Recital 61
Digital Operational Resilience Act · UE 2022/2554
| (61) | In order to take advantage of internal resources available at corporate level, this Regulation should allow the use of internal testers for the purposes of carrying out TLPT, provided there is supervisory approval, no conflicts of interest, and periodical alternation of the use of internal and external testers (every three tests), while also requiring the provider of the threat intelligence in the TLPT to always be external to the financial entity. The responsibility for conducting TLPT should remain fully with the financial entity. Attestations provided by authorities should be solely for the purpose of mutual recognition and should not preclude any follow-up action needed to address the ICT risk to which the financial entity is exposed, nor should they be seen as a supervisory endorsement of a financial entity’s ICT risk management and mitigation capabilities. |
In Luxembourg, the CSSF is the designated TLPT authority and applies the TIBER-LU framework (Threat Intelligence-Based Ethical Red Teaming), aligned with the ECB's TIBER-EU. CSSF Regulation 24-01 on DORA and CSSF Circular 22/806 on ICT outsourcing specify the approval conditions for internal testers: file submitted at least 6 months before test launch, independence charter countersigned by the Board, and notification of any team change during the test.
Luxgap practice: our consultants prepare your CSSF approval file in parallel with TIBER-LU scoping to avoid the typical 4-to-8 month gap between internal decision and supervisory green light.