NIS 2 in Luxembourg: what ILR really expects under Article 21
ILR clarifies board duties and expected controls for NIS 2 Article 21, aligned with Implementing Regulation (EU) 2024/2690 and Luxembourg’s 5 May 2026 law.
NIS 2 in Luxembourg: what ILR really expects from Article 21’s “10 measures”
Verifiable fact: on 17 February 2026, ILR published “Guidelines NIS2 – Governing bodies” clarifying approval and oversight of the risk-management measures under NIS 2 Article 21. Controls are also aligned with Implementing Regulation (EU) 2024/2690.
The situation
On 17 February 2026, the Institut Luxembourgeois de Régulation (ILR) released “Guidelines NIS2 – Organes de direction” (version 17/02/2026) detailing the role of governing bodies in implementing and overseeing the risk-management measures required by NIS 2 Article 21. Boards must “approve cybersecurity risk-management measures and supervise their implementation,” and “undertake necessary training” to assess practices and their impact on services. ILR also reiterates the duty to organise incident notification. Source: ILR, Guidelines NIS2 – Governing bodies (17/02/2026). See the official PDF. ILR, Guidelines NIS2 – Governing bodies (ilr.lu).
In the same vein, ILR maintains a “NIS 2 Security Measures” page reflecting Article 21’s core: essential and important entities must implement “appropriate and proportionate” technical, operational and organisational measures to manage risks and minimise incident impacts. The page refers to the national law of 5 May 2026 (NIS 2 transposition) and the NISS supervisory scope. ILR – NIS 2 Security Measures (ilr.lu).
At EU level, Implementing Regulation (EU) 2024/2690 of 17 October 2024 sets technical and methodological requirements for risk-management measures and defines when an incident is “significant” for certain providers (cloud, data centres, managed services, etc.). It is the core reference supporting national supervision. EUR-Lex – Implementing Regulation (EU) 2024/2690 (eur-lex.europa.eu).
For a practical overview in Luxembourg, see our NIS 2 in Luxembourg and ILR’s role page, and consider governance support via an outsourced CISO to steer cybersecurity.
Legal reasoning
- Foundation: Directive (EU) 2022/2555 (NIS 2) – Article 21(1) – requires “appropriate and proportionate technical, operational and organisational measures” to manage risks to network and information systems and to prevent/reduce the impact of incidents on service recipients. ILR mirrors this wording on its reference pages. ILR – NIS 2 Security Measures (excerpt reflecting Art. 21(1)).
- Governance: Article 20 of NIS 2 assigns governing bodies the approval and oversight of risk-management measures and mandates their training. ILR formalises these expectations: directors must “validate risk assessment results and remediation plans” and “ensure incident notification duties are met.” ILR, Guidelines NIS2 – Governing bodies.
- Technical specifics: Implementing Regulation (EU) 2024/2690 provides criteria and methods: it frames risk management, detection, vulnerability handling, authentication, logging, incident response and continuity — and clarifies, for certain sectors, when an incident is “significant.” EUR-Lex – 2024/2690.
- National framework: Luxembourg’s law of 5 May 2026 on a high level of cybersecurity (NIS 2 transposition) enters into force in 2026; ILR confirms supervision (NISS service) and publishes resources on measures and notification. ILR – Entry into force of the 5 May 2026 law.
Conclusion: in Luxembourg, ILR relies on NIS 2 Art. 21, the 5 May 2026 law, and Regulation (EU) 2024/2690. Boards must evidence effective “approval” and “oversight,” not just a cybersecurity budget.
What this changes in practice
- The “appropriate and proportionate” test becomes demonstrable. A control plan not tied to an up-to-date risk analysis will not suffice. ILR expects proof: critical asset inventory, risk scenarios, chosen measures and proportionality rationale. ILR – NIS 2 Security Measures.
- Boards/executive committees must attest their involvement: agendas, formal approvals of measures and remediation plans, security KPI/KRI monitoring, and NIS 2 training attestations for directors. ILR, Guidelines NIS2 – Governing bodies.
- Minimum measures translate into concrete controls ILR may verify:
- Asset and risk management: central inventory (CMDB or equivalent), supplier dependency mapping, periodic risk reviews, and supply-chain integration in assessments. ILR – “6 fundamental security measures”.
- Hardening and segmentation: secure configuration, MFA, encryption, network segmentation, logging and detection. ILR – 6 measures.
- Vulnerability and patch management: risk-based patching, pre-production testing, vendor advisories tracking. ILR – 6 measures.
- Continuity/BCM and incident response: tested backups, escalation playbooks, crisis directory, and channels to notify ILR within legal deadlines. ILR – 6 measures and ILR notification pages.
- Awareness/training: annual programme, effectiveness measurement (phishing simulations, quizzes), board training. ILR – 6 measures and Guidelines.
To reach auditable execution, a cybersecurity audit to prepare for NIS 2 helps structure evidence, gaps and remediation, while a robust business continuity and DRP addresses continuity and notification duties.
Examples
Example 1 (industry/OT): for an important-entity SME in industry, ILR will expect a unified OT/IT inventory, VLANs separating PLCs, MFA for remote maintenance access, a risk-based OT patch cycle, and continuity plans tested on a pilot cell.
Example 2 (managed services/MSP in Luxembourg): if you provide managed or managed security services, 2024/2690 also sets “significant incident” criteria. You must track client dependencies, logs and remediation SLAs, and be able to trigger ILR notification once relevant thresholds are crossed. EUR-Lex – 2024/2690.
Common pitfalls
- Controls without an up-to-date risk analysis. Deploying EDR/MFA/backups is not enough if proportionality is not justified against scenario-based risks. ILR expects board validation of assessment results and remediation plans. ILR – Guidelines, §§1–2.
- Poor inventory and supplier blind spots. “Outsourced assets” and the supply chain must be included in risk and update management. ILR – 6 measures, lines 9–13 and 41–47.
- “Best-effort” patching. 2024/2690 expects tooled processes, pre-prod testing and criticality-based prioritisation. A non-executed policy is non-compliant. EUR-Lex – 2024/2690.
- Untested continuity. Backups without tested restore and without crisis exercises do not meet ILR expectations. ILR – 6 measures, lines 36–40.
- “Paper” governance. Lack of director training, formal approvals of measures, and cyber dashboards is a gap against Article 20 and ILR Guidelines. ILR – Guidelines, §§1 and 4.
Official sources
- ILR – Guidelines NIS2 – Governing bodies (Version 17/02/2026)
- ILR – NIS 2 Security Measures
- ILR – NIS 2 Incident Notification
- EUR-Lex – Implementing Regulation (EU) 2024/2690
- ILR – Entry into force of the 5 May 2026 law
- ILR – 6 fundamental security measures
If you cannot show formal board approval and the linkage between documented risks and proportionate measures, you will struggle during supervision. ILR has set the markers: traceable governance, justified measures, and verifiable execution. For a compliance overview, see our NIS 2 obligations and compliance.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →