Recital 134

Recital 134

Directive on the security of network and information systems · UE 2022/2555

(134)

For the purpose of ensuring entities’ compliance with their obligations laid down in this Directive, Member States should cooperate with and assist each other with regard to supervisory and enforcement measures, in particular where an entity provides services in more than one Member State or where its network and information systems are located in a Member State other than that where it provides services. When providing assistance, the requested competent authority should take supervisory or enforcement measures in accordance with national law. In order to ensure the smooth functioning of mutual assistance under this Directive, the competent authorities should use the Cooperation Group as a forum to discuss cases and particular requests for assistance.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite (modifiee par la loi du 28 juillet 2025)

In Luxembourg, the ILR is the single point of contact for incoming and outgoing mutual assistance requests under article 37 NIS 2. The law of 28 July 2023 on cybersecurity (as amended by the law of 28 July 2025) empowers the ILR to enforce on Luxembourg territory the supervisory measures requested by a peer authority of another Member State, and to bring complex cross-border cases to the NIS Cooperation Group.

Luxgap practice: if you are a Luxembourg essential or important entity with operations in France, Belgium or Germany, appoint a single internal cybersecurity contact point and align your ILR declarations with your ANSSI / CCB / BSI filings to avoid any inconsistency detectable within days.