The classic trap
This recital is misread in both directions. Some financial entities assume that meeting the quantitative thresholds automatically exempts them, when in fact the CSSF (TLPT authority under Article 46 of DORA) and the BCL retain a qualitative margin of appreciation. Others assume they are out of scope because their activity is modest, without documenting the overall assessment of their ICT risk profile. In both cases the entity keeps no opposable record of the scoping decision and cannot justify, during a dialogue with the CSSF, why it is or is not subject to TLPT.
Recital 2: a qualitative exemption, not a vested right
The legislator makes clear that inclusion in TLPT scope is not purely mechanical. Even a credit or payment institution that ticks the quantitative criteria may be released in light of an overall assessment. In practice this requires building a robust scoping file that feeds the dialogue with the Luxembourg TLPT authority (BCL and CSSF within the TIBER-LU framework, whose Implementation Document was revised on 20 June 2025).
- Document real ICT maturity: governance, ICT risk management under CSSF circular 20/750, results of prior tests.
- Map the systemic impact of your critical or important functions on the Luxembourg financial sector.
- Include ICT third-party providers in scope, in line with the outsourcing RTS 2025/532 and CSSF circulars 22/806 and 25/882.
- Keep the justification for each inclusion or exclusion decision, timestamped, to make it opposable during a review.
- Align the methodology with TIBER-EU (revised by the ECB on 11 February 2025) and its TIBER-LU implementation.
The recital sheds light on Articles 26 and 27 of DORA: entity selection is never a simple checkbox, it is a reasoned decision you must be able to defend.
How Luxgap automates this risk
Our Luxgap TLPT Scoping Advisor turns the fuzzy question are you subject to TLPT into a reasoned scoping file opposable to the CSSF. A specialised AI agent cross-references your ICT governance data, your critical function registers and your provider contracts (Odoo, Microsoft Defender, Azure Sentinel, eBRC, LuxConnect) to rebuild your risk profile within the meaning of recital 2, without a tedious questionnaire.
- Evaluates your DORA quantitative criteria and confronts the result with the qualitative overall assessment expected by the BCL and the CSSF.
- Rebuilds the mapping of your critical or important functions from the DORA register of information and your real flows.
- Automatically includes ICT providers in the potential test scope, consistent with RTS 2025/532 and CSSF circulars 22/806 and 25/882.
- Calculates an ICT maturity score aligned with circular 20/750 and the TIBER-LU methodology of 20 June 2025.
- Generates a timestamped PDF report, a scoping argument ready for dialogue with the Luxembourg TLPT authority.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your perimeter. Request a tailored quote and our teams will prepare a demonstration on your real perimeter, with a free blind audit within 48h to measure your exposure before any commitment.