Recital 125

Recital 125

Directive on the security of network and information systems · UE 2022/2555

(125)

The competent authorities should ensure that their supervisory tasks in relation to essential and important entities are carried out by trained professionals, who should have the necessary skills to carry out those tasks, in particular with regard to conducting on-site inspections and off-site supervision, including the identification of weaknesses in databases, hardware, firewalls, encryption and networks. Those inspections and that supervision should be conducted in an objective manner.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority designated by the law of 28 July 2023 on cybersecurity (as amended by the law of 28 July 2025) to conduct on-site inspections and off-site supervision of essential and important entities. ILR inspectors have the power to access premises, systems, technical data and logs, and may require targeted security audits at the inspected entity's expense.

Luxgap practice: maintain a permanent ILR inspection file (up-to-date network map, register of technical measures, evidence of cryptographic effectiveness, 12-month SIEM logs) and have it challenged quarterly by an external blank audit, to avoid the sanction that strikes the gap between declared and measured posture.