Closure, report and remediation: what the authority expects
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing (TLPT) under DORA · UE 2025/1190
At the end of the test, the entity produces a summary report and a documented remediation plan, prioritising identified vulnerabilities and corrective actions with deadlines. The TLPT authority (CSSF in Luxembourg) issues an attestation of completion of a TLPT compliant with requirements.
The remediation plan feeds directly into the ICT risk management framework (DORA Art. 5 to 16, CSSF Circular 20/750 as amended by 25/881). A TLPT is only valuable if the flaws found are actually fixed and re-tested.