TLPT RTS (EU 2025/1190): DORA penetration testing, finally clear.
Commission Delegated Régulation (EU) 2025/1190 is the technical standard (RTS) completing Article 26 of DORA on threat-led penetration testing (TLPT). Applicable since 8 July 2025, implemented in Luxembourg via the TIBER-LU framework (BCL + CSSF). Let's clear the fog.
Law contents
All 17 articles, in the order of the official text. Each one is analysed separately, with the official text and Luxgap practical guidance.
- 1. Definitions
- 2. Identification of financial entities required to perform TLPT
- 3. TCT and TLPT Test Managers
- 4. Organisational arrangements for financial entities
- 5. Risk management for TLPT
- 6. Risk management for pooled or joint TLPTs
- 7. Selection of TLPT providers
- 8. Specificities for pooled or joint TLPTs
- 9. Preparation phase
- 10. Testing phase: threat intelligence
- 11. Testing phase: red team test
- 12. Closure phase
- 13. Remediation plan
- 14. Attestation
- 15. Use of internal testers
- 16. Cooperation and mutual recognition
- 17. Entry into force
Annexes
- I. Content of the project charter (Article 9(2)(a))
- II. Content of the scope specification document (Article 9(6))
- III. Content of the targeted threat intelligence report (Article 10(5))
- IV. Content of the red team test plan (Article 11(1))
- V. Content of the red team test report (Article 12(2))
- VI. Content of the blue team test report (Article 12(4))
- VII. Details of the report summarizing the relevant findings of the TLPT referred to in Article 26(6) of Regulation (EU) 2022
- VIII. Details of the attestation of the TLPT referred to in Article 26(7) of Regulation (EU) 2022/2554
Who is concerned?
Financial entities identified as significant by their size and systemic importance: systemic crédit institutions, certain payment and e-money institutions, central securities depositories (CSDs), central counterparties (CCPs), trading venues, some insurance and reinsurance undertakings.
A TLPT must be conducted at least every 3 years on critical or important functions, on real production systems (not test environments).
Key obligations
- Identification: determine whether the entity falls within TLPT scope (RTS 2025/1190 criteria applied by the CSSF, TLPT authority under DORA Art. 46).
- Threat intelligence: have an external provider produce credible entity-specific attack scénarios.
- Red teaming: have a certified red team execute realistic attacks (advanced adversary TTPs) on production systems over 10 to 12 weeks, without the defence teams (blue team) being warned.
- Testers: external by default; internal only under strict independence conditions and authority authorisation.
- Closure and remédiation: detailed report, prioritised remédiation plan, attestation issued by the CSSF.
- TIBER-LU: organise the test per the TIBER-LU Implementation Document (revised 20 June 2025).
Deadlines
RTS 2025/1190 was published in the Official Journal on 18 June 2025 and has applied directly since 8 July 2025. DORA's TLPT requirements (Art. 26) have applied since 17 January 2025. The TIBER-LU framework was revised on 20 June 2025 to align with DORA and the ECB-revised TIBER-EU of 11 February 2025.
Sanctions for non-compliance
TLPT falls under the DORA supervisory framework run by the CSSF. Failing test obligations, or not remediating identified vulnerabilities, exposes entities to DORA and CSSF sanctions: injunctions, administrative sanctions, and up to 1% of average daily worldwide turnover for critical ICT third-party providers. Beyond that, a test revealing unfixed flaws weakens the entity's whole operational résilience posture.
How Luxgap helps
Our CISO mandate dedicated to the financial sector and our pentest / red team teams cover the full TLPT cycle: eligibility diagnosis, TIBER-LU préparation, threat intelligence and red teaming by certified testers, remédiation and re-test integrated into the ICT risk management framework.
Let's discuss your situation.
This topic is handled case by case. Get in touch to discuss it: reply within one business day, no commitment.
Contact us →