Recital 13

Recital 13

Directive on the security of network and information systems · UE 2022/2555

(13)

Given the intensification and increased sophistication of cyber threats, Member States should strive to ensure that entities that are excluded from the scope of this Directive achieve a high level of cybersecurity and to support the implementation of equivalent cybersecurity risk-management measures that reflect the sensitive nature of those entities.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity (amended on 28 July 2025) transposes this recital by giving the ILR the power to designate essential or important entities beyond automatic thresholds, based on an assessment of the critical nature of the activity. Out-of-scope entities are therefore never definitively safe from later qualification.

Luxgap practice: prepare an Article 21 equivalence dossier even if you are out of scope, because the ILR can requalify your entity and a pre-built dossier saves you 6 to 12 months of emergency upgrade.