← All articles

consultant

NIS 2 in Luxembourg: what ILR really expects under Article 21

ILR clarifies board duties and expected controls for NIS 2 Article 21, aligned with Implementing Regulation (EU) 2024/2690 and Luxembourg’s 5 May 2026 law.

NIS 2 in Luxembourg: what ILR really expects from Article 21’s “10 measures”

Verifiable fact: on 17 February 2026, ILR published “Guidelines NIS2 – Governing bodies” clarifying approval and oversight of the risk-management measures under NIS 2 Article 21. Controls are also aligned with Implementing Regulation (EU) 2024/2690.

The situation

On 17 February 2026, the Institut Luxembourgeois de Régulation (ILR) released “Guidelines NIS2 – Organes de direction” (version 17/02/2026) detailing the role of governing bodies in implementing and overseeing the risk-management measures required by NIS 2 Article 21. Boards must “approve cybersecurity risk-management measures and supervise their implementation,” and “undertake necessary training” to assess practices and their impact on services. ILR also reiterates the duty to organise incident notification. Source: ILR, Guidelines NIS2 – Governing bodies (17/02/2026). See the official PDF. ILR, Guidelines NIS2 – Governing bodies (ilr.lu).

In the same vein, ILR maintains a “NIS 2 Security Measures” page reflecting Article 21’s core: essential and important entities must implement “appropriate and proportionate” technical, operational and organisational measures to manage risks and minimise incident impacts. The page refers to the national law of 5 May 2026 (NIS 2 transposition) and the NISS supervisory scope. ILR – NIS 2 Security Measures (ilr.lu).

At EU level, Implementing Regulation (EU) 2024/2690 of 17 October 2024 sets technical and methodological requirements for risk-management measures and defines when an incident is “significant” for certain providers (cloud, data centres, managed services, etc.). It is the core reference supporting national supervision. EUR-Lex – Implementing Regulation (EU) 2024/2690 (eur-lex.europa.eu).

For a practical overview in Luxembourg, see our NIS 2 in Luxembourg and ILR’s role page, and consider governance support via an outsourced CISO to steer cybersecurity.

Legal reasoning

  • Foundation: Directive (EU) 2022/2555 (NIS 2) – Article 21(1) – requires “appropriate and proportionate technical, operational and organisational measures” to manage risks to network and information systems and to prevent/reduce the impact of incidents on service recipients. ILR mirrors this wording on its reference pages. ILR – NIS 2 Security Measures (excerpt reflecting Art. 21(1)).
  • Governance: Article 20 of NIS 2 assigns governing bodies the approval and oversight of risk-management measures and mandates their training. ILR formalises these expectations: directors must “validate risk assessment results and remediation plans” and “ensure incident notification duties are met.” ILR, Guidelines NIS2 – Governing bodies.
  • Technical specifics: Implementing Regulation (EU) 2024/2690 provides criteria and methods: it frames risk management, detection, vulnerability handling, authentication, logging, incident response and continuity — and clarifies, for certain sectors, when an incident is “significant.” EUR-Lex – 2024/2690.
  • National framework: Luxembourg’s law of 5 May 2026 on a high level of cybersecurity (NIS 2 transposition) enters into force in 2026; ILR confirms supervision (NISS service) and publishes resources on measures and notification. ILR – Entry into force of the 5 May 2026 law.

Conclusion: in Luxembourg, ILR relies on NIS 2 Art. 21, the 5 May 2026 law, and Regulation (EU) 2024/2690. Boards must evidence effective “approval” and “oversight,” not just a cybersecurity budget.

What this changes in practice

  • The “appropriate and proportionate” test becomes demonstrable. A control plan not tied to an up-to-date risk analysis will not suffice. ILR expects proof: critical asset inventory, risk scenarios, chosen measures and proportionality rationale. ILR – NIS 2 Security Measures.
  • Boards/executive committees must attest their involvement: agendas, formal approvals of measures and remediation plans, security KPI/KRI monitoring, and NIS 2 training attestations for directors. ILR, Guidelines NIS2 – Governing bodies.
  • Minimum measures translate into concrete controls ILR may verify:
    • Asset and risk management: central inventory (CMDB or equivalent), supplier dependency mapping, periodic risk reviews, and supply-chain integration in assessments. ILR – “6 fundamental security measures”.
    • Hardening and segmentation: secure configuration, MFA, encryption, network segmentation, logging and detection. ILR – 6 measures.
    • Vulnerability and patch management: risk-based patching, pre-production testing, vendor advisories tracking. ILR – 6 measures.
    • Continuity/BCM and incident response: tested backups, escalation playbooks, crisis directory, and channels to notify ILR within legal deadlines. ILR – 6 measures and ILR notification pages.
    • Awareness/training: annual programme, effectiveness measurement (phishing simulations, quizzes), board training. ILR – 6 measures and Guidelines.

To reach auditable execution, a cybersecurity audit to prepare for NIS 2 helps structure evidence, gaps and remediation, while a robust business continuity and DRP addresses continuity and notification duties.

Examples

Example 1 (industry/OT): for an important-entity SME in industry, ILR will expect a unified OT/IT inventory, VLANs separating PLCs, MFA for remote maintenance access, a risk-based OT patch cycle, and continuity plans tested on a pilot cell.

Example 2 (managed services/MSP in Luxembourg): if you provide managed or managed security services, 2024/2690 also sets “significant incident” criteria. You must track client dependencies, logs and remediation SLAs, and be able to trigger ILR notification once relevant thresholds are crossed. EUR-Lex – 2024/2690.

Common pitfalls

  1. Controls without an up-to-date risk analysis. Deploying EDR/MFA/backups is not enough if proportionality is not justified against scenario-based risks. ILR expects board validation of assessment results and remediation plans. ILR – Guidelines, §§1–2.
  2. Poor inventory and supplier blind spots. “Outsourced assets” and the supply chain must be included in risk and update management. ILR – 6 measures, lines 9–13 and 41–47.
  3. “Best-effort” patching. 2024/2690 expects tooled processes, pre-prod testing and criticality-based prioritisation. A non-executed policy is non-compliant. EUR-Lex – 2024/2690.
  4. Untested continuity. Backups without tested restore and without crisis exercises do not meet ILR expectations. ILR – 6 measures, lines 36–40.
  5. “Paper” governance. Lack of director training, formal approvals of measures, and cyber dashboards is a gap against Article 20 and ILR Guidelines. ILR – Guidelines, §§1 and 4.

Official sources

If you cannot show formal board approval and the linkage between documented risks and proportionate measures, you will struggle during supervision. ILR has set the markers: traceable governance, justified measures, and verifiable execution. For a compliance overview, see our NIS 2 obligations and compliance.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →