Content of the scope specification document (Article 9(6))
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
1.
The scope specification document shall contain a list of all critical or important functions identified by the financial entity.
2.
For each identified critical or important function, the following information shall be included:| (a) | where the critical or important function is not included in the scope of the TLPT, the explanation of the reasons for which it is not included; |
| (b) | where the critical or important function is included in the scope of the TLPT:
|
In Luxembourg, the TLPT authority under Article 26 of DORA is the CSSF, operating jointly with the BCL within the TIBER-LU framework. The TIBER-LU Implementation Document was revised on 20 June 2025 and details local expectations on the scope specification document content, in particular the link with the ICT third-party register (CSSF circulars 22/806 and 25/882). The methodology aligns with TIBER-EU as revised by the ECB on 11 February 2025.
Luxgap practice: we align your scope specification document with the 20 June 2025 TIBER-LU template and check consistency with your CSSF declaration before submission to the BCL test team.