The classic trap
Article 4 of the TLPT RTS is a governance trap, not a technical one. The CSSF, as TLPT authority under Article 26 of DORA, sanctions entities that launch a threat-led test without formalising the control team or naming its lead. In practice, what fails is the loss of secrecy: a TLPT known to too many people is no longer realistic, and both the BCL and the CSSF, under the TIBER-LU framework (Implementation Document revised on 20 June 2025), consider that a leak of the scope or code name invalidates the test and forces a replay. The second classic trap is the absence of a containment procedure: when the blue team detects the red team and triggers a real incident response, no one is authorised to contain the escalation.
The organisational measures the CSSF will ask you to prove
- A named control team lead responsible for the day-to-day management of the TLPT and for all decisions of the team (Art. 4.1).
- Scope access strictly limited on a need-to-know basis: control team, management body, testers, threat intelligence provider and TLPT authority only (Art. 4.2.a).
- A documented consultation of the TIBER-LU test managers before involving any blue team member (Art. 4.2.b).
- A containment procedure: the control team is informed of any detection and can contain the incident response escalation (Art. 4.2.c).
- Secrecy undertakings signed by internal staff, the relevant ICT third-party service providers (CSSF circulars 22/806 and 25/882), the testers and the threat intelligence provider (Art. 4.2.d).
- Systematic use of the code name in all communication linked to the test (Art. 4.2.f).
The challenge is not drafting these rules but proving they were respected continuously over the weeks of the test, while ICT providers are in scope and outsourcing arrangements (RTS 2025/532) must already provide for participation in tests.
How Luxgap automates this risk
Our Luxgap TLPT Secrecy Warden makes a silent scope leak impossible by turning the secrecy obligations of Article 4 into a timestamped evidence log, enforceable before the CSSF and the BCL. The tool integrates with your Active Directory, Microsoft Defender, Azure Sentinel and your ITSM to map in real time who holds information about the TLPT, and alerts the control team as soon as access falls outside the validated need-to-know circle.
- Generates and electronically collects the secrecy undertakings of internal staff, ICT third-party providers (circulars 22/806 and 25/882), testers and the threat intelligence provider, with full traceability.
- Detects in real time via Defender and Sentinel any incident response triggered by the blue team on the test scope, and instantly notifies the control team lead to decide on containment (Art. 4.2.c).
- Locks the register of authorised individuals and raises a Teams alert whenever an account outside need-to-know accesses a test-related resource.
- Automatically substitutes the code name for the real project name in ITSM tickets and logs any mention of the real name as a secrecy incident (Art. 4.2.f).
- Traces every consultation of the TIBER-LU test managers before a blue team member is involved, with enforceable timestamps (Art. 4.2.b).
- Produces a cryptographically sealed PDF report demonstrating continuous compliance with Article 4, ready for the TLPT closure file submitted to the CSSF and feeding ICT risk management (circular 20/750).
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real scope, with a free blind audit within 48h to measure your exposure before any commitment.