ECB TIBER-EU Framework
Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
TIBER-EU Governance and DORA Alignment
The TIBER-EU framework is adopted and governed at the jurisdiction level (national implementation), with a TIBER Cyber Team overseeing tests and maintaining consistency with the framework.
- National TIBER implementation guidance and TCT oversight
- Ad-hoc red-teaming not aligned to the TIBER-EU framework
For entities operating across borders or as a group, tests are coordinated across the relevant authorities (TIBER-XX) to avoid duplication and enable joint recognition.
- Cross-border test coordination records where applicable
- Duplicated, uncoordinated tests across jurisdictions
TIBER-EU Phase 0: Generic Threat Landscape
A Generic Threat Landscape (GTL) for the jurisdiction/sector is produced (by the relevant authorities) to inform the threat scenarios used in TIBER-EU tests; entities and providers take it into account when developing targeted threat intelligence.
- Reference to the applicable GTL in test scoping and threat intelligence
- Threat scenarios not informed by the jurisdiction GTL
TIBER-EU Phase 1: Preparation
The test is initiated and launched through engagement between the entity and the authority's TIBER Cyber Team (TCT), confirming the test mandate, the management body's approval, and the engagement plan.
- Board-level approval of the TIBER-EU test
- Engagement/launch records with the TCT
- No management-body mandate for the test
A small White Team (Control Team) led by a White Team Lead is established to manage the test confidentially; the Blue Team (defenders) and wider staff remain unaware to ensure a realistic test.
- Defined White Team with confidentiality undertakings
- Evidence the Blue Team was not informed
- Wider awareness undermining test realism
The White Team and TCT define the scope, including the critical or important functions, the underlying systems and people, and the flags (objectives) the red team will seek to capture.
- Scope specification covering critical/important functions and flags
- Scoping meeting records
- Scope omitting critical functions
The entity procures qualified threat-intelligence and red-team providers in line with the TIBER-EU Services Procurement Guidelines, assessing suitability, expertise and (for the red team) insurance and legal arrangements.
- Provider due-diligence and contracts per the Services Procurement Guidelines
- Using providers that do not meet the procurement requirements
A risk management approach is agreed for testing on live production systems, including controls, escalation procedures and a risk management plan to prevent and contain unintended impact.
- Risk management plan for the live test with escalation and abort procedures
- Live testing without a risk management plan
TIBER-EU Phase 2: Testing
The threat-intelligence provider prepares a Targeted Threat Intelligence (TTI) Report on the entity, identifying realistic threat scenarios and providing the input for the red-team test plan.
- TTI Report tailored to the entity and its critical functions
- No targeted threat intelligence underpinning the test
The red-team provider develops a Red Team Test Plan that translates the threat scenarios from the TTI Report into attack scenarios targeting the in-scope critical functions and flags.
- A Red Team Test Plan derived from the TTI scenarios and agreed scope
- Test plan not based on targeted threat intelligence
The red team conducts active testing against the entity's live production systems supporting critical functions, attempting to capture the agreed flags, with leg-ups provided where necessary to progress the test.
- Red-team execution records and evidence of flags attempted/captured
- Use of leg-ups documented
- Testing not performed on live production critical functions
The Blue Team responds to the activity as it would to a real attack, without prior knowledge, providing a realistic measure of detection and response capability.
- Blue Team alerting/response logs captured during the test
- Blue Team pre-informed, invalidating the response measurement
TIBER-EU Phase 3: Closure
The red-team provider drafts a Red Team Test Report detailing the scenarios executed, the attack paths, findings and observations.
- Red Team Test Report
- No documented red-team findings
The Blue Team produces a report on what it detected and how it responded, to be compared with the red-team activity.
- Blue Team Report on detection/response
- No blue-team perspective captured
A replay/purple-teaming workshop is held where the red and blue teams walk through the attack scenarios together to maximise learning.
- Replay/purple-teaming workshop records
- No replay workshop conducted
A 360-degree feedback meeting is held among the key stakeholders (entity, providers, authority) to review the test and the process.
- 360-degree feedback meeting records
- No structured feedback on the test
A Test Summary Report on the findings (including the Remediation Plan) is produced, summarising the test outcomes for the entity and the authority.
- Test Summary Report shared with the authority
- No consolidated test summary
The entity agrees and finalises a Remediation Plan for the findings, in close consultation with the supervisor/authority, and tracks remediation to completion.
- A Remediation Plan with owners and timelines, tracked to closure
- Findings without a remediation plan
An attestation is provided confirming that the test was conducted in accordance with the TIBER-EU requirements.
- Attestation that the test followed TIBER-EU
- No attestation of TIBER-EU conformance
Test results and attestations may be shared with relevant authorities, and (for cross-border/group tests) recognised across jurisdictions, supporting mutual recognition including for DORA threat-led penetration testing.
- Records of results sharing / mutual-recognition arrangements where applicable
- No mechanism for cross-authority recognition where relevant
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ECB TIBER-EU Framework framework page.