Recital 26

Recital 26

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

(26)

The competent authorities referred to in Article 46 of Regulation (EU) 2022/2554 and TLPT authorities, where different, should cooperate to incorporate advanced testing by means of TLPT into the existing supervisory processes. In that respect and to share the correct understanding of the TLPT findings and of how they should be interpreted, it is appropriate that, in particular for the test summary report and remediation plans, a close cooperation between test managers who were involved in the TLPT and the responsible supervisors is established.

Luxembourg specificity
TIBER-LU Implementation Document (BCL et CSSF), revise le 20 juin 2025

In Luxembourg, TLPT is run through the TIBER-LU framework, jointly overseen by the BCL and the CSSF, whose Implementation Document was revised on 20 June 2025. The cooperation between test managers and supervisors set out in recital 26 materialises within this two-authority national governance, with the CSSF acting as TLPT authority under Article 46 of DORA.

Luxgap practice: align your test schedule and deliverables with the 20 June 2025 version of the TIBER-LU Implementation Document, and involve the national TIBER Cyber Team from the scoping phase to avoid any interpretive misalignment at closure.