eu-space-act

Art. 88(3)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (20)

Techniques referencing this article

  • DE-0003.12Poison AI/ML Training for EvasionST0006
    addresses
    moderate
    direct

    AI/ML training-data poisoning (primary: Art. 88(1)) cascades to 88(3) — TLPT every 3 years should validate ML pipeline integrity against adversarial-input tests.

  • DE-0007Evasion via RootkitST0006
    addresses
    high
    direct

    Rootkit detection (primary: Art. 88(1)) cascades to 88(3) — TLPT 3-yearly cadence is exactly the offensive-testing discipline that surfaces persistent rootkits between security audits.

  • PNT-geofenced malware detection (primary: Art. 88(1)) cascades to 88(3) — TLPT can include orbital-trajectory behavioral testing across the 3-year cadence.

  • EX-0005.01Design FlawsST0004
    addresses
    moderate
    direct

    Hardware-design-flaw exploitation (primary: Art. 88(1)) cascades to 88(3) — pre-launch + 3-yearly TLPT is the cadence at which design-flaw classes are stressed by external testers.

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    direct

    Code-flaw exploitation (primary: Art. 88(1)) cascades to 88(3) — TLPT prior-to-launch and every 3 years validates that code-defect classes remain detected by operator testing.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high
    direct

    FSW code-flaw testing (primary: Art. 88(1)) cascades to 88(3) — pre-launch TLPT is the canonical case for FSW security-test cadence.

  • EX-0009.02Operating SystemST0004
    addresses
    moderate
    direct

    OS-layer testing (primary: Art. 88(1)) cascades to 88(3) — TLPT 3-yearly cadence covers kernel-and-driver attack surfaces.

  • EX-0010Malicious CodeST0004
    addresses
    high
    direct

    Malicious-code testing (primary: Art. 88(1)) cascades to 88(3) — pre-launch and 3-yearly TLPT validates that update/file-transfer/maintenance pathways do not accept malicious payloads.

  • EX-0010.03RootkitST0004
    addresses
    moderate
    direct

    Rootkit testing (primary: Art. 88(1)) cascades to 88(3) — out-of-band attestation testing in TLPT cadence is the operator discipline that surfaces rootkit persistence.

  • EX-0012.13Poison AI/ML Training DataST0004
    addresses
    moderate
    direct

    AI/ML training-data testing (primary: Art. 88(1)) cascades to 88(3) — TLPT cadence covers ML pipeline adversarial-input scenarios.

  • EX-0015Side-Channel AttackST0004
    addresses
    moderate
    direct

    Side-channel testing (primary: Art. 88(1)) cascades to 88(3) — periodic side-channel and fault-injection testing falls within the TLPT 3-yearly framework.

  • EXF-0002Side-Channel ExfiltrationST0008
    addresses
    moderate
    direct

    Side-channel exfiltration testing (primary: Art. 88(1)) cascades to 88(3) — TLPT 3-yearly cadence covers side-channel and emanation testing as part of broader penetration testing.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    moderate
    direct

    Dev-environment compromise testing (primary: Art. 88(1)) cascades to 88(3) — TLPT scope can include dev-pipeline integrity validation against the 3-yearly cadence.

  • Software-dependency testing (primary: Art. 88(1)) cascades to 88(3) — TLPT can include dependency provenance testing across the 3-yearly cadence.

  • LM-0005Virtualization EscapeST0007
    addresses
    moderate
    direct

    Hypervisor-escape testing (primary: Art. 88(1)) cascades to 88(3) — TLPT 3-yearly cadence covers separation-kernel boundary fuzzing on operator products.

  • PER-0002BackdoorST0005
    addresses
    high
    direct

    Backdoor detection (primary: Art. 88(1)) cascades to 88(3) — TLPT prior-to-launch + 3-yearly is the canonical operator-side cadence for adversary-perspective backdoor surfacing.

  • PER-0002.01Hardware BackdoorST0005
    addresses
    moderate
    direct

    Hardware-backdoor testing (primary: Art. 88(1)) cascades to 88(3) — TLPT cadence with hardware-attestation testing surfaces durable backdoors.

  • PER-0002.02Software BackdoorST0005
    addresses
    moderate
    direct

    Software-backdoor testing (primary: Art. 88(1)) cascades to 88(3) — TLPT cadence with adversary-emulating code review surfaces nonpublic command paths.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    moderate
    direct

    Security-testing-tool reconnaissance (primary: Art. 88(1)) cascades to 88(3) — TLPT 3-yearly cadence is the high-level discipline that surfaces gaps in operator's own testing programme.

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    moderate
    direct

    Known-vulnerability reconnaissance (primary: Art. 88(1)) cascades to 88(3) — TLPT validates that operator products are tested against known-vuln catalogs at the 3-yearly cadence.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.