Recital 106

Recital 106

Directive on the security of network and information systems · UE 2022/2555

(106)

In order to simplify the reporting of information required under this Directive as well as to decrease the administrative burden for entities, Member States should provide technical means such as a single entry point, automated systems, online forms, user-friendly interfaces, templates, dedicated platforms for the use of entities, regardless of whether they fall within the scope of this Directive, for the submission of the relevant information to be reported. Union funding supporting the implementation of this Directive, in particular within the Digital Europe programme, established by Regulation (EU) 2021/694 of the European Parliament and of the Council (21), could include support for single entry points. Furthermore, entities are often in a situation where a particular incident, because of its features, needs to be reported to various authorities as a result of notification obligations included in various legal instruments. Such cases create additional administrative burden and could also lead to uncertainties with regard to the format and procedures of such notifications. Where a single entry point is established, Member States are encouraged also to use that single entry point for notifications of security incidents required under other Union law, such as Regulation (EU) 2016/679 and Directive 2002/58/EC. The use of such single entry point for reporting of security incidents under Regulation (EU) 2016/679 and Directive 2002/58/EC should not affect the application of the provisions of Regulation (EU) 2016/679 and Directive 2002/58/EC, in particular those relating to the independence of the authorities referred to therein. ENISA, in cooperation with the Cooperation Group, should develop common notification templates by means of guidelines to simplify and streamline the information to be reported under Union law and decrease the administrative burden on notifying entities.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the single entry point for NIS 2 incident notifications via its dedicated platform, but the CNPD keeps its own channel for personal data breaches under GDPR article 33, and the CSSF imposes its circular 24/847 for PSF and credit institutions. The law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) confirms that notifying the ILR does not discharge sector-specific reporting obligations: the same incident in a Luxembourg bank can therefore trigger three distinct parallel notifications.

Luxgap practice: for dual entities (NIS 2 + CSSF), we pre-wire the orchestrator on the three official forms (ILR, CNPD form_breach, CSSF eDesk) and guarantee a single opposable timeline during a cross-audit.