The classic trap
This recital is not a bureaucratic formality. It reminds us that the TLPT RTS was born from the joint work of the three European Supervisory Authorities (EBA, EIOPA, ESMA), in agreement with the ECB. In practice, this means the RTS is locked onto the TIBER-EU methodology revised by the ECB on 11 February 2025. The trap: believing that the CSSF and the BCL have broad local interpretation leeway on TLPT. The CSSF, TLPT authority under Article 26 of DORA, applies the TIBER-LU framework (Implementation Document revised on 20 June 2025) which faithfully reproduces the European architecture. A financial entity that builds its test on a homemade methodology, not aligned with TIBER, will be denied recognition of compliance.
Why the ECB anchoring changes your implementation
The ECB agreement mentioned in this recital has a direct operational consequence: consistency between TLPT under DORA and the ECB's historical TIBER-EU framework. For a significant Luxembourg entity, this imposes several points of attention:
- Align the threat intelligence and red team scenarios with the Threat Intelligence-Based Ethical Red Teaming defined by the ECB, not with a classic pentest.
- Structure the teams according to the TIBER quadrature: internal white team, external qualified red team and threat intelligence provider, uninformed blue team.
- Target critical or important functions in live production, which requires risk governance validated upstream (CSSF circular 20/750).
- Include ICT providers in the test scope (subcontracting RTS 2025/532, CSSF circulars 22/806 and 25/882).
- Document remediation as a formal input into ICT risk management, enforceable before the CSSF and the BCL.
In other words, this recital tells you the legislator's intent is supervised convergence: your TLPT must be recognisable by the CSSF as an authentic TIBER-LU test, otherwise remediation does not count.
How Luxgap automates this risk
Our Luxgap TLPT Readiness Cockpit turns the European convergence intent into verifiable TIBER-LU alignment evidence before your red team even launches. The tool maps your critical functions in live production by cross-referencing your CMDB, Microsoft Defender, Azure Sentinel and your ICT provider register, then automatically measures the gap between your setup and the TIBER-EU requirements revised by the ECB.
- Detects critical or important functions eligible for TLPT by cross-referencing CMDB, Sentinel flows and application mapping, with no manual questionnaire.
- Verifies the effective separation of white team, red team, threat intelligence and blue team roles against the TIBER-LU grid of 20 June 2025.
- Automatically integrates the ICT providers in scope from your subcontracting register (RTS 2025/532, CSSF circulars 22/806 and 25/882).
- Generates the pre-test scoping file aligned with the ECB methodology, ready to submit to the TLPT Cyber Team of the BCL and CSSF.
- Tracks each remediation action and injects it as a timestamped entry into your ICT risk management (circular 20/750).
- Produces a timestamped PDF report demonstrating TIBER-LU alignment, enforceable during the CSSF and BCL supervisory dialogue.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real scope, with a free blank audit within 48h to measure your exposure before any commitment.