Recital 132
Directive on the security of network and information systems · UE 2022/2555
| (132) | Where this Directive does not harmonise administrative penalties or where necessary in other cases, for example in the event of a serious infringement of this Directive, Member States should implement a system which provides for effective, proportionate and dissuasive penalties. The nature of such penalties and whether they are criminal or administrative should be determined by national law. |
In Luxembourg, the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, articulates the NIS 2 sanctions regime around the ILR for the administrative side, with possible referral to the public prosecutor in case of criminal qualification (obstruction of inspection, false declaration, incident concealment). Directors of essential entities can be held personally liable under Luxembourg business criminal law, on top of administrative fines capped at EUR 10M or 2% of global turnover.
Luxgap practice: we recommend formally documenting, in a board-approved governance charter, the incident escalation process and the 24h / 72h ILR notification chain, to neutralise the risk of requalification as serious infringement or concealment during an ILR inspection.