Mutual recognition and cross-border pooled testing
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
For cross-border groups, the RTS provides for mutual recognition of a TLPT between authorities: a test conducted under another Member State's TLPT authority can be recognised, avoiding duplication of exercises.
The RTS also frames pooled TLPT: several entities of the same group or sharing ICT systems can conduct a joint TLPT, and joint tests involving a critical ICT third-party provider common to several financial entities. Cooperation between the CSSF and other European authorities (and the BCL) is central to these arrangements.
In Luxembourg, mutual recognition is conditional on the TIBER-LU Implementation Document revised on 20 June 2025, co-signed by BCL and CSSF. Concretely, even a TLPT conducted under TIBER-DE or TIBER-FR must be subject to prior joint notification to the CSSF and the BCL, with explicit inclusion of critical functions operated from Luxembourg in the scope. The CSSF reserves the right to impose additional controls if the group scope does not sufficiently cover the specificities of the financial centre (UCITS funds, depositaries, support PFS).
Luxgap practice: never launch a group pooled TLPT without first obtaining written CSSF/BCL confirmation of eligibility for recognition, based on the LU-annotated scoping document.