Recital 104

Recital 104

Directive on the security of network and information systems · UE 2022/2555

(104)

Providers of public electronic communications networks or of publicly available electronic communications services should implement security by design and by default, and inform their service recipients of significant cyber threats and of measures they can take to protect the security of their devices and communications, for example by using specific types of software or encryption technologies.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority for providers of electronic communications networks and services, under the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) and the Electronic Communications Code. Operators such as POST Luxembourg, Proximus Luxembourg, Orange Luxembourg, Tango and Eltrona are classified as essential entities and must demonstrate the implementation of security by design and by default as well as proactive subscriber information during significant incidents. CERT.LU centralizes threat bulletins that these operators must relay.

Luxgap practice: we integrate the CERT.LU feed by default into Luxgap Subscriber Threat Broadcaster and align subscriber communication templates with ILR expectations and ENISA recommendations adapted to the Luxembourg multilingual context (FR/DE/EN/LU).