← All articles

consultant

NIS 2 in Luxembourg: Law of 5 May 2026 published—what to do before 10 May

Luxembourg’s law transposing NIS 2 was published on 5 May 2026 and enters into force on 10 May. Broader scope, stronger governance, incident reporting within 24 h/72 h to ILR via SERIMA. Priority actions and official sources.

Summary — Luxembourg’s law transposing NIS 2 was published on 5 May 2026 and enters into force on 10 May 2026. It broadens scope, strengthens governance, and requires 24 h/72 h incident alert/notification to ILR. Key sources and actions below.

The general rule

What the regulators say

How to apply in practice

Case of an “important” entity (manufacturing/ICT B2B), week of 5–10 May 2026

  1. Before 10 May (D‑3 to D‑0)
  2. During an incident (upon detection)
  3. After (within 90 days)

Who is in scope (EE vs EI)

Sanctions

Common pitfalls

  1. Limiting to “critical systems” as under NIS 1: NIS 2 covers all networks/IS supporting the business (Art. 21). https://www.ilr.lu/secteurs-activites/niss/nis-2/mesures-securite-nis2/.
  2. Overlooking the supply chain (MSP/MSSP, SaaS): align contracts and evidence of controls (Art. 21(2)). https://www.ilr.lu/secteurs-activites/niss/nis-2/mesures-securite-nis2/.
  3. Confusing NIS 2 and GDPR timelines: NIS 2 (24 h/72 h) does not remove the 72 h CNPD notification. ILR “Incident notification”; EDPB 9/2022; CNPD. https://www.ilr.lu/secteurs-activites/niss/nis-2/notification-incident-nis2/https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-92022-personal-data-breach-notification-under_enhttps://cnpd.public.lu/fr/professionnels/obligations/violation-de-donnees.html.
  4. Neglecting management training (Art. 20) and their accountability. https://www.ilr.lu/secteurs-activites/niss/nis-2/mesures-securite-nis2/.
  5. Waiting for “official lists”: NIS 2 relies on self‑identification/self‑registration; controls must be in place at entry into force. ILR FAQ: https://www.ilr.lu/en/sectors/niss/nis-2/frequently-asked-questions-about-nis2-faq/.

Official sources

In brief — As of 7 May 2026, potentially in‑scope Luxembourg companies should assume they are covered based on activity and size, self‑register, formalize management bodies’ responsibility, secure the supply chain, and immediately enable 24 h/72 h incident alert/notification via SERIMA, coordinating GDPR notification to CNPD within 72 h where applicable. https://www.ilr.lu/secteurs-activites/niss/nis-2/

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →