Recital 56
Digital Operational Resilience Act · UE 2022/2554
| (56) | In order to achieve a high level of digital operational resilience, and in line with both the relevant international standards (e.g. the G7 Fundamental Elements for Threat-Led Penetration Testing) and with the frameworks applied in the Union, such as the TIBER-EU, financial entities should regularly test their ICT systems and staff having ICT-related responsibilities with regard to the effectiveness of their preventive, detection, response and recovery capabilities, to uncover and address potential ICT vulnerabilities. To reflect differences that exist across, and within, the various financial subsectors as regards financial entities’ level of cybersecurity preparedness, testing should include a wide variety of tools and actions, ranging from the assessment of basic requirements (e.g. vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing or end-to-end testing) to more advanced testing by means of TLPT. Such advanced testing should be required only of financial entities that are mature enough from an ICT perspective to reasonably carry it out. The digital operational resilience testing required by this Regulation should thus be more demanding for those financial entities meeting the criteria set out in this Regulation (for example, large, systemic and ICT-mature credit institutions, stock exchanges, central securities depositories and central counterparties) than for other financial entities. At the same time, the digital operational resilience testing by means of TLPT should be more relevant for financial entities operating in core financial services subsectors and playing a systemic role (for example, payments, banking, and clearing and settlement), and less relevant for other subsectors (for example, asset managers and credit rating agencies). |
In Luxembourg, the CSSF is the DORA competent authority and has published a regularly updated DORA FAQ, along with dedicated guidance on TIBER-LU (national framework derived from TIBER-EU). CSSF Circular 24/847 on ICT incident reporting and CSSF Circular 22/806 on ICT outsourcing (still applicable as a complement) specify local expectations on ICT maturity and on which entities will be designated for TLPT. The BCL cooperates with the CSSF on TIBER-LU for market infrastructures (Clearstream, LuxCSD).
Luxgap practice: for ManCos, AIFMs and support PFS, do not budget a TLPT in your 2025 roadmap, the CSSF is unlikely to designate you. Focus spending on the other 7 test families from Recital 56, and document the non-applicability of TLPT in your testing policy to pre-empt any inspection question.