The classic trap
Recital 6 aligns the TLPT cyber teams of authorities (in Luxembourg, the CSSF together with the BCL under the TIBER-LU framework) on the TIBER-EU model. The trap for financial entities is real: CSSF-regulated significant entities assume the authority test manager is a passive observer, when in fact they validate scope, threat intelligence and the test plan. What the CSSF penalises in practice is the entity that runs its TLPT without documenting every interaction with this single point of contact, making it impossible to prove that the test followed the methodology of Article 26 of DORA and the TIBER-LU Implementation Document revised on 20 June 2025.
What this recital changes concretely for your test governance
A recital is not normative, but it clarifies intent: the legislator wants a single authority gateway that capitalises on lessons learned. For the tested entity, this imposes bilateral traceability discipline.
- Name your CSSF/BCL test manager and log every exchange (scope, TI, remediation) as evidence usable in a supervisory review.
- Align your internal white team with the single point of contact role: one voice on the entity side, one voice on the authority side.
- Integrate the lessons learned from previous tests that the authority team is meant to collect, and document how they feed your ICT risk management under CSSF circular 20/750.
- Verify that your ICT providers within scope (RTS 2025/532, CSSF circulars 22/806 and 25/882) contractually accept this centralised communication.
- Link the remediation phase to Articles 26-27 of DORA to evidence the expected improvement loop.
How Luxgap automates this risk
Our Luxgap TLPT Liaison Logbook turns the relationship with the CSSF/BCL cyber team into a timestamped, admissible journal, making the traceability gap that sinks a TLPT under review impossible. The tool automatically aggregates exchanges from Microsoft 365 (Outlook, Teams), your GRC and your Jira/ServiceNow tickets to reconstruct, with no manual entry, the full chronology across test manager, white team, red team and threat intelligence.
- Detects and timestamps every test-related communication between your white team and the authority single point of contact, straight from Teams and Outlook.
- Structures the file along TIBER-LU phases (preparation, TI, red teaming, closure, remediation) aligned with the 20 June 2025 Implementation Document.
- Maps the ICT providers within scope and verifies the centralised communication clause required by RTS 2025/532 and circulars 22/806 and 25/882.
- Capitalises lessons learned from one test to the next and links them to entries in your ICT risk register (circular 20/750).
- Generates a timestamped, cryptographically sealed PDF report demonstrating to the CSSF compliance with the methodology of Articles 26-27 of DORA.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real perimeter, with a free blank audit within 48h to measure your exposure before any engagement.