Recital 13
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
| (13) | There may be exceptional circumstances where financial entities are unable to contract TLPT providers that meet the comprehensive criteria. Financial entities, upon evidencing the unavailability of such threat intelligence providers, should therefore be allowed to engage persons who do not satisfy all comprehensive criteria, provided that they properly mitigate any resultant additional risks and that the TLPT authority assesses all those criteria. |
In Luxembourg, TLPT is operated through the TIBER-LU framework, jointly steered by the BCL and the CSSF, whose Implementation Document was revised on 20 June 2025. The Recital 13 exception must be validated by the Luxembourg TIBER Cyber Team, which concretely assesses the provider's criteria and mitigation measures before any test launch.
Luxgap practice: prepare the unavailability file and mitigation plan ahead of the TIBER-LU scoping meeting, as the TIBER Cyber Team will refuse a start until the criteria assessment is documented.