Recital 11
Directive on the security of network and information systems · UE 2022/2555
| (11) | Some entities carry out activities in the areas of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences, while also providing trust services. Trust service providers which fall within the scope of Regulation (EU) No 910/2014 of the European Parliament and of the Council (6) should fall within the scope of this Directive in order to secure the same level of security requirements and supervision as that which was previously laid down in that Regulation in respect of trust service providers. In line with the exclusion of certain specific services from Regulation (EU) No 910/2014, this Directive should not apply to the provision of trust services that are used exclusively within closed systems resulting from national law or from agreements between a defined set of participants. |
In Luxembourg, the ILR is designated by the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) as the NIS 2 competent authority for trust service providers, in coordination with ILNAS which remains the eIDAS supervisory body. This duality imposes a double notification in case of incident: ILR within 24h for the NIS 2 leg, ILNAS for the eIDAS leg.
Luxgap practice: we configure a dual notification workflow (ILR + ILNAS) with timestamped acknowledgement of receipt, to avoid the classic trap of notifying only one authority and triggering the other's sanction.