Details of the report summarizing the relevant findings of the TLPT referred to in Article 26(6) of Regulation (EU) 2022/2554
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
The test summary report shall contain information on at least all of the following:
| (a) | the parties involved; |
| (b) | the project plan; |
| (c) | the validated scope, including the rationale behind the inclusion or exclusion of critical or important functions and identified ICT systems, processes, and technologies supporting the critical or important functions covered by the TLPT; |
| (d) | selected scenarios and any significant deviation from the targeted threat intelligence report; |
| (e) | executed attack paths, and used tactics, techniques and procedures; |
| (f) | captured and non-captured flags; |
| (g) | deviations from the red team test plan, if any; |
| (h) | blue team detections, if any; |
| (i) | purple teaming in testing phase, where conducted and the related conditions; |
| (j) | leg-ups used, if any; |
| (k) | risk management measures taken; |
| (l) | identified vulnerabilities and other findings, including their criticality; |
| (m) | root cause analysis of successful attacks; |
| (n) | high level plan for remediation, linking the vulnerabilities and other findings, their root causes and remediation priority; |
| (o) | lessons derived from feedback received. |
In Luxembourg, the TLPT is implemented through the TIBER-LU framework jointly run by the BCL and the CSSF, whose Implementation Document was revised on 20 June 2025. The Annex VII summary report must be presented to the Luxembourg TIBER Cyber Team, which checks its compliance before issuing the attestation, a condition for mutual recognition of the test under Article 26(6) of DORA.
Luxgap practice: we align each report section with the expectations of the TIBER-LU Implementation Document of 20 June 2025 and embed the covered TIC providers (CSSF circulars 22/806 and 25/882) directly into the validated scope of point (c).