The classic trap
Recital 129 expresses a strong political intent: without real financial sanctioning power, NIS 2 remains a dead letter. In practice, Luxembourg's ILR now has an arsenal ranging from direct administrative fines to requesting imposition via a court. Essential and important entities that still think cybersecurity is a 'declarative' obligation discover too late that the ILR cross-checks incident notifications, inspection reports and sectoral declarations to qualify repeated negligence, a systematic aggravating circumstance.
What this recital concretely changes for you
- The ILR no longer needs to prove a materialized incident to sanction: a breach of article 21 measures (risk management) is enough.
- NIS 2 ceilings are concrete: up to 10 M EUR or 2% of worldwide turnover for essential entities, 7 M EUR or 1.4% for important entities.
- Personal liability of executives (article 20) combines with this sanctioning power: temporary ban from exercising management functions is possible.
- The absence of documentary evidence (ISMS policy, incident register, continuity exercises) becomes in itself an aggravating factor when calculating the fine.
- Sanctions are published: direct reputational impact on public tenders and banking counterparty trust.
The 'ability to demonstrate' test before the ILR
The ILR does not assess your actual cybersecurity, it assesses your ability to demonstrate it within 48 hours during a control. An entity applying good practices but unable to produce a signed policy, a timestamped incident register, or proof of recent exercises will be sanctioned as a negligent entity. Recital 129 must therefore be read as a documentary imperative: every measure of article 21 must have its opposable evidence, dated, validated by management.
How Luxgap automates this risk
Our Luxgap NIS2 Evidence Vault transforms your NIS 2 compliance into a vault of opposable evidence, ready to be produced within 48 hours before the ILR. The tool connects in read-only mode to Microsoft Defender, Azure Sentinel, CrowdStrike, Wazuh, Active Directory, your EDR and your SIEM to automatically collect the technical evidence the ILR will request, without depending on your CISO's availability on the day of the control.
- Continuously collects evidence of application of the 10 article 21 measures (MFA, backups, vulnerability management, training) with cryptographic timestamping.
- Generates a pre-built defense file, structured according to the ILR inspection grid, downloadable in one click as a sealed PDF.
- Calculates a sanction exposure score based on detected gaps, weighted by the aggravating factors of article 32 NIS 2 (severity, duration, recidivism).
- Alerts management via Teams or email as soon as an ILR control becomes likely (notified incident + critical documentary gap).
- Archives board decisions relating to cybersecurity (article 20), the only opposable evidence of executive accountability.
- Produces a quarterly maturity report signed digitally, opposable in any appeal against a sanction.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalized quote and our teams will prepare a demonstration on your real IT environment, with a free white audit within 48 hours to measure your exposure to ILR sanctions before any commitment.