Recital 25

Recital 25

Digital Operational Resilience Act · UE 2022/2554

(25)

Digital operational resilience testing requirements have been developed in certain financial subsectors setting out frameworks that are not always fully aligned. This leads to a potential duplication of costs for cross-border financial entities and makes the mutual recognition of the results of digital operational resilience testing complex which, in turn, can fragment the internal market.

Luxembourg specificity
loi luxembourgeoise du 1er juin 2023 portant mise en oeuvre du reglement DORA et circulaire CSSF 24/847

In Luxembourg, the CSSF is the competent authority to supervise digital operational resilience tests for financial entities, including TLPT (Threat-Led Penetration Testing). The law of 1 June 2023 implementing the DORA regulation and CSSF circular 24/847 specify that tests performed under the TIBER-LU framework (Luxembourg transposition of TIBER-EU led by the BCL) are automatically recognised as meeting DORA article 26 requirements, avoiding duplication for systemic banks.

Luxgap practice: if your entity has already performed a TIBER-LU exercise in the last three years, we reuse it as the DORA baseline without redoing the test, and only fill the documentation gaps required by the CSSF.