Article T.3

Internal and external testers: conditions and independence

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

The RTS sets strict requirements on testers (red team) and the threat intelligence provider: certified skills, demonstrated experience, liability insurance, absence of conflicts of interest.

External testers are the norm. Using internal testers is only possible under reinforced conditions: the TLPT authority must authorise it, the entity must demonstrate the internal team's independence from the tested functions, and the threat intelligence provider must remain external. An internal tester cannot be used for two consecutive TLPTs.

Luxembourg specificity
TIBER-LU Implementation Document revise le 20 juin 2025 (BCL et CSSF)

In Luxembourg, the CSSF is the designated TLPT authority under Article 46 of DORA and co-pilots the TIBER-LU framework with the BCL. The Implementation Document revised on 20 June 2025 requires the red team eligibility file to be jointly validated by the CSSF and the BCL before the reconnaissance phase starts, and mandates that the entity's White Team Lead be named in the engagement letter with the testers.

Luxgap practice: we file the tester eligibility dossier simultaneously with CSSF and BCL via the official TIBER-LU channel, and we formalise the White Team / Red Team / Threat Intelligence Provider engagement letter as a single tripartite enforceable instrument.