The classic trap
Recital 15 looks harmless, but it sets the real cadence of a TLPT. In practice, the CSSF (TLPT authority under Article 46 of DORA) and the BCL, through the TIBER-LU framework, penalise entities that treat the white team and synchronisation points as mere paperwork. A significant financial entity that skips the scoping meeting, neglects the weekly updates or rushes the purple teaming during closure ends up with a non compliant test, hence one that is not recognised, and has to start over. The trap is not technical: it is the lack of traceability of the mandatory meetings required by TIBER-EU (revised on 11 February 2025) and mirrored in the TIBER-LU Implementation Document of 20 June 2025.
The meeting moments recital 15 makes unavoidable
This recital turns a good practice into a structuring regulatory expectation. Concretely, your testing governance must evidence meetings (in-person or virtual) at every milestone:
- Preparation phase: TLPT launch meeting to finalise the scope of critical functions in live production, with the white team and the BCL/CSSF TLPT cyber team.
- Testing phase: validation of the threat intelligence report and the red team test plan before any offensive action.
- Testing phase: documented weekly updates between red team, white team and authority.
- Closure phase: replay of red team and blue team actions, purple teaming session, and exchange of feedback on the TLPT.
- Each meeting must include the right stakeholders: entity, authorities, testers and threat intelligence providers (Articles 26-27 of DORA), plus the ICT providers included in the test scope (outsourcing RTS 2025/532, CSSF circulars 22/806 and 25/882).
The remediation stemming from closure must then feed your ICT risk management under CSSF circular 20/750: recital 15 therefore links the meeting ritual to an opposable remediation loop.
How Luxgap automates this risk
Our Luxgap TLPT Milestone Tracker makes it impossible to miss a mandatory meeting milestone and turns every synchronisation into evidence opposable to the CSSF and the BCL. The tool connects to your M365 (Outlook, Teams, SharePoint), reads the test calendar and reconciles each meeting held against the milestone sequence imposed by TIBER-LU, without asking the white team to keep a spreadsheet by hand.
- Automatically detects each milestone meeting in Outlook and Teams and maps it to the relevant TLPT phase (preparation, testing, closure).
- Alerts in real time via Teams if a weekly update is missing or if the red team test plan finalisation meeting is not scheduled before offensive actions begin.
- Verifies that each meeting brings together the required stakeholders (entity, BCL/CSSF TLPT cyber team, testers, threat intelligence provider, in-scope ICT providers).
- Generates timestamped minutes of the purple teaming and the red team / blue team replay, structured according to the TIBER-LU Implementation Document of 20 June 2025.
- Produces a sealed, timestamped PDF file, opposable during the authority review, demonstrating the proper conduct of the test under recital 15.
- Injects remediation items from closure into your ICT risk management register (CSSF circular 20/750).
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real test calendar, with a free blind audit within 48h to measure your exposure before any commitment.