The classic trap
Many Luxembourg organisations read this recital backwards: 'I am not in NIS 2 Annex I or II, therefore I have no cyber obligations'. This is a misreading. The European legislator explicitly asks Member States to push out-of-scope entities towards a high level of cybersecurity, and both the ILR and CSSF rely on this intent to require equivalent measures through other vectors: contractual requirements from essential clients, clauses of the law of 28 July 2023, sectoral expectations, or simply the GDPR Article 32 security obligation read in light of the state of the art.
Why being 'out of NIS 2 scope' does not protect you
- Your essential or important clients will impose NIS 2 on you through contractual cascade (Article 21 on supply chain security).
- The ILR can qualify your entity as critical by reasoned decision, even if you are not automatically designated by thresholds.
- The state-of-the-art standard is hardening: what was 'appropriate' in 2022 no longer is in 2025, and both the CNPD and CSSF align expectations on ENISA and NIS 2.
- Cyber insurers align their underwriting questionnaires on NIS 2, even for non-covered entities: coverage refusal if you do not implement the 10 Article 21 measures.
- In case of incident, demonstrating that you ignored recommended equivalent measures becomes an aggravating circumstance.
The 'equivalent measures' test: how to argue it
Recital 13 does not set a binary threshold but a proportional requirement. Concretely, an out-of-scope SME must be able to demonstrate that it evaluated the 10 Article 21 measures, retained those relevant to its attack surface, and documented justified gaps. Without this traceability, you are naked before an audit, a demanding client, or a claim.
How Luxgap automates this risk
Our Luxgap NIS2 Equivalence Mapper answers exactly the question 'am I at the level, even out of scope?' by turning the 10 Article 21 measures into an automated assessment grid on your real IT estate. The tool connects to Microsoft Defender, Azure Sentinel, Active Directory, Wazuh, CrowdStrike, your firewalls and your MDM to measure your cyber posture without declarative questionnaires, then produces an equivalence dossier defensible before your essential clients, your insurer or the ILR.
- Automatically scans your M365 tenant, Active Directory and endpoints to assess each NIS 2 Article 21 measure on a maturity scale aligned with ENISA.
- Detects gaps against the state-of-the-art standard and proposes a remediation plan prioritised by impact/effort ratio.
- Generates a timestamped, cryptographically sealed NIS 2 equivalence dossier presentable to an essential client cascading Article 21, to your cyber insurer, or to the ILR during an inspection.
- Alerts in real time when a measure regresses: new admin account without MFA, backup failed for 7 days, subcontractor ISO 27001 certificate expired.
- Compares your posture against the median of your Luxembourg sector (law firm, fiduciary, industrial SME, non-regulated fintech) to materialise your relative exposure.
- Produces a quarterly executive report for your management committee, demonstrating cyber diligence even out of NIS 2 scope.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your perimeter. Request a tailored quote and our teams will prepare a demonstration on your real IT estate, with a free white audit within 48h to measure your gap against the 10 Article 21 measures before any commitment.