Recital 29
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
| (29) | The European Supervisory Authorities have conducted open public consultations on the draft regulatory technical standards on which this Regulation is based, analysed the potential related costs and benefits and requested the advice of the Banking Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1093/2010 of the European Parliament and of the Council (3), the Insurance and Reinsurance Stakeholder Group and the Occupational Pensions Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1094/2010 of the European Parliament and of the Council (4), and the Securities and Markets Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1095/2010 of the European Parliament and of the Council (5). |
In Luxembourg, the TLPT authority within the meaning of Article 26 of DORA is the CSSF, operating jointly with the BCL under the TIBER-LU framework. The TIBER-LU Implementation Document was revised on 20 June 2025 and specifies the role of the local Test Cyber Team (white team) as well as the threat intelligence requirements specific to the Luxembourg financial centre.
Luxgap practice: validate your scoping note with the CSSF and the BCL before launch, relying on the 20 June 2025 version of the TIBER-LU framework to avoid any re-scoping during the test.