← All articles

consultant

NIS 2 in Luxembourg: scope, categories and self‑registration

Luxembourg’s law of 5 May 2026 transposing NIS 2 has been in force since 10 May 2026. The ILR clarifies scope, the “essential/important entity” categorization, and self‑registration.

Verifiable fact — Luxembourg’s law of 5 May 2026 transposing NIS 2 entered into force on 10 May 2026. The ILR provides dedicated pages clarifying scope, the “essential/important entity” categorization, and self‑registration. Here is the operational mapping.

For a local, hands‑on overview, see our page on NIS 2 in Luxembourg and the ILR’s role.

The case

On 15 May 2026, the ILR announced that the “law of 5 May 2026 on measures to ensure a high level of cybersecurity (NIS 2)” took effect on 10 May 2026, with pointers to its dedicated NIS 2 section. That section details what is new, including the harmonized definition of covered entities, accountability of management bodies, and self‑registration with the ILR. Sources: ILR “Entry into force” (15/05/2026) and ILR’s NIS 2 page. See ILR “Entry into force of the Law of 5 May 2026” and “NIS 2 – ILR”. ILR, 15 May 2026 ILR, NIS 2 section.

At EU level, Directive (EU) 2022/2555 (“NIS 2”) sets the scope logic: by default, “medium” and “large” enterprises in the sectors of Annex I (high criticality) and Annex II (other critical sectors) fall under NIS 2, with a categorization as “essential entities” (Annex I) or “important entities” (Annex II). See the official text on EUR‑Lex: official text.

Finally, the EUR‑Lex “national information notification” fiche lists Luxembourg’s law of 5 May 2026 as a transposition instrument: NIM fiche.

Legal reasoning

  • EU basis. NIS 2 (Art. 2(1) and 2(2)) relies on size: by default, “medium and large entities” as per Recommendation 2003/361/EC (≥ 50 employees and ≥ €10m turnover/balance sheet for “medium”, higher thresholds for “large”) are covered when operating in an Annex I or II sector. The annexes list, by sector/sub‑sector/entity‑type, the activities in scope (electricity, drinking water, health, banking, cloud, data centres, DNS/TLD, etc.). Text: Directive (EU) 2022/2555 and Annexes I/II (EUR‑Lex) — link.
  • Essential/important categorization. The directive distinguishes “essential entities” (Annex I) and “important entities” (Annex II), which affects supervision and, at times, the intensity of checks — text.
  • Luxembourg: transposition and ILR clarifications. The ILR notes: (1) NIS 2 was transposed by the law of 5 May 2026; (2) the law entered into force on 10 May 2026; (3) entities must self‑register with the competent authority; (4) risk management measures apply to all networks and information systems supporting the entity’s activities. Details: ILR NIS 2 page.
  • Sectoral implementation method. For digital actors (digital infrastructure, managed ICT services, Annex II digital providers), ENISA published the “NIS2 Technical Implementation Guidance” (2025) mapping Article 21 measures to concrete controls (MFA, hardening, dependency management) — ENISA guidance.

What changes in practice

1) Who falls in scope in Luxembourg?

By default: any “medium” or “large” entity active in an Annex I/II sector is covered.

  • Annex I (essential): electricity, drinking water, healthcare providers, banks, financial market infrastructures, wastewater, transport (air, rail, road, maritime), digital infrastructure (IXPs, DNS, TLDs, cloud, data centres, CDNs, trust services), public administration, space.
  • Annex II (important): postal/courier, waste management, chemicals, food, manufacturing (electrical equipment, optics, machinery, vehicles…), digital providers (online marketplaces, search engines, social networks).

Basis: Annexes I/II of Directive (EU) 2022/2555 — reference version and annexes.

2) Size thresholds (principle)

“Medium/large” is assessed against Recommendation 2003/361/EC (headcount and financials), used by the ILR for scope analysis. In practice: ≥ 50 FTE and ≥ €10m (turnover or balance sheet) for “medium”; above for “large”. Reference: Directive (EU) 2022/2555 Art. 2 and ILR reminders — text, ILR.

3) Small/micro exceptions still covered

Certain small/micro entities can be included if they provide critical services (e.g., DNS/TLD operators, qualified trust service providers) or if they are the sole provider in a Member State for a given service. See Art. 2(2) and annexes — EUR‑Lex.

4) Steps in Luxembourg

  1. Check your sector/sub‑sector against Annexes I/II.
  2. Apply the 2003/361/EC size test.
  3. Determine “essential” (Annex I) vs “important” (Annex II).
  4. Complete ILR self‑registration and provide security contact details — ILR NIS 2 section.

5) Practical effects of categorization

  • Security measures (Art. 21 NIS 2). Apply to the entire IT/OT supporting the activity, not only “essential services” (per ILR).
  • Governance. Management bodies’ accountability and training (ILR).
  • Incident reporting. 24h/72h/1‑month staging aligned with the EU framework; ILR maintains forms: Incident notification – ILR.

Concrete examples (Luxembourg and cross‑border)

  • A Luxembourg cloud host operating a data centre with >50 FTE falls under “Digital infrastructure” (Annex I): essential entity; self‑registration and Art. 21 measures across the estate. Basis: Annex I and ILR — EUR‑Lex.
  • A manufacturer of electronic components (NACE 26) in the Greater Region with 120 FTE supplying Luxembourg falls under Annex II manufacturing: important entity; Art. 21 obligations (supply‑chain, MFA, logging) and ILR notification if significant impact. Basis: Annex II; ILR notification.
  • A DNS operator acting as the “.lu” TLD remains in scope even if small: inclusion by critical entity type listed in Annex I — text.

Common pitfalls

  1. Limiting to “essential systems”. ILR clarifies measures apply to all networks and IS supporting the activity (incl. HR, finance, M365, ERP). ILR source. To baseline controls across the scope, consider a cybersecurity audit.
  2. Misclassifying the sector. Annexes detail sub‑sectors (health, transport, digital: DNS/TLD, data centres). Wrong mapping shifts the category (essential vs important) — Annexes I/II.
  3. Ignoring critical small/micro exceptions. Some entities are still in scope due to their service type. Check Art. 2(2) — text.
  4. Skipping self‑registration and points of contact. ILR requires NIS 2 self‑registration; unclear contacts delay incident handling and risk sanctions — ILR page. For governance and roadmap, see our overview of NIS 2 obligations and consider virtual CISO oversight.
  5. Implementing controls without evidence. ENISA advises traceable implementation mapped to Art. 21 (MFA, inventory, hardening, supply chain) — ENISA guide.

Official sources

In summary, since 10 May 2026, the “sector (Annexes I/II) + 2003/361/EC size + critical exceptions” test governs NIS 2 inclusion in Luxembourg. The ILR provides the compliance milestones (self‑registration, scope, transversal security measures), while the EU text and ENISA guides help objectify mapping and the roadmap.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →