Remediation plan
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
Remediation plan
1. Within 8 weeks from the notification referred to in Article 12(7) of this Regulation, the financial entity shall provide the remediation plans and the documentation referred to in Article 26(6) of Regulation (EU) 2022/2554 to the TLPT authority and, where different, to the financial entity’s competent authority.
2. The remediation plan referred in paragraph 1 shall include, for each finding occurred in the framework of the TLPT:
| (a) | a description of the identified shortcomings; |
| (b) | a description of the proposed remediation measures and of their prioritisation and expected completion, including, where relevant, measures to improve the identification, protection, detection and response capabilities; |
| (c) | a root cause analysis; |
| (d) | the financial entity’s staff or functions responsible for the implementation of the proposed remediation measures or improvements; |
| (e) | the risks associated to not implementing the measures referred to in point (b) and, where relevant, risks associated to the implementation of such measures. |
In Luxembourg, the TLPT authority under Article 26 of DORA is the CSSF, which runs the TIBER-LU framework jointly with the BCL. The TIBER-LU Implementation Document, revised on 20 June 2025, sets out how the remediation plan is submitted and reviewed, and remediation feeds the ICT risk management expected under CSSF circular 20/750. ICT providers within the test scope fall under circulars 22/806 and 25/882 and the subcontracting RTS 2025/532.
Luxgap practice: anchor the start of your 8 week deadline on the formal Article 12(7) notification and submit one consolidated plan to the CSSF, clearly flagging measures that depend on an ICT provider to avoid rejection for incomplete scope.