Recital 1
Directive on the security of network and information systems · UE 2022/2555
| (1) | Directive (EU) 2016/1148 of the European Parliament and the Council (4) aimed to build cybersecurity capabilities across the Union, mitigate threats to network and information systems used to provide essential services in key sectors and ensure the continuity of such services when facing incidents, thus contributing to the Union’s security and to the effective functioning of its economy and society. |
In Luxembourg, the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, transposes NIS 2 and designates the ILR as the single competent authority for entity registration, incident notification, inspections and administrative sanctions. The continuity referenced in recital 1 concretely translates into the obligation for every essential or important entity to register with the ILR and demonstrate implementation of the 10 measures of article 21.
Luxgap practice: do not assume your status, have eligibility settled through an ILR-defensible file before the next inspection wave, especially if you were out of scope under NIS 1.