Recital 138
Directive on the security of network and information systems · UE 2022/2555
| (138) | In order to ensure a high common level of cybersecurity across the Union on the basis of this Directive, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission in respect of supplementing this Directive by specifying which categories of essential and important entities are to be required to use certain certified ICT products, ICT services and ICT processes or obtain a certificate under a European cybersecurity certification scheme. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (22). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts. |
In Luxembourg, the ILR is designated by the Law of 28 July 2023 on cybersecurity (as amended by the Law of 28 July 2025) as the competent authority for monitoring compliance with cybersecurity obligations, including future European certification requirements arising from the delegated acts referred to in recital 138. The ILR will be able to require proof that critical ICT products of an essential or important entity comply with EUCC and EUCS schemes as soon as they become mandatory.
Luxgap practice: commit your cloud and infrastructure suppliers (POST, LuxConnect, eBRC, Proximus, Telindus) today through a contractual amendment to obtain the applicable European certification, rather than waiting for the delegated acts to force an urgent replacement.