Recital 6

Recital 6

Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190

(6)

To ensure that the TLPT benefits from the experience developed in the framework of TIBER-EU implementation and to reduce the risks associated to the performance of TLPT, it should be ensured that the responsibilities of the TLPT cyber teams to be set up at the level of TLPT authorities match as closely as possible those of the TIBER-EU cyber teams. Hence, the TLPT cyber teams should have test managers that are responsible for overseeing individual TLPTs and for planning and coordinating individual tests. TLPT cyber teams should serve as a single point of contact for test-related communication to internal and external stakeholders, for collecting and processing feedback and lessons learned from previously conducted tests, and for supporting financial entities undergoing TLPT testing.

Luxembourg specificity
Cadre TIBER-LU (BCL et CSSF), Implementation Document revise le 20 juin 2025

In Luxembourg, the TLPT authority within the meaning of Article 26 of DORA is the CSSF, operating jointly with the BCL under the TIBER-LU framework. The TLPT cyber team and its test manager referred to in recital 6 are concretely defined in the TIBER-LU Implementation Document revised on 20 June 2025, which specifies the single point of contact role and the link to remediation feeding ICT risk management (CSSF circular 20/750).

Luxgap practice: identify your single CSSF/BCL contact from the scoping phase and log every exchange in line with TIBER-LU to hold admissible evidence in case of review.