The classic trap
Article 7 sets quantified, non-negotiable selection criteria for your TLPT providers (threat intelligence and external testers). The trap: Luxembourg financial entities pick a red team on reputation or price, without documenting the references (at least three for threat intelligence, at least five for testers), the seniority of managers (minimum five years), the professional indemnity insurances and above all the strict separation between red team and threat intelligence provider. The CSSF, TLPT authority under Article 26 of DORA and joint operator of the TIBER-LU framework with the BCL, requires documentary evidence (Article 7(2)). Without an opposable selection file, the control team cannot validate the provider and the entire test may be invalidated.
The control points the CSSF checks on your provider file
- Detailed CVs and market-recognised certifications for each external tester and threat intelligence analyst (Article 7(1)(a)).
- Professional indemnity insurance certificate covering misconduct and negligence (Article 7(1)(b)).
- At least three references for the threat intelligence provider, at least five for the testers, from penetration testing and red team assignments (7(1)(c) and (d)).
- Compliant team composition: a manager with five years' experience, additional members with two years, combined participation in three (TI) or five (red team) previous assignments (7(1)(e) and (f)).
- No conflict of interest: the tester cannot perform blue team tasks nor report to the staff providing threat intelligence for the same TLPT.
- Documented post-test restoration procedures: secure deletion of compromised credentials, kill switches, backdoor removal, potential breach notification (7(1)(g) and (h)).
The ICT third-party service provider falls within the test scope under CSSF circulars 22/806 and 25/882 and the outsourcing RTS 2025/532. Exceptional derogations from criteria 7(1)(a) to (f) must be justified by appropriate mitigation measures, which must themselves be documented.
How Luxgap automates this risk
Our Luxgap TLPT Provider Vetting turns the selection of your TLPT providers into a compliance file opposable to the CSSF, article by article. The tool ingests the CVs, certifications, insurance certificates and reference lists supplied by the threat intelligence provider and the red team, then a specialised LLM agent maps them automatically against each quantified criterion of Article 7, without your control team filling in a single manual grid.
- Automatically extracts and verifies the seniority of managers (five years) and members (two years) from the supplied CVs, flagging any team below the Article 7(1)(e) and (f) threshold.
- Counts and validates the minimum references (three for threat intelligence, five for testers) and alerts as soon as a file is incomplete.
- Detects conflicts of interest and red team / threat intelligence separation breaches by cross-checking the declared org charts and assignments.
- Checks the validity and scope of professional indemnity insurances, including misconduct and negligence coverage.
- Generates the post-test restoration checklist (kill switches, credential deletion, backdoor removal) aligned with TIBER-LU and RTS 2025/1190.
- Produces a timestamped PDF report opposable to the CSSF and the BCL, evidencing compliance with points (a) to (f) and documenting any exceptional derogation under Article 7(2).
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams prepare a demonstration on your real provider file, with a free blind audit within 48h to measure your exposure before any commitment.