Recital 60

Recital 60

Digital Operational Resilience Act · UE 2022/2554

(60)

Pooled testing within the meaning of this Regulation – involving the participation of several financial entities in a TLPT and for which an ICT third-party service provider can directly enter into contractual arrangements with an external tester – should be allowed only where the quality or security of services delivered by the ICT third-party service provider to customers that are entities falling outside the scope of this Regulation, or the confidentiality of the data related to such services, are reasonably expected to be adversely impacted. Pooled testing should also be subject to safeguards (direction by one designated financial entity, calibration of the number of participating financial entities) to ensure a rigorous testing exercise for the financial entities involved which meet the objectives of the TLPT pursuant to this Regulation.

Luxembourg specificity
circulaire CSSF 24/847 et reglement CSSF 20-09 sur l'externalisation TIC, framework TIBER-LU

In Luxembourg, the CSSF is the designated TLPT authority and operates the TIBER-LU framework, the national declension of TIBER-EU adopted by the ECB. CSSF circular 24/847 on ICT incident management and CSSF regulation 20-09 on ICT outsourcing frame the accountability chain, including for pooled testing where the CSSF requires prior notification and validation of the eligibility file before signing the tripartite contract.

Luxgap practice: before launching a pooled TLPT on a shared ICT provider (typically a hyperscaler hosted in Bissen or Roost), have the CSSF validate the adverse impact justification and the lead entity mandate at least 90 days before kick-off, and align the scope with the generic threat landscape published by the BCL and CERT.LU.