Recital 101

Recital 101

Directive on the security of network and information systems · UE 2022/2555

(101)

This Directive lays down a multiple-stage approach to the reporting of significant incidents in order to strike the right balance between, on the one hand, swift reporting that helps mitigate the potential spread of significant incidents and allows essential and important entities to seek assistance, and, on the other, in-depth reporting that draws valuable lessons from individual incidents and improves over time the cyber resilience of individual entities and entire sectors. In that regard, this Directive should include the reporting of incidents that, based on an initial assessment carried out by the entity concerned, could cause severe operational disruption of the services or financial loss for that entity or affect other natural or legal persons by causing considerable material or non-material damage. Such initial assessment should take into account, inter alia, the affected network and information systems, in particular their importance in the provision of the entity’s services, the severity and technical characteristics of a cyber threat and any underlying vulnerabilities that are being exploited as well as the entity’s experience with similar incidents. Indicators such as the extent to which the functioning of the service is affected, the duration of an incident or the number of affected recipients of services could play an important role in identifying whether the operational disruption of the service is severe.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) assigns to the ILR the reception of significant incident notifications. The ILR notification portal requires the 24h early warning, the 72h detailed notification and the 1-month final report, in line with Article 23 NIS 2. The initial assessment foreseen by recital 101 must be retained even for non-notified incidents: the ILR may request it during an inspection to verify that the incident qualification was reasoned.

Luxgap practice: maintain a threshold matrix approved by your executive board, integrated into your SIEM, and keep the timestamp of every initial assessment for at least 5 years to cover the limitation period of ILR sanctions.