NIS 2 · DORA · ISO 27001 mandate
Outsourced CISO in Luxembourg.
Looking for a CISO in Luxembourg? Luxgap provides an outsourced CISO to run your cybersecurity, your NIS 2/DORA compliance and your ISO 27001 certification. An integrated team of cyber engineers + lawyers, with a regular on-site presence in Kirchberg/Esch/Capellen.
Why outsource the CISO role rather than hire one?
Hiring a senior CISO in Luxembourg takes 9-12 months and costs 150 to 200 k EUR fully loaded. For an SME or mid-sized company with fewer than 500 staff, that is rarely justifiable. Our outsourced mandate gives you access to a senior engineer + their team (lawyers, pentesters, developers) for a fraction of the cost, with real continuity of service (no single-person resignation risk).
The other benefit: independence from IT vendors. We resell neither Microsoft, nor Cisco, nor Palo Alto. Our recommendations are not biased by a commercial partnership.
The other benefit: independence from IT vendors. We resell neither Microsoft, nor Cisco, nor Palo Alto. Our recommendations are not biased by a commercial partnership.
What does a Luxgap CISO actually do?
Security policy aligned with ISO 27001/NIS 2/DORA. Cyber risk mapping with a criticality matrix. Risk treatment plan (technical + organisational measures). Incident reporting to the authorities (ILR within 24h for NIS 2, CSSF for DORA). Supply chain audit: assessment of critical suppliers. Monthly security committee governance with the executive committee. Awareness for management + IT teams + users. Regulatory watch CSSF/ILR/HCPN/ENISA.
Build a CISO mandate →
Build a CISO mandate →
Which sectors are affected in Luxembourg?
Financial sector (banks, PSF, funds, insurers): DORA since January 2025 + CSSF circulars 22/806, 24/847. NIS 2 essential entities: energy, transport, health, digital infrastructure, public administration. NIS 2 important entities: industry, research, e-commerce, postal services. Health sector: heightened GDPR requirements + medical ISO 27001. Industry: ISO 27001 required by international clients.
What CISO mandate models are available?
Essential (SMEs, 50-150 staff): 1 day/month + on-call incident support, governance, policy, annual audit.
Standard (150-500 staff): 2-3 days/month, quarterly executive committee, incident handling, half-yearly audit, roadmap management.
Premium (500+ or sensitive sector): 5+ days/month, dedicated team, direct integration into the executive committee, continuous audit, supply chain.
Quote-based pricing, calibrated to your actual scope.
Standard (150-500 staff): 2-3 days/month, quarterly executive committee, incident handling, half-yearly audit, roadmap management.
Premium (500+ or sensitive sector): 5+ days/month, dedicated team, direct integration into the executive committee, continuous audit, supply chain.
Quote-based pricing, calibrated to your actual scope.
Let's talk about your situation.
Quote within 24 business hours. No commitment, no sales pressure.