NIS 2, the EU cybersecurity directive 2022/2555.
NIS 2 (EU directive 2022/2555) replaces the 2016 NIS directive and significantly broadens the scope of organisations subject to cyber obligations. Transposed in Luxembourg in 2024, it has been applicable since 17 October 2024. What does it change for you?
Law contents
All 46 articles, in the order of the official text. Each one is analysed separately, with the official text and Luxgap practical guidance.
- 1. Subject matter
- 2. Scope
- 3. Essential and important entities
- 4. Sector-specific Union legal acts
- 5. Minimum harmonisation
- 6. Definitions
- 7. National cybersecurity strategy
- 8. Competent authorities and single points of contact
- 9. National cyber crisis management frameworks
- 10. Computer security incident response teams (CSIRTs)
- 11. Requirements, technical capabilities and tasks of CSIRTs
- 12. Coordinated vulnerability disclosure and a European vulnerability database
- 13. Cooperation at national level
- 14. Cooperation Group
- 15. CSIRTs network
- 16. European cyber crisis liaison organisation network (EU-CyCLONe)
- 17. International cooperation
- 18. Report on the state of cybersecurity in the Union
- 19. Peer reviews
- 20. Governance
- 21. Cybersecurity risk-management measures
- 22. Union level coordinated security risk assessments of critical supply chains
- 23. Reporting obligations
- 24. Use of European cybersecurity certification schemes
- 25. Standardisation
- 26. Jurisdiction and territoriality
- 27. Registry of entities
- 28. Database of domain name registration data
- 29. Cybersecurity information-sharing arrangements
- 30. Voluntary notification of relevant information
- 31. General aspects concerning supervision and enforcement
- 32. Supervisory and enforcement measures in relation to essential entities
- 33. Supervisory and enforcement measures in relation to important entities
- 34. General conditions for imposing administrative fines on essential and important entities
- 35. Infringements entailing a personal data breach
- 36. Penalties
- 37. Mutual assistance
Annexes
Who is concerned?
NIS 2 distinguishes two catégories: essential entities (EE) and important entities (IE), based on sector and size. Highly critical sectors include energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, B2B ICT management, public administration, space.
The Luxembourg ILR and ANSSI Lux have been designated as supervisory authorities.
Key obligations
- Technical and organisational measures (Article 21): security policy, risk management, incident handling, business continuity, supply chain security, acquisition and development security, effectiveness assessment, cyber training, cryptography, identity management, secure communications.
- Incident notification (Article 23): early warning within 24 h, incident notification within 72 h, final report within 1 month.
- Management governance and liability (Article 20): leadership approves measures, oversees implementation, and is personally liable in case of demonstrated failure.
Deadlines
The Luxembourg law of 28 July 2023 on cybersecurity transposes NIS 2 and has applied since 17 October 2024. It was amended by the law of 28 July 2025 to align thresholds, clarify sanctions and tighten the management accountability chain. All concerned entities must already be compliant. ILR inspections began in 2025.
Sanctions for non-compliance
Administrative sanctions: up to €10 million or 2% of worldwide turnover for essential entities; €7 million or 1.4% for important entities. The directive provides for personal liability of executives: temporary disqualification from management duties.
How Luxgap helps
Our external CISO mandate covers the full NIS 2 requirements. For organisations unsure whether they are concerned, we offer a NIS 2 eligibility diagnosis within 5 business days.
Let's set up your NIS 2 compliance.
Configure a quote for a CISO mandate or a targeted NIS 2 audit. Reply within one business day.
Build my quote →