Article 6

Risk management for pooled or joint TLPTs

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

Risk management for pooled or joint TLPTs

1.   In the case of a joint TLPT or a pooled TLPT, the control team of each financial entity shall conduct its own risk assessment and establish its own risk management measures.

2.   The control team of the designated financial entity referred to in Article 16(3), point (b), of this Regulation, or the financial entity designated in accordance with Article 26(4) of Regulation (EU) 2022/2554, shall assess the risks relating to the involvement in the TLPT of multiple financial entities. The control teams of the involved financial entities shall cooperate with the control team of the designated financial entity to identify potential joint risks.

Luxembourg specificity
TIBER-LU Implementation Document (BCL / CSSF), version révisée du 20 juin 2025

In Luxembourg, the TLPT authority under article 26 of DORA is the CSSF, which runs the TIBER-LU framework jointly with the BCL. The TIBER-LU Implementation Document, revised on 20 June 2025, sets out the coordination arrangements for pooled and joint tests among significant financial entities established in Luxembourg, and requires designating a lead entity when several entities share a critical ICT provider.

Luxgap practice: identify the designated entity early and formalise in writing the split of roles between control teams before any contact with the BCL TIBER Cyber Team, otherwise scoping will stall.