration testing) a framework that mimics the tactics, techniques and procedures of real-life threat actors perceived as posing a genuine cyber threat, that delivers a controlled, bespoke, intelligence-led (red team) test of the financial entity’s critical live production systems performed with internal testers for the purposes of Article 26(8), first subparagraph, of Regulation (EU) 2022/2554.