← All articles

consultant

NIS 2: ILR frames directors’ accountability

ILR issues NIS 2 Guidelines for governing bodies: approval, oversight and training become verifiable and sanctionable.

On 4 March 2026, the Luxembourg Institute of Regulation (ILR) issued its NIS 2 Guidelines – Governing Bodies, making leaders’ active involvement, approval and oversight of measures, and training verifiable. Key takeaway: governance is now sanctionable. ILR – publication page and PDF (17/02/2026).

The case

The guide clarifies expectations for executive committees and boards under the Luxembourg law of 5 May 2026 transposing Directive (EU) 2022/2555. Three flagship duties: approve risk-management measures, oversee their implementation, and undertake training (for leaders and staff). ILR, NIS 2 Guidelines – Governing Bodies and ILR PDF.

This local framing complements NIS 2, whose Article 20 requires that “governing bodies approve the measures (Art. 21), oversee their implementation and may be held liable in case of infringement.” Article 20 NIS 2 – EUR‑Lex. On 6 July 2026, the Government recalled fines up to EUR 10m or 2% of global turnover for essential entities. Government/ILR release 06/07/2026.

Legal reasoning

  • Article 20 (Governance): liability of governing bodies, approval and oversight; training for leaders and staff. EUR‑Lex.
  • Article 21 (Risk management measures): minimum requirements (policies, incident response, continuity, supply chain, etc.). EUR‑Lex.

The Commission clarified the intrinsic link between governance (Art. 20) and technical/organizational requirements (Art. 21), notably where an EU sectoral cybersecurity framework applies. Commission Communication on Article 4 NIS 2.

ILR translates this standard into concrete governance expectations: validation of the security policy, risk assessments and remediation plans; training of leaders and a continuous program for staff; oversight of incident notification (Art. 23 NIS 2) and cooperation with the authority. ILR, Guidelines (sections 1 and 2).

On sanctions, NIS 2 sets a harmonised floor: essential entities (EUR 10m or 2% of global turnover), important entities (EUR 7m or 1.4%). NIS 2 FAQ – European Commission. In Luxembourg, the 5 May 2026 law is published and notified on EUR‑Lex (NIM). NIM file – Law of 05/05/2026.

What changes in practice

  • Executive and Board involvement: formal deliberations on the security policy, risk appetite, Art. 21 measures and budgets; periodic reviews of risks and major incidents.
  • Leadership training: an annual documented program aligned with ILR topics (NIS 2 governance, risk analysis, incident notification, supply chain). See an example of an annual cyber awareness training program.
  • Traceability: decision logs, agendas and minutes evidencing approval (Art. 20); risk dashboards, compliance KPIs (Art. 21), and training records.
  • Governance fines risk: lack of ownership (no minutes, no tracked remediation, no training) = non‑compliance regardless of technical controls. For the local context, see NIS 2 in Luxembourg and ILR. For group alignment, managed cyber leadership by an external CISO can help.

Typical use cases

  • Banks, PSFs, asset managers, insurers (DORA/NIS 2 overlap): board approval of critical dependency mapping and crisis exercises; auditors and the CSSF verify governance evidence against ICT risks.
  • Energy, health, transport, water, public sector: validation of risk analysis, inventory of critical assets, continuity plan and detection strategy; NIS 2 training; oversight of SERIMA notifications (24h / 72h / 1 month).
  • Cross-border groups: harmonise minutes, policies and KPIs to anticipate parallel checks; ILR provides guides and an eligibility simulator.

Common pitfalls

  • Mistaking information for traceable approval: without minutes or formal decisions, evidence is missing (Art. 20). Article 20 – EUR‑Lex.
  • Delegating to the CISO alone: ILR requires leaders’ “active and demonstrable engagement” and continuous training. ILR, Guidelines (p. 1).
  • Overlooking the supply chain: Art. 21 mandates supplier risk management; the board should require a supplier onboarding policy and measurable third‑party controls. Article 21 – EUR‑Lex.
  • Underestimating training: obligations cover leaders and staff; no program, misaligned content, or poor evidence = non‑compliance. ILR – publication page.
  • Ignoring “defective governance” sanctions: high fine thresholds and potential compliance orders. Commission FAQ – Sanctions and Government/ILR release.

Official sources

  • ILR – NIS 2 Guidelines – Governing Bodies: page and PDF
  • Directive (EU) 2022/2555 – Arts. 20 and 21: EUR‑Lex and EUR‑Lex
  • European Commission – NIS 2 FAQ (sanctions): link
  • Luxembourg Government – Law overview (06/07/2026): link
  • NIM file – Law of 05/05/2026: link
  • Commission Communication (Art. 4 NIS 2): link
  • ILR – Eligibility simulator: link

In practice, Luxembourg leadership must treat cybersecurity as a board competence: set risk appetite, approve an Art. 21 measures plan, require KPIs, undertake training — and evidence all of it. For the local framework, see the NIS 2 directive and obligations.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

How Luxgap can help

External CISO

Appoint us as your information security officer: we take operational ownership of policy, governance, risk, audits and incidents, with NIS 2 or DORA where they apply.

See the CISO mandate
LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →