← All articles

consultant

NIS 2 vs DORA in Luxembourg: notify in 24 h or 4 h?

Verifiable fact: CSSF Circular 25/893 (27/05/2025) aligns DORA reporting with a first notification “within 4 hours” after classification. NIS 2 requires a preliminary alert “within 24 hours.” Key issue: who to notify, when, and against which clock in Luxembourg.

Verifiable fact — On 27 May 2025, the CSSF issued Circular 25/893 aligning DORA reporting, with a first notification “within 4 hours” after classification; NIS 2 requires a preliminary alert “within 24 hours.” The key issue in Luxembourg is who to notify, when, and under which clock. (cssf.lu)

The case

On 27 May 2025, the CSSF published Circular CSSF 25/893 “on reporting of major ICT-related incidents and significant cyber threats under DORA.” This circular requires financial entities under DORA to follow the timelines set in EU delegated/implementing acts: a first notification within 4 hours after classifying the incident as “major,” interim reports within 72 hours, then a final report using the standard templates. (cssf.lu)

At EU level, Directive (EU) 2022/2555 (NIS 2) sets a different scheme: an early warning without undue delay and in any event within 24 hours from becoming aware of a “significant” incident, a notification within 72 hours, and a final report within one month. These obligations are set out in Article 23(4)(a)–(d). (eur-lex.europa.eu)

EU law resolved how these frameworks interact: Regulation (EU) 2022/2554 (DORA) is lex specialis vis‑à‑vis NIS 2 for the financial sector; NIS 2 itself defers to sectoral acts that are “at least equivalent” (Article 4). The Commission reiterated this in its guidance on Article 4 of NIS 2. (eur-lex.europa.eu)

In Luxembourg, NIS 2 is transposed by the law of 5 May 2026, with ILR as the competent authority for many sectors, while the CSSF remains the competent authority for banking, certain market infrastructures and supervised activities. (ilr.lu)

Legal reasoning

  • NIS 2 basis. Article 23 of Directive (EU) 2022/2555 structures reporting in three steps: preliminary alert ≤ 24 h after awareness, notification ≤ 72 h, final report ≤ 1 month. The “significant incident” test combines operational/financial severity and impact on other persons (Art. 23(3)). (eur-lex.europa.eu)
  • DORA basis. Articles 18–20 of DORA (Regulation (EU) 2022/2554) establish reporting of “major ICT-related incidents” to financial competent authorities. Delegated/technical acts set the timelines: Delegated Regulation (EU) 2025/301 requires the first notification “within 4 hours” from classification as major (with safeguards for weekends/public holidays), an interim report within 72 h after the first notification, then a final report; Implementing Regulation (EU) 2025/302 prescribes templates and procedures. CSSF Circular 25/893 makes these timelines and formats applicable via eDesk. (eur-lex.europa.eu)
  • Lex specialis articulation. DORA’s recitals and provisions qualify it as lex specialis to NIS 2 for financial entities; correspondingly, NIS 2 Article 4 provides that where a sectoral act imposes at least equivalent measures/reporting, NIS 2 obligations (including supervision/sanctions) do not apply. The Commission’s guidance on Article 4 confirms DORA as the relevant sectoral act. (eur-lex.europa.eu)
  • Potential “cross” notifications. DORA leaves room for Member States to decide that some or all financial entities also transmit the initial notification and reports to NIS 2 CSIRTs/authorities “using the templates” under NIS 2 (Art. 19(1), second subparagraph). This means a dual addressee (financial authority + NIS 2 CSIRT) may be required for national coordination. (eur-lex.europa.eu)

Practical consequence in Luxembourg: for DORA financial entities, the CSSF prevails for content, formats and the clock (4 h after classification). For NIS 2 entities outside DORA (e.g., health, industry, public administrations, certain B2B ICT providers), ILR supervises the 24 h / 72 h / 1 month scheme. The key is to correctly identify your scope and competent authority. (ilr.lu)

What it changes in practice

  • Banks, PSFs, asset managers, insurers, payment/e-money institutions in DORA scope: your reporting clock runs in two stages. First, classify the incident against DORA criteria; once it is “major,” the first notification must be sent within 4 hours via CSSF eDesk, then an interim report at +72 h (after the first notification) and a final per the ITS. Plan for near‑real‑time classification and a 24/7 notification team. See DORA in Luxembourg and strengthen your DORA operational resilience. (cssf.lu)
  • NIS 2 entities outside DORA (energy, health, water, transport, public sector, etc.): you follow Article 23 NIS 2 with a preliminary alert ≤ 24 h from awareness, notification ≤ 72 h, then a final report ≤ 1 month, under ILR (or the designated sectoral authority). The early warning can be brief; the aim is to trigger CSIRT support quickly. Learn more about NIS 2 in Luxembourg. (eur-lex.europa.eu)
  • Dual applicability? The lex specialis principle prevents double application of material rules. However, watch for national decisions that, in addition to DORA filings, require transmission to the NIS 2 CSIRT using Article 20 NIS 2 templates (enabled by DORA Art. 19(1), second subparagraph). Proactively map channels and internal roles (who reports what, to whom, when). (eur-lex.europa.eu)
  • Governance and accountability. Management bodies must approve and oversee cybersecurity measures (NIS 2) and the operational resilience framework (DORA). In Luxembourg, the CSSF has in parallel tightened governance/risk requirements (Circular 26/906 for payment/e-money institutions) with a compliance deadline of 30 June 2026: DORA–NIS 2 alignment should be led at executive level. (cssf.lu)

Common pitfalls

  1. Confusing “awareness” and “classification”. Under NIS 2, the trigger is becoming aware of a significant incident (≤ 24 h). Under DORA, the 4 h clock starts upon classification as “major.” Without a tooled triage/qualification process, the DORA clock may start too late… or too early. (eur-lex.europa.eu)
  2. Forgetting the weekend/public‑holiday exception in the DORA delegated act or, conversely, assuming it applies to NIS 2. This relief exists only in the DORA package (2025/301). (eur-lex.europa.eu)
  3. Multiplying filings and templates. Circular 25/893 mandates DORA forms via eDesk; NIS 2 has its own templates. Without a unified playbook, messages get blurred and mandatory fields are missed. (cssf.lu)
  4. Overlooking the national “CSIRT copy” option under DORA. Even though DORA is lex specialis, Article 19(1) allows Member States to require sending notifications to NIS 2 CSIRTs/authorities. Anticipate this potential requirement in your flows. (eur-lex.europa.eu)
  5. Underestimating traceability. Both DORA and NIS 2 require quickly reconstructing chronology, IOCs and response measures. Without tooled logging and configured “incident notifier” roles (eDesk), the 4 h/24 h deadlines become untenable. (cssf.lu)

Official sources

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →