Back to Frameworks

ECB TIBER-EU Framework

European Union (coordinated by ENISA, adopted by national authorities and the ECB)
v2023
5 domains
20 controls

The ECB TIBER-EU Framework for Threat Intelligence-based Ethical Red Teaming, the European framework for controlled, intelligence-led red-team testing of the live production systems of financial entities. Defines a three-phase process (Preparation, Testing, Closure) supported by an optional jurisdiction-level Generic Threat Landscape, the roles of the White/Control Team, Blue Team, Red Team, threat-intelligence provider and the authority TIBER Cyber Team, and the deliverables (Targeted Threat Intelligence Report, Red Team Test Plan and Report, Blue Team Report, replay/purple teaming, Test Summary Report, Remediation Plan and attestation). TIBER-EU underpins mutual recognition of threat-led penetration testing under DORA.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

TIBER-EU Governance and DORA Alignment

2 controls
Controls in the TIBER-EU Governance and DORA Alignment domain of ECB TIBER-EU Framework2 controls
CodeTitle
TIBER-GOV-1TIBER-EU adoption and programme governance
TIBER-GOV-2Cross-border coordination (TIBER-XX)

TIBER-EU Phase 0: Generic Threat Landscape

1 controls
Controls in the TIBER-EU Phase 0: Generic Threat Landscape domain of ECB TIBER-EU Framework1 controls
CodeTitle
TIBER-0.1Generic Threat Landscape

TIBER-EU Phase 1: Preparation

5 controls
Controls in the TIBER-EU Phase 1: Preparation domain of ECB TIBER-EU Framework5 controls
CodeTitle
TIBER-1.1Test initiation and launch
TIBER-1.2White Team establishment and confidentiality
TIBER-1.3Scoping of critical functions and flags
TIBER-1.4Procurement of threat intelligence and red team providers
TIBER-1.5Risk management for live testing

TIBER-EU Phase 2: Testing

4 controls
Controls in the TIBER-EU Phase 2: Testing domain of ECB TIBER-EU Framework4 controls
CodeTitle
TIBER-2.1Targeted Threat Intelligence Report
TIBER-2.2Red Team Test Plan
TIBER-2.3Active red team testing on live production
TIBER-2.4Blue Team detection and response (unaware)

TIBER-EU Phase 3: Closure

8 controls
Controls in the TIBER-EU Phase 3: Closure domain of ECB TIBER-EU Framework8 controls
CodeTitle
TIBER-3.1Red Team Test Report
TIBER-3.2Blue Team Report
TIBER-3.3Replay and purple teaming workshop
TIBER-3.4360-degree feedback meeting
TIBER-3.5Test Summary Report
TIBER-3.6Remediation Plan
TIBER-3.7Attestation
TIBER-3.8Results sharing and mutual recognition

Maps to 2 other frameworks

20 total controls
DORA
3 source controls mapped|2 target controls covered
15%
NIST SP 800-53 Rev 5
1 source controls mapped|1 target controls covered
5%

Frequently Asked Questions

What is ECB TIBER-EU Framework?

ECB TIBER-EU Framework is a compliance framework from European Union (coordinated by ENISA, adopted by national authorities and the ECB) with 5 domains and 20 controls. The ECB TIBER-EU Framework for Threat Intelligence-based Ethical Red Teaming, the European framework for controlled, intelligence-led red-team testing of the live production systems of financial entities. Defines a three-phase process (Preparation, Testing, Closure) supported by an optional jurisdiction-level Generic Threat Landscape, the roles of the White/Control Team, Blue Team, Red Team, threat-intelligence provider and the authority TIBER Cyber Team, and the deliverables (Targeted Threat Intelligence Report, Red Team Test Plan and Report, Blue Team Report, replay/purple teaming, Test Summary Report, Remediation Plan and attestation). TIBER-EU underpins mutual recognition of threat-led penetration testing under DORA. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ECB TIBER-EU Framework have?

ECB TIBER-EU Framework has 20 controls organised across 5 domains. The largest domains are TIBER-EU Phase 3: Closure (8 controls), TIBER-EU Phase 1: Preparation (5 controls), TIBER-EU Phase 2: Testing (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ECB TIBER-EU Framework map to?

ECB TIBER-EU Framework maps to 2 other compliance frameworks. The top mapping partners are DORA (15% coverage), NIST SP 800-53 Rev 5 (5% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with ECB TIBER-EU Framework compliance?

Start your ECB TIBER-EU Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ECB TIBER-EU Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required