Published on 20 June 2025 Email this Share this on LinkedIn Share this on Facebook Communiqué TIBER-LU Implementation document The BCL and the CSSF are pleased to announce the release of the TIBER-LU Implementation Document, updated as of 20 June 2025. Following the entry into force of the Digital Operational Resilience Act (DORA), in particular the Threat Led Penetration Testing (TLPT) requirements, and the publication of the revised TIBER-EU Framework by the ECB on 11 February 2025, the Banque centrale du Luxembourg (BCL) and the Commission de surveillance du secteur financier (CSSF) decided to revise the TIBER-LU framework for controlled cyber-attacks, which was implemented jointly on 3 November 2021. This revision marks an important step for the continuation of the TIBER-LU programme after the entry into force of DORA and its TLPT component. 3 November 2021 - Updated on 20 June 2025 TIBER-LU Implementation guide CSSF guidance PDF (108.37Kb) Main topic: ICT and cyber risk – for DORA entities Relevant for Central Securities Depositories (CSDs) Credit institutions Crowdfunding service providers Crypto-Assets Service Providers (CASPs) Data Reporting Service Providers (DRSPs) Investment firms Investment fund managers Issuers of Tokens Payment institutions/electronic money institutions/AISPs Pension fund Specialised PFS Support PFS TIBER-LU Implementation Document 20 June 2025 Introduction The TIBER-LU Framework, which was implemented jointly by the BCL and the CSSF and communicated on November 3rd 2021, was revised following the entry into force of the Digital Operational Resilience Act (DORA), in particular the Threat Led Penetration Testing (TLPT) requirements (Article 26) on 17th January 2025, and the publication of the revised TIBER-EU Framework by the ECB on 11th February 2025. DORA TLPT and TIBER-EU The BCL and the CSSF acknowledge that
AI explanation based on the official legal text. Indicative, not a substitute for legal advice.