The classic trap
Recital 26 exposes a reality many financial entities underestimate: TLPT is not a closed technical exercise between red team and blue team, it is a supervisory act. What the CSSF (TLPT authority under Article 46 of DORA) and the BCL scrutinise in practice is the summary report that is unreadable for a supervisor, or the remediation plan disconnected from the ICT risk management required by CSSF circular 20/750. The recital imposes an interpretive consistency: your TIBER-LU test managers and the supervisors must read the same findings the same way. A report the CSSF cannot understand is a report that triggers questions, not closure.
Turning the legislator's intent into defensible deliverables
Recital 26 is not normative, but it directly informs the RTS articles on the test summary report and the remediation plan. In practice, it forces you to produce deliverables intelligible to three distinct audiences: the red team, your management, and the supervisor (CSSF plus BCL). Key practical points:
- Align your summary report structure with the TIBER-LU Implementation Document revised on 20 June 2025, not a generic red team template.
- Trace each finding to a dated, owned remediation action integrated into the ICT risk register (circular 20/750).
- Include ICT providers in the tested scope, in line with the outsourcing RTS 2025/532 and CSSF circulars 22/806 and 25/882.
- Document the coordination between test managers and supervisors from the scoping phase, not only at closure.
- Link each scenario to the critical functions tested in live production, so the supervisor can measure business impact.
How Luxgap automates this risk
Our Luxgap TLPT Findings Translator turns a raw red team report into a supervision-ready dossier that is defensible before the CSSF, without your test managers spending weeks reformatting. A specialised AI agent reads the technical deliverables (Purple Team reports, Defender exports, Sentinel, CrowdStrike, Jira remediation tickets) and automatically restructures them along the TIBER-LU grid of 20 June 2025, producing the two required views: the supervisor's and management's.
- Automatically generates the TLPT summary report aligned with the TIBER-LU Implementation Document, with traceability from each finding to its critical function.
- Classifies each finding by severity and links it to a dated remediation action, feeding directly into your ICT risk register under circular 20/750.
- Detects ICT providers in the tested scope and checks their contractual coverage against RTS 2025/532 and circulars 22/806 and 25/882.
- Produces a remediation plan structured for the joint CSSF and BCL review, with tracking indicators.
- Generates a timestamped PDF dossier, defensible during the prudential dialogue, evidencing the cooperation between test managers and supervisors required by recital 26.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams prepare a demonstration on your real deliverables, with a free blank audit within 48h to measure the readability of your reporting before any engagement.