Recital 59

Recital 59

Digital Operational Resilience Act · UE 2022/2554

(59)

Since this Regulation does not require financial entities to cover all critical or important functions in one single threat-led penetration test, financial entities should be free to determine which and how many critical or important functions should be included in the scope of such a test.

Luxembourg specificity
cadre TIBER-LU (CSSF, 2018) et article 26 DORA (UE 2022/2554)

In Luxembourg, the CSSF is the competent authority for supervising TLPT tests under Article 26 DORA, in coordination with the BCL for systemic players. The Luxembourg financial centre has applied the TIBER-LU framework since 2018, whose convergence with the DORA TLPT RTS the CSSF has confirmed: entities already tested under TIBER-LU benefit from partial recognition but must demonstrate multi-year coverage of all their critical functions.

Luxgap practice: for Luxembourg private banks, funds and PSFs, we recommend submitting the TLPT scope matrix to the CSSF TIBER Cyber Team upstream, ideally 6 months before the Red Team phase, to avoid a scope reclassification during the test.