Article T.5

TLPT phases: preparation, threat intelligence, red teaming, closure

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

RTS 2025/1190 imposes a phased methodology aligned with TIBER-EU:

  1. Preparation phase: scoping, scope validation by the authority, team designation, exercise risk management.
  2. Threat intelligence and red teaming phase: the TI provider produces credible attack scenarios, then the red team executes attacks on real production systems over an extended period (often 10 to 12 weeks).
  3. Closure and remediation phase: debrief, detailed report, remediation plan, and test recognition by the authority.

Each phase produces specific deliverables (test plan, threat intelligence report, red team report, summary report) whose minimum content is defined by the RTS.

Luxembourg specificity
TIBER-LU Implementation Document revise le 20 juin 2025 (CSSF + BCL)

In Luxembourg, the TLPT authority designated under DORA Article 26(9) is the CSSF, acting jointly with the BCL under the TIBER-LU framework. The TIBER-LU Implementation Document revised on 20 June 2025 sets out local expectations: a joint CSSF / BCL TIBER Cyber Team (TCT) validates each phase, and test recognition takes the form of a co-signed attestation. ICT providers in scope under CSSF circulars 22/806 and 25/882 must be included in the test perimeter as soon as they support a critical function being tested.

Luxgap practice: from the scoping phase, we align our TLPT Orchestrator with the Luxembourg TCT calendar and with the ICT provider register declared to the CSSF, to avoid any gap between the tested scope and the actually supervised perimeter.