ECB TIBER-EU Framework
TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) is a framework developed under the coordination of the European Union Cybersecurity Agency (ENISA) and adopted by national authorities and central banks across the EU, including the European Central Bank. It provides a standardized approach for intelligence-led red team exercises to test the cyber resilience of financial entities by simulating realistic, threat-informed cyber attacks on critical functions.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (20)
Attestation
| Code | Title |
|---|---|
| TIBER.16 | Attestation and Authority Communication |
Closure
| Code | Title |
|---|---|
| TIBER.14 | Blue Team Report and Replay Workshop |
Confidentiality
| Code | Title |
|---|---|
| TIBER.19 | Confidentiality and Data Handling of Test Artefacts |
Coordination
| Code | Title |
|---|---|
| TIBER.17 | Cross-Border Coordination (TIBER-XX) |
DORA
| Code | Title |
|---|---|
| TIBER.18 | Mutual Recognition Under DORA TLPT |
Governance
| Code | Title |
|---|---|
| TIBER.1 | TIBER-EU Programme Governance |
Improvement
| Code | Title |
|---|---|
| TIBER.20 | Lessons Learned and Continuous Improvement |
Legal
| Code | Title |
|---|---|
| TIBER.10 | Rules of Engagement and Safe Harbour |
Operations
| Code | Title |
|---|---|
| TIBER.11 | Blue Team Confidentiality |
Phase 0: Generic Threat Landscape (Optional)
| Code | Title |
|---|---|
| TIBER-0.1 | Sector Threat Landscape Assessment |
| TIBER-0.2 | Threat Actor Mapping |
Phase 1: Preparation
| Code | Title |
|---|---|
| TIBER-1.1 | Test Initiation |
| TIBER-1.2 | Control Team Formation |
| TIBER-1.3 | Scope Definition |
| TIBER-1.4 | Provider Procurement |
| TIBER-1.5 | Risk Management |
Phase 2: Testing
| Code | Title |
|---|---|
| TIBER-2.1 | Targeted Threat Intelligence |
| TIBER-2.2 | Red Team Test Planning |
| TIBER-2.3 | Red Team Test Execution |
| TIBER-2.4 | Blue Team Response |
Phase 3: Closure
| Code | Title |
|---|---|
| TIBER-3.1 | Red Team Test Report |
| TIBER-3.2 | Blue Team Test Report |
| TIBER-3.3 | Replay and Purple Teaming |
| TIBER-3.4 | 360-Degree Feedback |
| TIBER-3.5 | Test Summary and Remediation |
| TIBER-3.6 | Attestation |
Procurement
| Code | Title |
|---|---|
| TIBER.5 | Threat Intelligence Provider Procurement |
| TIBER.6 | Red Team Provider Procurement |
Remediation
| Code | Title |
|---|---|
| TIBER.15 | Remediation Plan |
Reporting
| Code | Title |
|---|---|
| TIBER.13 | Red Team Test Report |
Roles
| Code | Title |
|---|---|
| TIBER.2 | White Team Composition |
Scope
| Code | Title |
|---|---|
| TIBER.3 | Critical or Important Functions Scoping |
Testing
| Code | Title |
|---|---|
| TIBER.12 | Active Test Execution |
| TIBER.8 | Red Team Test Plan |
| TIBER.9 | Leg-Up Procedures |
Threat Intel
| Code | Title |
|---|---|
| TIBER.4 | Generic Threat Landscape (GTL) Alignment |
| TIBER.7 | Targeted Threat Intelligence (TTI) Report |
Your Compliance Coverage
If you comply with ECB TIBER-EU Framework, you already cover:
HKMA Cyber Resilience Assessment Framework (C-RAF)
19%
7 controls mapped
Compare →O-RAN Alliance Security Specifications (O-RAN.WG11)
19%
7 controls mapped
Compare →Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct
16%
6 controls mapped
Compare →+ 546 more: NIST Cybersecurity Framework 2.0 (16%), BS 65000:2014 — Guidance on Organizational Resilience (16%)
See all 549 mapped frameworks ↓Maps to 549 other frameworks
Frequently Asked Questions
What is ECB TIBER-EU Framework?
ECB TIBER-EU Framework is a compliance framework from European Union (coordinated by ENISA, adopted by national authorities and the ECB) with 20 domains and 37 controls. TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) is a framework developed under the coordination of the European Union Cybersecurity Agency (ENISA) and adopted by national authorities and central banks across the EU, including the European Central Bank. It provides a standardized approach for intelligence-led red team exercises to test the cyber resilience of financial entities by simulating realistic, threat-informed cyber attacks on critical functions. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ECB TIBER-EU Framework have?
ECB TIBER-EU Framework has 37 controls organised across 20 domains. The largest domains are Phase 3: Closure (6 controls), Phase 1: Preparation (5 controls), Phase 2: Testing (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ECB TIBER-EU Framework map to?
ECB TIBER-EU Framework maps to 549 other compliance frameworks. The top mapping partners are HKMA Cyber Resilience Assessment Framework (C-RAF) (19% coverage), O-RAN Alliance Security Specifications (O-RAN.WG11) (19% coverage), Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct (16% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ECB TIBER-EU Framework compliance?
Start your ECB TIBER-EU Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ECB TIBER-EU Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 37 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required