Recital 113

Recital 113

Directive on the security of network and information systems · UE 2022/2555

(113)

Entities falling within the scope of this Directive should be considered to fall under the jurisdiction of the Member State in which they are established. However, providers of public electronic communications networks or providers of publicly available electronic communications services should be considered to fall under the jurisdiction of the Member State in which they provide their services. DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines and of social networking services platforms should be considered to fall under the jurisdiction of the Member State in which they have their main establishment in the Union. Public administration entities should fall under the jurisdiction of the Member State which established them. If the entity provides services or is established in more than one Member State, it should fall under the separate and concurrent jurisdiction of each of those Member States. The competent authorities of those Member States should cooperate, provide mutual assistance to each other and, where appropriate, carry out joint supervisory actions. Where Member States exercise jurisdiction, they should not impose enforcement measures or penalties more than once for the same conduct, in line with the principle of ne bis in idem.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) is the national competent authority designated by the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025). Any essential or important entity established in Luxembourg, or whose EU main establishment is in Luxembourg for cloud/DNS/MSP/marketplace services, falls directly under the ILR for designation, incident notification, inspection and administrative penalties. In case of concurrent jurisdiction with a foreign authority, the ILR will cooperate via the NIS Cooperation Group and CSIRT network, and will strictly apply the ne bis in idem principle.

Luxgap practice: if your group is headquartered in Luxembourg but cyber operations are managed from another Member State, explicitly document where cyber risk management decisions are taken (security committee, CISO RACI) as this ultimately determines whether the ILR or the foreign authority is the lead authority.