Identification of financial entities required to perform TLPT
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
Identification of financial entities required to perform TLPT
1. TLPT authorities shall assess whether any financial entity is required to perform TLPT, taking into account the impact of those financial entities, their systemic character and their ICT risk profile, on the basis of all of the following criteria:
| (a) | impact-related and systemic character related factors:
|
| (b) | ICT risk-related factors:
|
For the purposes of point (a)(i), the TLPT authority shall, where possible, consider:
| (a) | the market share position of the financial entity at Union and national level; |
| (b) | the range of activities offered by the financial entity; |
| (c) | the market share of the services provided by the financial entity or of the activities undertaken at Union and national level. |
For the purposes of point (a)(v), the TLPT authority shall, where possible, consider:
| (a) | whether the financial entity operates more than one business model; |
| (b) | the interconnectedness of different business processes and the related services. |
2. TLPT authorities shall require all of the following financial entities to perform TLPT, unless the assessment referred to in paragraph 1 in respect of a financial entity indicates that its impact, the financial stability concerns relating to that financial entity, or its ICT risk profile, does not justify the performance of a TLPT:
| (a) | credit institutions that meet any of the following conditions:
|
| (b) | payment institutions that exceeded in each of the 2 calendar years preceding the assessment by the TLPT authority EUR 150 billion of total value of payment transactions as defined in Article 4, point (5), of Directive (EU) 2015/2366 of the European Parliament and of the Council (8); |
| (c) | electronic money institutions that exceeded in each of the 2 calendar years preceding the assessment by the TLPT authority either EUR 150 billion of total value of payment transactions as defined in Article 4, point (5), of Directive (EU) 2015/2366 or EUR 40 billion of total value of the amount of outstanding electronic money; |
| (d) | central securities depositories; |
| (e) | central counterparties; |
| (f) | trading venues with an electronic trading system that meet any of the following criteria:
|
| (g) | insurance and reinsurance undertakings that meet all the following criteria:
|
For the purposes of (f)(ii), where the trading venue is part of a group sharing ICT systems or the same ICT intra-group service provider, the turnover of the securities and derivatives contracts on all trading venues pertaining to the same group and established in the Union shall be considered.
For the purposes of point (g), TLPT authorities shall identify a subset of all insurance and reinsurance undertakings by applying the criteria laid down in points (g)(i), (ii), and (iii). Insurance and reinsurance undertakings included in that subset shall be required to perform TLPT where they also meet any of the following criteria:
| (a) | gross written premium (GWP) that exceeds EUR 3 000 000 000; |
| (b) | technical provisions that exceed EUR 30 000 000 000; |
| (c) | total assets that exceed 10 % of the sum of the total assets valuated in accordance with Article 75 of Directive 2009/138/EC of the insurance and reinsurance undertakings established in the Member State. |
3. Where more than one financial entity belonging to the same group and sharing ICT systems, or where more than one financial entity using the same ICT intra-group service provider, meet the criteria set out in paragraph 2, the TLPT authorities of those financial entities shall, in accordance with Article 16(2), decide whether the requirement to perform TLPT on an individual basis is relevant for those financial entities.
Where the TLPT authority of the parent undertaking of a group of financial entities referred to in the first subparagraph is different from the TLPT authorities of the financial entities of the group, that authority shall be consulted by the TLPT authorities of the financial entities belonging to that group on whether it is appropriate to perform TLPT on an individual basis.
In Luxembourg, the competent TLPT authority is the CSSF, which runs the TIBER-LU framework jointly with the BCL. The TIBER-LU Implementation Document, revised on 20 June 2025 and aligned with TIBER-EU (ECB version of 11 February 2025), sets out the arrangements for designation, scoping and conduct of the test (red team, blue team, white team, threat intelligence) on critical functions in live production. Remediation from the test feeds ICT risk management under CSSF circular 20/750, while the inclusion of ICT providers in scope relies on CSSF circulars 22/806 and 25/882.
Luxgap practice: anticipate the Article 2 assessment by building your self-assessment file aligned with the TIBER-LU Implementation Document now, so you engage the CSSF and the BCL from a documented position rather than a reactive one.