Recital 17

Recital 17

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

(17)

The financial entity should select the critical or important functions that will be in scope of the TLPT. When selecting those functions, the financial entity should base itself on various criteria relating to the importance of each function for the financial entity itself and for the financial sector, at Union and at national level, not only in economic terms but also considering the symbolic or political status of the function. To facilitate a smooth transition to the phase of threat intelligence gathering, the control team should provide the testers and threat intelligence provider that are not involved in the scoping process with detailed information on the agreed scoping.

Luxembourg specificity
TIBER-LU Implementation Document (BCL/CSSF), revise le 20 juin 2025

In Luxembourg, the designated TLPT authority under Article 26 of DORA is the CSSF, which runs the TIBER-LU framework jointly with the BCL. The TIBER-LU Implementation Document revised on 20 June 2025 sets out the scope validation arrangements and the interplay with CSSF circulars 22/806 and 25/882 on ICT subcontracting, which broaden the potential scope of the test to critical providers.

Luxgap practice: have your multi-criteria scoping matrix validated by the control team before any exchange with the CSSF, and document the inclusion of critical ICT providers to avoid a scope rejection.