Recital 115
Directive on the security of network and information systems · UE 2022/2555
| (115) | Where a publicly available recursive DNS service is provided by a provider of public electronic communications networks or of publicly available electronic communications services only as a part of the internet access service, the entity should be considered to fall under the jurisdiction of all the Member States where its services are provided. |
In Luxembourg, ILR is designated as the competent authority and national CSIRT by the law of 28 July 2023 on cybersecurity (as amended by the law of 28 July 2025). For a Luxembourg ISP or MVNO operating an ancillary recursive DNS resolver, ILR is the single point of contact for significant incident notification (early warning within 24h, full notification within 72h), but retains the obligation to coordinate with authorities of other Member States where the service is provided, in line with the cooperation mechanism set out by the law.
Luxgap practice: maintain a 'Member State -> authority -> point of contact' matrix validated quarterly, and pre-wire your ILR notification templates with an 'other concerned jurisdictions' field auto-populated by your DNS mapping.