ECB TIBER-EU Framework
TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) is the European Central Bank's framework for intelligence-led red team testing of financial entities' cyber resilience. It provides a standardised approach across the EU for simulating real-world cyber attacks against critical functions of financial entities. Tests are conducted by accredited threat intelligence and red team providers. Adopted by multiple EU member states and aligned with similar frameworks (CBEST, iCAST, TLPT under DORA).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Phase 0: Generic Threat Landscape (Optional)
| Code | Title |
|---|---|
| TIBER-0.1 | Sector Threat Landscape Assessment |
| TIBER-0.2 | Threat Actor Mapping |
Phase 1: Preparation
| Code | Title |
|---|---|
| TIBER-1.1 | Test Initiation |
| TIBER-1.2 | Control Team Formation |
| TIBER-1.3 | Scope Definition |
| TIBER-1.4 | Provider Procurement |
| TIBER-1.5 | Risk Management |
Phase 2: Testing
| Code | Title |
|---|---|
| TIBER-2.1 | Targeted Threat Intelligence |
| TIBER-2.2 | Red Team Test Planning |
| TIBER-2.3 | Red Team Test Execution |
| TIBER-2.4 | Blue Team Response |
Phase 3: Closure
| Code | Title |
|---|---|
| TIBER-3.1 | Red Team Test Report |
| TIBER-3.2 | Blue Team Test Report |
| TIBER-3.3 | Replay and Purple Teaming |
| TIBER-3.4 | 360-Degree Feedback |
| TIBER-3.5 | Test Summary and Remediation |
| TIBER-3.6 | Attestation |
Maps to 526 other frameworks
Frequently Asked Questions
What is ECB TIBER-EU Framework?
ECB TIBER-EU Framework is a compliance framework from European Union (ECB) with 4 domains and 17 controls. TIBER-EU (Threat Intelligence-Based Ethical Red Teaming) is the European Central Bank's framework for intelligence-led red team testing of financial entities' cyber resilience. It provides a standardised approach across the EU for simulating real-world cyber attacks against critical functions of financial entities. Tests are conducted by accredited threat intelligence and red team providers. Adopted by multiple EU member states and aligned with similar frameworks (CBEST, iCAST, TLPT under DORA). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ECB TIBER-EU Framework have?
ECB TIBER-EU Framework has 17 controls organised across 4 domains. The largest domains are Phase 3: Closure (6 controls), Phase 1: Preparation (5 controls), Phase 2: Testing (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ECB TIBER-EU Framework map to?
ECB TIBER-EU Framework maps to 526 other compliance frameworks. The top mapping partners are HKMA Cyber Resilience Assessment Framework (C-RAF) (41% coverage), O-RAN Alliance Security Specifications (O-RAN.WG11) (41% coverage), Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct (35% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ECB TIBER-EU Framework compliance?
Start your ECB TIBER-EU Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ECB TIBER-EU Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 17 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required