Recital 102

Recital 102

Directive on the security of network and information systems · UE 2022/2555

(102)

Where essential or important entities become aware of a significant incident, they should be required to submit an early warning without undue delay and in any event within 24 hours. That early warning should be followed by an incident notification. The entities concerned should submit an incident notification without undue delay and in any event within 72 hours of becoming aware of the significant incident, with the aim, in particular, of updating information submitted through the early warning and indicating an initial assessment of the significant incident, including its severity and impact, as well as indicators of compromise, where available. A final report should be submitted not later than one month after the incident notification. The early warning should only include the information necessary to make the CSIRT, or where applicable the competent authority, aware of the significant incident and allow the entity concerned to seek assistance, if required. Such early warning, where applicable, should indicate whether the significant incident is suspected of being caused by unlawful or malicious acts, and whether it is likely to have a cross-border impact. Member States should ensure that the obligation to submit that early warning, or the subsequent incident notification, does not divert the notifying entity’s resources from activities related to incident handling that should be prioritised, in order to prevent incident reporting obligations from either diverting resources from significant incident response handling or otherwise compromising the entity’s efforts in that respect. In the event of an ongoing incident at the time of the submission of the final report, Member States should ensure that entities concerned provide a progress report at that time, and a final report within one month of their handling of the significant incident.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite (modifiee par la loi du 28 juillet 2025)

In Luxembourg, the recipient authority for early warnings and incident notifications is the ILR (Institut Luxembourgeois de Regulation), via the national CSIRT (CIRCL for the private sector, GOVCERT for the public sector). The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, transposes the 24h/72h/1 month deadlines without modulation: essential and important entities designated by ILR must strictly follow recital 102's timeline, under penalty of administrative sanctions up to 10 M EUR or 2% of worldwide turnover.

Luxgap practice: we configure your Incident Clock with the official ILR notification portal webhook and the CIRCL/MISP alert format, for native submission without re-entry.