Recital 139
Directive on the security of network and information systems · UE 2022/2555
| (139) | In order to ensure uniform conditions for the implementation of this Directive, implementing powers should be conferred on the Commission to lay down the procedural arrangements necessary for the functioning of the Cooperation Group and the technical and methodological as well as sectoral requirements concerning the cybersecurity risk-management measures, and to further specify the type of information, the format and the procedure of incident, cyber threat and near miss notifications and of significant cyber threat communications, as well as cases in which an incident is to be considered to be significant. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council (23). |
In Luxembourg, the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, designates the ILR as the single competent authority to receive NIS 2 incident notifications and to monitor compliance with EU implementing acts. The ILR publishes its own notification templates aligned with Commission gabarits and mandates their exclusive use via its electronic portal.
Luxgap practice: wire your SOC to the current ILR notification format and re-verify alignment at every Commission implementing act release, since the ILR updates its forms with no transitional period.