TLPT phases: preparation, threat intelligence, red teaming, closure
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
RTS 2025/1190 imposes a phased methodology aligned with TIBER-EU:
- Preparation phase: scoping, scope validation by the authority, team designation, exercise risk management.
- Threat intelligence and red teaming phase: the TI provider produces credible attack scenarios, then the red team executes attacks on real production systems over an extended period (often 10 to 12 weeks).
- Closure and remediation phase: debrief, detailed report, remediation plan, and test recognition by the authority.
Each phase produces specific deliverables (test plan, threat intelligence report, red team report, summary report) whose minimum content is defined by the RTS.
In Luxembourg, the TLPT authority designated under DORA Article 26(9) is the CSSF, acting jointly with the BCL under the TIBER-LU framework. The TIBER-LU Implementation Document revised on 20 June 2025 sets out local expectations: a joint CSSF / BCL TIBER Cyber Team (TCT) validates each phase, and test recognition takes the form of a co-signed attestation. ICT providers in scope under CSSF circulars 22/806 and 25/882 must be included in the test perimeter as soon as they support a critical function being tested.
Luxgap practice: from the scoping phase, we align our TLPT Orchestrator with the Luxembourg TCT calendar and with the ICT provider register declared to the CSSF, to avoid any gap between the tested scope and the actually supervised perimeter.