DORA TLPT vs TIBER‑EU/LU: the key gap on internal testers
Delegated Regulation (EU) 2025/1190 allows, under strict conditions, internal testers for DORA TLPT. TIBER‑EU/TIBER‑LU require external providers for recognition.
Summary — On 13 February 2025, the EU adopted Delegated Regulation (EU) 2025/1190 governing DORA TLPT (Art. 30). Unlike TIBER‑EU/TIBER‑LU, it allows, under strict conditions, the use of internal testers. This is immediately relevant for Luxembourg entities supervised by the CSSF.
The case
The European Commission published Delegated Regulation (EU) 2025/1190 supplementing DORA (Regulation (EU) 2022/2554) on threat‑led penetration tests (TLPT) under Article 30. It details scoping, identification criteria and “requirements and standards governing the use of internal testers.”
In parallel, the ECB updated the TIBER‑EU framework to align with DORA while reaffirming the central role of external TI/RT providers and mutual recognition: TIBER‑EU Framework updated to align with DORA.
In Luxembourg, the BCL and CSSF revised TIBER‑LU accordingly: see the TIBER‑LU implementation notice and the implementation guide (PDF).
Legal reasoning
- DORA Article 30 — TLPT for certain financial entities, mutual recognition and a TLPT authority. Technical details via delegated acts/RTS/ITS. See the ESAs/EBA “second batch” under DORA (17/07/2024): ESAs – second batch under DORA.
- TLPT Delegated Act 2025/1190 — Clarifies identification criteria, scope, methodology, phases and the requirements governing the use of internal testers. Text: EUR‑Lex.
- TIBER‑EU position — An ethical red teaming framework: to be recognised as TIBER‑EU, testing must be conducted by independent third‑party TI/RT providers. See framework and adoption/implementation: Executive summary, Adoption & implementation, and the PDF.
- TIBER‑EU procurement/attestation — Requirements for TI/RT providers: Service Provider Procurement – RT and Annexes. Structured attestation: TIBER‑EU Attestation Guidance.
Key divergence: DORA (via 2025/1190) opens a strictly governed internal‑tester route (independence, segregation, competence), while TIBER‑EU/TIBER‑LU require external providers for TIBER recognition. A DORA TLPT can, in theory, be performed internally if all conditions are met, but it will not be “TIBER‑recognised” without qualified external teams.
What this changes in practice
For DORA entities in Luxembourg
- The CSSF acts as the TLPT authority. Planning must respect the identification criteria, three‑year windows and cooperation/mutual recognition requirements in 2025/1190.
- If you target TIBER‑LU recognition (useful for cross‑jurisdictional sharing), execute under TIBER‑LU with external TI/RT providers compliant with TIBER‑EU: see the TIBER‑LU implementation and the ECB’s TIBER‑EU update.
To structure your programme, consider external support for the governance of cybersecurity audits and advanced testing, and refer to our overview of DORA operational resilience requirements for applicable obligations.
Internal vs external execution
- DORA 2025/1190 — Internal testers may be used under strict standards (functional independence, role segregation, skills, traceability, governance and TLPT authority validation).
- TIBER‑EU/TIBER‑LU — TIBER recognition requires independent external TI/RT providers with specific experience and security qualifications, under TCT oversight.
For a multi‑country group headquartered in Luxembourg, the most robust path remains a TIBER‑LU engagement with TIBER‑EU‑compliant external TI/RT, which will also satisfy DORA TLPT: see our focus on DORA in Luxembourg and the CSSF’s role.
Common pitfalls
- Equating “DORA‑compliant TLPT” with “TIBER‑recognised test.” An internal‑team test may meet DORA (if all 2025/1190 conditions are fulfilled) but will not be TIBER‑recognised without external providers.
- Underestimating governance and independence for internal testers: strong evidence is required, beyond basic HR segregation.
- Overlooking mutual recognition: DORA Art. 30/TIBER‑EU aim to avoid multi‑jurisdiction re‑testing. Without TIBER‑LU alignment, expect redundancy and challenges.
- Selecting non‑compliant TI/RT providers: adherence to TIBER procurement guidance and annexes is essential for recognition and supervisory confidence.
- Neglecting TIBER‑EU attestation/closure deliverables: without robust documentation, the test’s evidential value is weakened (Attestation Guidance).
Official sources
- DORA – TLPT (Art. 30) and delegated act: EUR‑Lex 2025/1190; ESAs/EBA (17/07/2024): second batch under DORA.
- TIBER‑EU (ECB) — update and framework: ECB news; executive summary; adoption & implementation; framework PDF; procurement guidance; annexes; attestation guidance.
- TIBER‑LU (Luxembourg): announcement and PDF guide.
Conclusion
The “DORA 2025/1190 vs TIBER‑EU/TIBER‑LU” divergence is operational: who can test. DORA opens a tightly governed internal route; TIBER remains anchored on external providers for recognition. Need to chart your TLPT/TIBER‑LU path? Tell us about your objectives and timeline.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →