Recital 25
Digital Operational Resilience Act · UE 2022/2554
| (25) | Digital operational resilience testing requirements have been developed in certain financial subsectors setting out frameworks that are not always fully aligned. This leads to a potential duplication of costs for cross-border financial entities and makes the mutual recognition of the results of digital operational resilience testing complex which, in turn, can fragment the internal market. |
In Luxembourg, the CSSF is the competent authority to supervise digital operational resilience tests for financial entities, including TLPT (Threat-Led Penetration Testing). The law of 1 June 2023 implementing the DORA regulation and CSSF circular 24/847 specify that tests performed under the TIBER-LU framework (Luxembourg transposition of TIBER-EU led by the BCL) are automatically recognised as meeting DORA article 26 requirements, avoiding duplication for systemic banks.
Luxgap practice: if your entity has already performed a TIBER-LU exercise in the last three years, we reuse it as the DORA baseline without redoing the test, and only fill the documentation gaps required by the CSSF.