Skip to content

Evidence request lists

ECB TIBER-EU Framework

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

TIBER-EU Governance and DORA Alignment

TIBER-GOV-1
TIBER-EU adoption and programme governance

The TIBER-EU framework is adopted and governed at the jurisdiction level (national implementation), with a TIBER Cyber Team overseeing tests and maintaining consistency with the framework.

Artefacts an auditor will ask for
  • National TIBER implementation guidance and TCT oversight
Where this commonly fails
  • Ad-hoc red-teaming not aligned to the TIBER-EU framework
TIBER-GOV-2
Cross-border coordination (TIBER-XX)

For entities operating across borders or as a group, tests are coordinated across the relevant authorities (TIBER-XX) to avoid duplication and enable joint recognition.

Artefacts an auditor will ask for
  • Cross-border test coordination records where applicable
Where this commonly fails
  • Duplicated, uncoordinated tests across jurisdictions

TIBER-EU Phase 0: Generic Threat Landscape

TIBER-0.1
Generic Threat Landscape

A Generic Threat Landscape (GTL) for the jurisdiction/sector is produced (by the relevant authorities) to inform the threat scenarios used in TIBER-EU tests; entities and providers take it into account when developing targeted threat intelligence.

Artefacts an auditor will ask for
  • Reference to the applicable GTL in test scoping and threat intelligence
Where this commonly fails
  • Threat scenarios not informed by the jurisdiction GTL

TIBER-EU Phase 1: Preparation

TIBER-1.1
Test initiation and launch

The test is initiated and launched through engagement between the entity and the authority's TIBER Cyber Team (TCT), confirming the test mandate, the management body's approval, and the engagement plan.

Artefacts an auditor will ask for
  • Board-level approval of the TIBER-EU test
  • Engagement/launch records with the TCT
Where this commonly fails
  • No management-body mandate for the test
TIBER-1.2
White Team establishment and confidentiality

A small White Team (Control Team) led by a White Team Lead is established to manage the test confidentially; the Blue Team (defenders) and wider staff remain unaware to ensure a realistic test.

Artefacts an auditor will ask for
  • Defined White Team with confidentiality undertakings
  • Evidence the Blue Team was not informed
Where this commonly fails
  • Wider awareness undermining test realism
TIBER-1.3
Scoping of critical functions and flags

The White Team and TCT define the scope, including the critical or important functions, the underlying systems and people, and the flags (objectives) the red team will seek to capture.

Artefacts an auditor will ask for
  • Scope specification covering critical/important functions and flags
  • Scoping meeting records
Where this commonly fails
  • Scope omitting critical functions
TIBER-1.4
Procurement of threat intelligence and red team providers

The entity procures qualified threat-intelligence and red-team providers in line with the TIBER-EU Services Procurement Guidelines, assessing suitability, expertise and (for the red team) insurance and legal arrangements.

Artefacts an auditor will ask for
  • Provider due-diligence and contracts per the Services Procurement Guidelines
Where this commonly fails
  • Using providers that do not meet the procurement requirements
TIBER-1.5
Risk management for live testing

A risk management approach is agreed for testing on live production systems, including controls, escalation procedures and a risk management plan to prevent and contain unintended impact.

Artefacts an auditor will ask for
  • Risk management plan for the live test with escalation and abort procedures
Where this commonly fails
  • Live testing without a risk management plan

TIBER-EU Phase 2: Testing

TIBER-2.1
Targeted Threat Intelligence Report

The threat-intelligence provider prepares a Targeted Threat Intelligence (TTI) Report on the entity, identifying realistic threat scenarios and providing the input for the red-team test plan.

Artefacts an auditor will ask for
  • TTI Report tailored to the entity and its critical functions
Where this commonly fails
  • No targeted threat intelligence underpinning the test
TIBER-2.2
Red Team Test Plan

The red-team provider develops a Red Team Test Plan that translates the threat scenarios from the TTI Report into attack scenarios targeting the in-scope critical functions and flags.

Artefacts an auditor will ask for
  • A Red Team Test Plan derived from the TTI scenarios and agreed scope
Where this commonly fails
  • Test plan not based on targeted threat intelligence
TIBER-2.3
Active red team testing on live production

The red team conducts active testing against the entity's live production systems supporting critical functions, attempting to capture the agreed flags, with leg-ups provided where necessary to progress the test.

Artefacts an auditor will ask for
  • Red-team execution records and evidence of flags attempted/captured
  • Use of leg-ups documented
Where this commonly fails
  • Testing not performed on live production critical functions
TIBER-2.4
Blue Team detection and response (unaware)

The Blue Team responds to the activity as it would to a real attack, without prior knowledge, providing a realistic measure of detection and response capability.

Artefacts an auditor will ask for
  • Blue Team alerting/response logs captured during the test
Where this commonly fails
  • Blue Team pre-informed, invalidating the response measurement

TIBER-EU Phase 3: Closure

TIBER-3.1
Red Team Test Report

The red-team provider drafts a Red Team Test Report detailing the scenarios executed, the attack paths, findings and observations.

Artefacts an auditor will ask for
  • Red Team Test Report
Where this commonly fails
  • No documented red-team findings
TIBER-3.2
Blue Team Report

The Blue Team produces a report on what it detected and how it responded, to be compared with the red-team activity.

Artefacts an auditor will ask for
  • Blue Team Report on detection/response
Where this commonly fails
  • No blue-team perspective captured
TIBER-3.3
Replay and purple teaming workshop

A replay/purple-teaming workshop is held where the red and blue teams walk through the attack scenarios together to maximise learning.

Artefacts an auditor will ask for
  • Replay/purple-teaming workshop records
Where this commonly fails
  • No replay workshop conducted
TIBER-3.4
360-degree feedback meeting

A 360-degree feedback meeting is held among the key stakeholders (entity, providers, authority) to review the test and the process.

Artefacts an auditor will ask for
  • 360-degree feedback meeting records
Where this commonly fails
  • No structured feedback on the test
TIBER-3.5
Test Summary Report

A Test Summary Report on the findings (including the Remediation Plan) is produced, summarising the test outcomes for the entity and the authority.

Artefacts an auditor will ask for
  • Test Summary Report shared with the authority
Where this commonly fails
  • No consolidated test summary
TIBER-3.6
Remediation Plan

The entity agrees and finalises a Remediation Plan for the findings, in close consultation with the supervisor/authority, and tracks remediation to completion.

Artefacts an auditor will ask for
  • A Remediation Plan with owners and timelines, tracked to closure
Where this commonly fails
  • Findings without a remediation plan
TIBER-3.7
Attestation

An attestation is provided confirming that the test was conducted in accordance with the TIBER-EU requirements.

Artefacts an auditor will ask for
  • Attestation that the test followed TIBER-EU
Where this commonly fails
  • No attestation of TIBER-EU conformance
TIBER-3.8
Results sharing and mutual recognition

Test results and attestations may be shared with relevant authorities, and (for cross-border/group tests) recognised across jurisdictions, supporting mutual recognition including for DORA threat-led penetration testing.

Artefacts an auditor will ask for
  • Records of results sharing / mutual-recognition arrangements where applicable
Where this commonly fails
  • No mechanism for cross-authority recognition where relevant
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ECB TIBER-EU Framework framework page.