← Luxembourg

TIBER-LU Implementation document

Published on 20 June 2025 Email this Share this on LinkedIn Share this on Facebook Communiqué TIBER-LU Implementation document The BCL and the CSSF are pleased to announce the release of the TIBER-LU Implementation Document, updated as of 20 June 2025. Following the entry into force of the Digital Operational Resilience Act (DORA), in particular the Threat Led Penetration Testing (TLPT) requirements, and the publication of the revised TIBER-EU Framework by the ECB on 11 February 2025, the Banque centrale du Luxembourg (BCL) and the Commission de surveillance du secteur financier (CSSF) decided to revise the TIBER-LU framework for controlled cyber-attacks, which was implemented jointly on 3 November 2021. This revision marks an important step for the continuation of the TIBER-LU programme after the entry into force of DORA and its TLPT component. 3 November 2021 - Updated on 20 June 2025 TIBER-LU Implementation guide CSSF guidance PDF (108.37Kb) Main topic: ICT and cyber risk – for DORA entities Relevant for Central Securities Depositories (CSDs) Credit institutions Crowdfunding service providers Crypto-Assets Service Providers (CASPs) Data Reporting Service Providers (DRSPs) Investment firms Investment fund managers Issuers of Tokens Payment institutions/electronic money institutions/AISPs Pension fund Specialised PFS Support PFS TIBER-LU Implementation Document 20 June 2025 Introduction The TIBER-LU Framework, which was implemented jointly by the BCL and the CSSF and communicated on November 3rd 2021, was revised following the entry into force of the Digital Operational Resilience Act (DORA), in particular the Threat Led Penetration Testing (TLPT) requirements (Article 26) on 17th January 2025, and the publication of the revised TIBER-EU Framework by the ECB on 11th February 2025. DORA TLPT and TIBER-EU The BCL and the CSSF acknowledge that

  1. i)
  2. ii)the DORA TLPT RTS requirements were developed “in accordance with TIBEREU” and in “agreement with the ECB”, the ECB integrated the necessary changes into the TIBER-EU documentation to ensure consistency, Given the above elements, BCL and CSSF decided to continue the joint implementation of the TIBER-LU Program and to adapt the TIBER-LU Framework where appropriate. TIBER-LU The revised TIBER-LU Program covers both tests conducted on a voluntary basis as well as mandatory tests initiated in the context of the DORA regulation. As a general principle, TIBER-LU adheres to the updated TIBER-EU implementation guide, guidance documents and any other documentation as published by the ECB website under the following link: https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html Notwithstanding the above, and while ensuring alignment with overarching TIBER-EU framework principles, the TIBER-LU authorities however reserve the right to develop and publish supplementary guidance, if necessary to address specific local needs and operational requirements. Such guidance, if any, will be published on the BCL and CSSF respective websites. The present “TIBER-LU Implementation Document” 1 replaces the previously published “TIBER-LU Implementation Guide” and the related templates published so far on the BCL and the CSSF respective websites. TIBER-LU TCT The TIBER Cyber Team continues to be operated jointly by the BCL and the CSSF. The teams can be contacted using the following email addresses tiber@cssf.lu and tiber@bcl.lu. Entities in scope In accordance with the revised TIBER-LU Framework, the financial entities in scope for TIBER-LU tests include the entities that are mandated to perform a TLPT test under DORA in accordance with RTS Article 9

(1)as well as entities, selected by BCL and CSSF, that agree to perform tests on a voluntary basis. 1 As referred to in the section 1.6 of the TIBER-EU Framework published in February 2025

🔗 Vers la source officielle

AI explanation based on the official legal text. Indicative, not a substitute for legal advice.