← All articles

redaction

NIS 2 Luxembourg: ILR releases incident guide via SERIMA

The ILR, with HCPN/ANSSI-GOVCERT.LU, CIRCL and CSSF, releases rulebooks to handle NIS 2 incidents and meet the 24h/72h/1-month milestones via SERIMA.

On 28 September 2026, the ILR, together with HCPN/ANSSI-GOVCERT.LU, CIRCL and the CSSF, released practical rulebooks to guide operational handling of NIS 2 incidents and structure exchanges via SERIMA. Goal: help teams meet the 24h / 72h / 1‑month deadlines.

Key facts

Who: ILR, HCPN (ANSSI/GOVCERT.LU), CIRCL, CSSF. What: joint release of Operational Guidance for Incident Handling (detection, containment, investigation, remediation, evidence preservation, communication). Where: Luxembourg (SERIMA). When: 28–29/09/2026. How much: timeboxed reporting milestones (24h / 72h / 1 month).

Legal basis

  • Luxembourg: 5 May 2026 law (transposing NIS 2). Article 14(5) provides, after the initial notification of a significant incident, a first feedback and operational advice from the authority with the CSIRT.
  • SERIMA deadlines: early warning within 24h, formal notification at 72h, final report within one month (extension possible if not closed).
  • SERIMA: national incident notification portal centralising to competent authorities.

What changes for companies

  • Actionable: rulebooks provide per‑scenario checklists (signals, immediate containment, investigation, remediation, evidence, communication) to streamline exchanges with ILR/CSIRT.
  • Governance: essential/important entities face enhanced supervision; notifications are expected even when impact is only partially qualified.
  • Financial sector: CSSF relays the same corpus; coordination in multi‑regime incidents (NIS 2 + GDPR + DORA) is easier. See our NIS 2 Luxembourg page for local context.

Actions to take this week

  • Map your top 5 scenarios and align IR playbooks with the ILR rulebooks; include “detection”, “immediate containment”, “evidence”, “24h message” and “72h update”; run a 60‑minute tabletop with CERT/IT and the DPO.
  • Secure the SERIMA notification chain: roles and deputies, tested access, distribution lists, early‑warning and formal templates.
  • Synchronise GDPR and NIS 2: set up a DPO–CISO bridge to qualify the incident and detect any data breach to notify to the CNPD. Our fractional CISO service can help structure accountability and notification readiness.
  • Document in the final report the technical measures, materiality criteria and lessons learned, aligned with your DORA controls if applicable.

Sources

  • Operational guidance for incident handling (ILR, 28/09/2026) — news page and PDF guide.
  • NIS 2 incident notification in Luxembourg — 24h / 72h / 1‑month deadlines (ILR).
  • Operational guidance for incident handling (CSSF, 28–29/09/2026) — financial sector relay.

Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →