Recital 127

Recital 127

Directive on the security of network and information systems · UE 2022/2555

(127)

In order to make enforcement effective, a minimum list of enforcement powers that can be exercised for breach of the cybersecurity risk-management measures and reporting obligations provided for in this Directive should be laid down, setting up a clear and consistent framework for such enforcement across the Union. Due regard should be given to the nature, gravity and duration of the infringement of this Directive, the material or non-material damage caused, whether the infringement was intentional or negligent, actions taken to prevent or mitigate the material or non-material damage, the degree of responsibility or any relevant previous infringements, the degree of cooperation with the competent authority and any other aggravating or mitigating factor. The enforcement measures, including administrative fines, should be proportionate and their imposition should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter of Fundamental Rights of the European Union (the ‘Charter’), including the right to an effective remedy and to a fair trial, the presumption of innocence and the rights of the defence.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority for applying the criteria of recital 127 when setting administrative sanctions under the Law of 28 July 2023 on cybersecurity (as amended by the Law of 28 July 2025). ILR decisions can be challenged before the administrative tribunal, in line with the Charter safeguards recalled by recital 127.

Luxgap practice: prepare a mitigation file in both French and English from the very first notification to the ILR, structuring your evidence along the 7 criteria of recital 127, to maximise your chances of an injunction rather than a fine.