Recital 4
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
| (4) | Financial entities may have the same ICT intra-group service provider or may belong to the same group and rely on the use of shared ICT systems. In that case, it is important that TLPT authorities consider the structure and systemic character or importance for the financial sector of that financial entity at national or Union level in the assessment of whether a financial entity should be subject to TLPT and of whether the TLPT should be conducted at entity level or at group level (through a joint TLPT). |
In Luxembourg, the TLPT authority within the meaning of article 46 of DORA is the CSSF, operating jointly with the BCL under the TIBER-LU framework. The TIBER-LU Implementation Document revised on 20 June 2025 sets out the national test governance, including the arbitration between entity-level TLPT and joint TLPT for groups sharing ICT systems.
Luxgap practice: document the systemic character and shared dependency analysis in the TIBER-LU scoping file from the outset, as this is the argument the CSSF and BCL challenge first.