Recital 15

Recital 15

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

(15)

As evidenced by the experience of the implementation of the TIBER-EU framework, holding in-person or virtual meetings including all stakeholders concerned (financial entities, authorities, testers and threat intelligence providers) is the most efficient way to ensure the appropriate conduct of the testing. In-person and virtual meetings should therefore be held at various steps of the process, and in particular during the preparation phase at the launch of the TLPT and to finalise on its scope, during the testing phase, to finalise the threat intelligence report and the red team test plan and for the weekly updates, and during the closure phase for replaying testers and blue team actions, purple teaming and to exchange feedback on the TLPT.

Luxembourg specificity
Implementation Document TIBER-LU (BCL/CSSF), version revisee du 20 juin 2025

In Luxembourg, the TLPT authority is the CSSF, which runs the TIBER-LU framework jointly with the BCL. The TIBER-LU Implementation Document revised on 20 June 2025 details the expected meeting milestones and the role of the national TLPT cyber team, consistent with recital 15 of the RTS.

Luxgap practice: from the TLPT launch, agree a meeting calendar with the TIBER-LU team (CSSF/BCL) and keep every timestamped minute, as the traceability of these synchronisations conditions the recognition of the test.