Annex II

Content of the scope specification document (Article 9(6))

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

1.   

The scope specification document shall contain a list of all critical or important functions identified by the financial entity.

2.   

For each identified critical or important function, the following information shall be included:

(a)

where the critical or important function is not included in the scope of the TLPT, the explanation of the reasons for which it is not included;

(b)

where the critical or important function is included in the scope of the TLPT:

(i)

the explanation of the reasons for its inclusion;

(ii)

the identified ICT system(s) supporting that critical or important function;

(iii)

for each identified ICT system:

1.

whether it is outsourced and if so, the name of the ICT third party service provider;

2.

the jurisdictions in which the ICT system is used;

3.

a high-level description of preliminary flag(s), indicating which security aspect of confidentiality, integrity, authenticity or availability is covered by each flag.

Luxembourg specificity
TIBER-LU Implementation Document (BCL + CSSF), révisé le 20 juin 2025

In Luxembourg, the TLPT authority under Article 26 of DORA is the CSSF, operating jointly with the BCL within the TIBER-LU framework. The TIBER-LU Implementation Document was revised on 20 June 2025 and details local expectations on the scope specification document content, in particular the link with the ICT third-party register (CSSF circulars 22/806 and 25/882). The methodology aligns with TIBER-EU as revised by the ECB on 11 February 2025.

Luxgap practice: we align your scope specification document with the 20 June 2025 TIBER-LU template and check consistency with your CSSF declaration before submission to the BCL test team.