Recital 123

Recital 123

Directive on the security of network and information systems · UE 2022/2555

(123)

The execution of supervisory tasks by the competent authorities should not unnecessarily hamper the business activities of the entity concerned. Where the competent authorities execute their supervisory tasks in relation to essential entities, including the conduct of on-site inspections and off-site supervision, the investigation of infringements of this Directive and the conduct of security audits or security scans, they should minimise the impact on the business activities of the entity concerned.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority designated by the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) to conduct on-site inspections, off-site supervision and security scans on essential and important entities. Inspections may be carried out with minimal prior notice for essential entities, and the ILR coordinates with the HCPN and the CSSF where the entity falls under multiple sectoral regulators.

Luxgap practice: prepare a bilingual FR/EN inspection file, set up a single ILR point of contact and rehearse handing over the file within 48 hours, because the impact minimisation promised by recital 123 only plays in favour of entities that respond fast.