Recital 59
Digital Operational Resilience Act · UE 2022/2554
| (59) | Since this Regulation does not require financial entities to cover all critical or important functions in one single threat-led penetration test, financial entities should be free to determine which and how many critical or important functions should be included in the scope of such a test. |
In Luxembourg, the CSSF is the competent authority for supervising TLPT tests under Article 26 DORA, in coordination with the BCL for systemic players. The Luxembourg financial centre has applied the TIBER-LU framework since 2018, whose convergence with the DORA TLPT RTS the CSSF has confirmed: entities already tested under TIBER-LU benefit from partial recognition but must demonstrate multi-year coverage of all their critical functions.
Luxgap practice: for Luxembourg private banks, funds and PSFs, we recommend submitting the TLPT scope matrix to the CSSF TIBER Cyber Team upstream, ideally 6 months before the Red Team phase, to avoid a scope reclassification during the test.