NIS 2 Luxembourg: ILR releases incident guide via SERIMA
The ILR, with HCPN/ANSSI-GOVCERT.LU, CIRCL and CSSF, releases rulebooks to handle NIS 2 incidents and meet the 24h/72h/1-month milestones via SERIMA.
On 28 September 2026, the ILR, together with HCPN/ANSSI-GOVCERT.LU, CIRCL and the CSSF, released practical rulebooks to guide operational handling of NIS 2 incidents and structure exchanges via SERIMA. Goal: help teams meet the 24h / 72h / 1‑month deadlines.
Key facts
Who: ILR, HCPN (ANSSI/GOVCERT.LU), CIRCL, CSSF. What: joint release of Operational Guidance for Incident Handling (detection, containment, investigation, remediation, evidence preservation, communication). Where: Luxembourg (SERIMA). When: 28–29/09/2026. How much: timeboxed reporting milestones (24h / 72h / 1 month).
Legal basis
- Luxembourg: 5 May 2026 law (transposing NIS 2). Article 14(5) provides, after the initial notification of a significant incident, a first feedback and operational advice from the authority with the CSIRT.
- SERIMA deadlines: early warning within 24h, formal notification at 72h, final report within one month (extension possible if not closed).
- SERIMA: national incident notification portal centralising to competent authorities.
What changes for companies
- Actionable: rulebooks provide per‑scenario checklists (signals, immediate containment, investigation, remediation, evidence, communication) to streamline exchanges with ILR/CSIRT.
- Governance: essential/important entities face enhanced supervision; notifications are expected even when impact is only partially qualified.
- Financial sector: CSSF relays the same corpus; coordination in multi‑regime incidents (NIS 2 + GDPR + DORA) is easier. See our NIS 2 Luxembourg page for local context.
Actions to take this week
- Map your top 5 scenarios and align IR playbooks with the ILR rulebooks; include “detection”, “immediate containment”, “evidence”, “24h message” and “72h update”; run a 60‑minute tabletop with CERT/IT and the DPO.
- Secure the SERIMA notification chain: roles and deputies, tested access, distribution lists, early‑warning and formal templates.
- Synchronise GDPR and NIS 2: set up a DPO–CISO bridge to qualify the incident and detect any data breach to notify to the CNPD. Our fractional CISO service can help structure accountability and notification readiness.
- Document in the final report the technical measures, materiality criteria and lessons learned, aligned with your DORA controls if applicable.
Sources
- Operational guidance for incident handling (ILR, 28/09/2026) — news page and PDF guide.
- NIS 2 incident notification in Luxembourg — 24h / 72h / 1‑month deadlines (ILR).
- Operational guidance for incident handling (CSSF, 28–29/09/2026) — financial sector relay.
Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →