Recital 3
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
| (3) | TLPT authorities should assess, in light of an overall assessment of the ICT risk profile and maturity, of the impact on the financial sector, and of related financial stability concerns, whether any type of financial entity other than credit institutions, payment institutions, electronic money institutions, central counterparties, central securities depositories, trading venues, insurance and reinsurance undertakings should be subject to TLPT. The assessment of whether such financial entities meet those qualitative criteria should aim at identifying financial entities for which TLPT is appropriate by using cross-sector and objective indicators. At the same time, the assessment of whether a financial entity meets those qualitative criteria should limit the entities subject to TLPT to those for which the testing is justified. Whether a financial entity meets those qualitative criteria should also be assessed in the light of new markets development and of the increasing importance of new market participants for the financial sector in the future, including crypto asset service providers authorised in accordance with Article 59 of Regulation (EU) 2023/1114 of the European Parliament and of the Council (2). |
In Luxembourg, the TLPT authority role is exercised by the CSSF in coordination with the BCL, through the TIBER-LU framework whose Implementation Document was revised on 20 June 2025. Designation of a financial entity under recital 3 is assessed in light of CSSF circulars 22/806 and 25/882 (ICT providers included in the test scope) and circular 20/750 (remediation feeds ICT risk management).
Luxgap practice: prepare your DORA register of information and critical function mapping now, as the CSSF may designate you on qualitative criteria even outside the nominative list, particularly if you are a MiCA-authorised crypto asset provider.