Recital 28

Recital 28

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

(28)

This Regulation is based on the draft regulatory technical standards submitted to the Commission by the European Banking Authority, the European Insurance and Occupational Pensions Authority, the European Securities and Markets Authority (European Supervisory Authorities), in agreement with the European Central Bank.

Luxembourg specificity
TIBER-LU Implementation Document (BCL et CSSF), revise le 20 juin 2025

In Luxembourg, the TLPT authority under Article 26 of DORA is the CSSF, which runs the TIBER-LU framework jointly with the BCL. The TIBER-LU Implementation Document was revised on 20 June 2025 to align with the ECB version of 11 February 2025 referred to in this recital. The national TLPT Cyber Team validates the scoping, the choice of red team and threat intelligence providers, and the closure of remediation.

Luxgap practice: open the scoping dialogue with the CSSF/BCL TLPT Cyber Team as soon as your critical functions are designated, and have your threat intelligence provider validated before any contractual commitment.