Recital 124
Directive on the security of network and information systems · UE 2022/2555
| (124) | In the exercise of ex ante supervision, the competent authorities should be able to decide on the prioritisation of the use of supervisory measures and means at their disposal in a proportionate manner. This entails that the competent authorities can decide on such prioritisation based on supervisory methodologies which should follow a risk-based approach. More specifically, such methodologies could include criteria or benchmarks for the classification of essential entities into risk categories and corresponding supervisory measures and means recommended per risk category, such as the use, frequency or types of on-site inspections, targeted security audits or security scans, the type of information to be requested and the level of detail of that information. Such supervisory methodologies could also be accompanied by work programmes and be assessed and reviewed on a regular basis, including on aspects such as resource allocation and needs. In relation to public administration entities, the supervisory powers should be exercised in line with the national legislative and institutional frameworks. |
In Luxembourg, the ILR is the competent authority designated by the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) to exercise ex ante supervision of essential entities. The ILR publishes its supervisory methodologies and may carry out on-site inspections, targeted security audits and security scans, in coordination with the HCPN for Luxembourg public administration entities.
Luxgap practice: prepare an ILR file ready to present within 48h, structured around the six standard inspection themes (governance, assets, supply chain, detection, response, continuity), to avoid unfavourable reclassification into a high risk category.