Recital 137
Directive on the security of network and information systems · UE 2022/2555
| (137) | This Directive should aim to ensure a high level of responsibility for the cybersecurity risk-management measures and reporting obligations at the level of the essential and important entities. Therefore, the management bodies of the essential and important entities should approve the cybersecurity risk-management measures and oversee their implementation. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) entrusts the ILR with the power to verify effective approval of measures by the management body and to impose administrative sanctions including temporary suspension of management functions in case of serious breach. ILR in practice requires production of board minutes approving the cyber policy during any inspection of essential entities.
Luxgap practice: we formalise a Luxembourg-specific NIS 2 governance kit (template minutes, executive accountability charter, training register) directly opposable to ILR inspectors, integrated into your existing board process.