Recital 117

Recital 117

Directive on the security of network and information systems · UE 2022/2555

(117)

In order to ensure a clear overview of DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines and of social networking services platforms, which provide services across the Union that fall within the scope of this Directive, ENISA should create and maintain a registry of such entities, based on the information received by Member States, where applicable through national mechanisms established for entities to register themselves. The single points of contact should forward to ENISA the information and any changes thereto. With a view to ensuring the accuracy and completeness of the information that is to be included in that registry, Member States can submit to ENISA the information available in any national registries on those entities. ENISA and the Member States should take measures to facilitate the interoperability of such registries, while ensuring protection of confidential or classified information. ENISA should establish appropriate information classification and management protocols to ensure the security and confidentiality of disclosed information and restrict the access, storage, and transmission of such information to intended users.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR acts as the single point of contact within the meaning of recital 117 and centralises registrations forwarded to ENISA. The law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025, designates the ILR as the competent authority to receive and maintain these declarations, and grants it inspection and administrative sanction powers in case of incomplete or non-updated declarations.

Luxgap practice: before any filing or update with the ILR, run a consistency audit between your declaration, Whois data, legal notices and client contracts to eliminate gaps detectable through ENISA cross-checking.