Recital 26
Digital Operational Resilience Act · UE 2022/2554
| (26) | In addition, where no ICT testing is required, vulnerabilities remain undetected and result in exposing a financial entity to ICT risk and ultimately create a higher risk to the stability and integrity of the financial sector. Without Union intervention, digital operational resilience testing would continue to be inconsistent and would lack a system of mutual recognition of ICT testing results across different jurisdictions. In addition, as it is unlikely that other financial subsectors would adopt testing schemes on a meaningful scale, they would miss out on the potential benefits of a testing framework, in terms of revealing ICT vulnerabilities and risks, and testing defence capabilities and business continuity, which contributes to increasing the trust of customers, suppliers and business partners. To remedy those overlaps, divergences and gaps, it is necessary to lay down rules for a coordinated testing regime and thereby facilitate the mutual recognition of advanced testing for financial entities meeting the criteria set out in this Regulation. |
In Luxembourg, the CSSF published in 2024 its circular 24/847 on ICT incident notification and confirms its alignment with the TIBER-LU framework, derived from TIBER-EU. Significant financial entities established in Luxembourg must perform their TLPT under this methodology to benefit from the mutual recognition provided in Article 26(8) of DORA.
Luxgap practice: we frame your TLPT directly under TIBER-LU to avoid any retest requested by the CSSF, and coordinate dialogue with the Luxembourg TIBER Cyber Team upstream of the test.