The classic trap
Recital 44 reminds us that Threat-Led Penetration Testing (TLPT) under article 26 only applies to a small percentage of financial entities, designated by the CSSF based on size, risk profile and systemic importance. The classic trap: assuming you are exempt because you are small, then discovering at designation time that you must run a TIBER-LU TLPT within 6 months without having budgeted the accredited red team, the blue team or the internal White Team. The reverse trap: over-investing in a TLPT when you are not designated, confusing TLPT with a standard pentest.
How to know if you are in the small percentage concerned
- Are you a significant bank under SSM, a CSD, a CCP, or a systemic payment actor in Luxembourg?
- Have you received a CSSF notification including you in the TIBER-LU or TIBER-EU scope?
- Are your critical functions (payments, custody, trading, fund administration) concentrated on a limited number of ICT systems?
- Is your cross-border exposure material (EU branches, cross-border clientele, depositary for UCITS/AIF funds)?
- Do you already have a mapping of flags and crown jewels usable by an accredited external tester?
If you answer yes to two of these criteria, anticipate designation: the CSSF does not warn you 18 months in advance. If you answer no everywhere, recital 44 protects you, but you still need to satisfy basic testing under article 25 (vulnerability assessments, scans, scenario-based tests).
How Luxgap automates this risk
Our Luxgap TLPT Readiness Radar tells you, within 72 hours and with an opposable scored output, whether you are in the small percentage of recital 44 or whether article 25 basic testing is enough, and budgets precisely the gap to bridge. The tool ingests your CSSF data (prudential category, total balance sheet, AuM, payment volumes), your critical functions mapping under article 8, your article 28 ICT contract register, and cross-references all of it with the TIBER-LU criteria published by BCL and CSSF.
- Computes a probabilistic TLPT designation score over 24 months, based on your prudential profile and the observed trajectory of entities already designated in Luxembourg and across the EU.
- Generates an automatic mapping of crown jewels and flags from your Azure, AWS, Active Directory inventories and declared critical functions.
- Simulates the full TLPT budget (accredited red team, internal white team, threat intelligence provider, remediation) with ranges aligned to the Luxembourg market.
- Detects gaps against article 26 requirements and the TIBER-LU framework, and lists the actions to execute before designation to avoid being caught off guard.
- For out-of-scope entities, automatically switches to the article 25 test plan (scans, targeted pentests, table-top exercises) with an annual calendar ready for the CSSF.
- Produces a timestamped, cryptographically signed PDF dossier, opposable to the CSSF should it question your digital resilience testing setup.
Available as a complement to a Luxgap CISO mandate or as a standalone SaaS module depending on your prudential status. Request your demonstration and our teams prepare an analysis on your real profile, with a free blank audit within 48h to measure your exposure to a TLPT designation before any engagement.