The classic trap
The project charter is the first deliverable the CSSF, the TLPT authority under Article 46 of DORA, reviews before validating the launch of the test. The trap is treating it as an administrative formality when it actually locks down the exact scope of critical or important functions being tested, the confidential codename, the encrypted communication channels and the deadlines for the four phases. An incomplete charter (missing cross-border functions, unidentified ICT providers, non-encrypted channels) leads the CSSF and the BCL to reject or delay the test under the TIBER-LU framework, whose Implementation Document was revised on 20 June 2025.
The mandatory fields your TLPT charter must fill without gaps
- The Control Team Lead, named with contact details, as the single person responsible for the project plan.
- The nature of testers (internal, external or both), with the independence justification required by Article 26 of DORA.
- The encrypted communication channels selected under Article 9(2)(d) and 9(4)(a): email encryption, online data rooms, instant messaging.
- The codename for the TLPT, ensuring confidentiality towards the blue team.
- The list of critical or important functions operated in other Member States, with precise indication of each Member State concerned.
- The functions supported by ICT third-party service providers, with identification of each provider (to be articulated with subcontracting RTS 2025/532 and CSSF circulars 22/806 and 25/882).
- The deadlines (yyyy-mm-dd) for the Preparation Phase (Art. 9), Testing Phase (Art. 10-11), Closure Phase (Art. 12) and Remediation plan (Art. 13).
The most frequently overlooked point: the scope of ICT providers. A supplier such as eBRC, LuxConnect or POST hosting a critical function must appear in the test scope, otherwise remediation cannot properly feed the ICT risk management framework under CSSF circular 20/750.
How Luxgap automates this risk
Our Luxgap TLPT Charter Composer turns the drafting of the project charter into a pre-filled, consistent deliverable ready to submit to the CSSF, pulling the data from your IT environment itself rather than asking the Control Team Lead to re-enter everything. The agent cross-references your critical functions register (aligned with circular 22/806), your ICT provider register (RTS 2025/532) and your Microsoft Defender, Azure Sentinel and Active Directory configurations to map the real scope of the test.
- Automatically imports the list of critical or important functions from your DORA register and detects those operated in other Member States.
- Identifies each ICT third-party service provider supporting a critical function by cross-referencing contracts, accesses and flows, including Luxembourg hosters (eBRC, LuxConnect, POST).
- Verifies that the declared communication channels (email encryption, data room, messaging) meet the requirements of Articles 9(2)(d) and 9(4)(a) before submission.
- Generates and manages the confidential TLPT codename, with access segregation to preserve the blue team's blindness.
- Computes and proposes a consistent schedule of the four phases (preparation, testing, closure, remediation) in yyyy-mm-dd format aligned with the TIBER-LU framework revised on 20 June 2025.
- Produces a time-stamped, admissible PDF report, structured according to Annex I of RTS 2025/1190, ready to send to the CSSF and the BCL.
Available as an add-on to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real scope, with a free mock audit within 48h to measure your exposure before any commitment.