Annex VIII

Details of the attestation of the TLPT referred to in Article 26(7) of Regulation (EU) 2022/2554

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

The attestation shall contain at least all of the following information:

(a)

on the performed TLPT:

(i)

the starting and end dates of the TLPT;

(ii)

the critical or important functions in scope of the test;

(iii)

where relevant, information on critical or important functions in scope of the test in relation to which the TLPT was not performed;

(iv)

where relevant, other financial entities that were involved in the TLPT;

(v)

where relevant, the ICT third-party services providers that participated in the TLPT;

(vi)

in respect of testers:

1.

whether internal testers were used;

2.

whether Article 5(3), second subparagraph, was used by the financial entity;

(vii)

the duration, in calendar days, of the active red team testing phase;

(b)

where several TLPT authorities have been involved in the TLPT, the other TLPT authorities, and in which capacity;

(c)

list of the documents examined by the TLPT authority for the purposes of the attestation.

Luxembourg specificity
TIBER-LU Implementation Document (BCL/CSSF), version revisee du 20 juin 2025

In Luxembourg, TLPT is implemented through the TIBER-LU framework, jointly run by the BCL and the CSSF, whose Implementation Document was revised on 20 June 2025 and aligned with TIBER-EU (ECB revision of 11 February 2025). The attestation must reflect TIBER-LU governance (role of the white team, of the BCL/CSSF test manager) and the minimum active red team phase duration set by that framework.

Luxgap practice: we align your attestation dossier with the latest TIBER-LU Implementation Document and check consistency with CSSF circulars 22/806, 25/882 and 20/750 before any submission to the TLPT authority.