The classic trap
This recital sheds light on an often underestimated requirement: the quality and independence of the test manager team steering your TLPT. In practice, the CSSF, as TLPT authority under Article 46 of DORA, and the BCL through the TIBER-LU framework expect at least two qualified test managers per exercise, able to technically challenge the proposals of the red team and the threat intelligence provider. Financial entities that treat the TLPT as a mere external service without a solid internal control room end up with a poorly scoped test, a contested perimeter, and a remediation that fails to properly feed the ICT risk management required by CSSF circular 20/750.
The legislator's intent: duality and separation of supervision and testing
Recital 7 sets out two non-normative but structuring principles for interpreting the RTS articles:
- The duality of test managers (at least two people) to secure judgement, continuity and the ability to challenge testers, in line with the TIBER-EU methodology revised by the ECB on 11 February 2025.
- The functional separation between prudential supervision and test steering: for the duration of the TLPT, managers should not carry out supervisory activities on the same entity, to safeguard confidentiality and the learning spirit.
- The effective competence requirement: advising and challenging implies real technical expertise, not a mere administrative follow-up role.
- The link with the perimeter: critical functions in live production and the ICT providers included (CSSF circulars 22/806 and 25/882, outsourcing RTS 2025/532) must be covered by a disciplined and well-managed white team.
Concretely, even if a recital is not binding, the CSSF will rely on it to assess the credibility of your test governance. Document your white team composition, the dual assignment of managers, the role separation matrix and the traceability of scoping decisions.
How Luxgap automates this risk
Our Luxgap TLPT Control Room turns the governance of your threat-led test into a continuous, structured evidence file opposable to the CSSF and the BCL. The tool orchestrates the white team, materialises the duality of test managers and their separation from supervision, and centralises every scoping decision, every challenge issued to the red team and every remediation milestone, connecting to your M365, Azure Sentinel, Microsoft Defender environments and to your ICT provider register.
- Generates a role separation matrix that verifies your two test managers do not combine supervisory activities on the tested entity for the duration of the exercise, aligned with recital 7 and the TIBER-LU Implementation Document of 20 June 2025.
- Traces every challenge and validation issued to testers and the threat intelligence provider, timestamped, to demonstrate the white team's effective ability to challenge proposals.
- Maps the real test perimeter by cross-referencing your critical functions and declared ICT providers (CSSF circulars 22/806 and 25/882, RTS 2025/532) to avoid any scoping blind spot.
- Drives the remediation plan and automatically feeds your ICT risk register in line with CSSF circular 20/750.
- Produces a timestamped, sealed PDF report, opposable during an exchange with the CSSF or the BCL, demonstrating the compliance of your test governance with Articles 26 and 27 of DORA and its RTS.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your perimeter. Request a personalised quote and our teams will prepare a demonstration on your real perimeter, with a free blank audit within 48h to measure your TLPT maturity before any engagement.