Recital 141

Recital 141

Directive on the security of network and information systems · UE 2022/2555

(141)

This Directive creates new tasks for ENISA, thereby enhancing its role, and could also result in ENISA being required to carry out its existing tasks under Regulation (EU) 2019/881 to a higher level than before. In order to ensure that ENISA has the necessary financial and human resources to carry out existing and new tasks, as well as to meet any higher level of execution of those tasks resulting from its enhanced role, its budget should be increased accordingly. In addition, in order to ensure the efficient use of resources, ENISA should be given greater flexibility in the way that it is able to allocate resources internally for the purpose of effectively carrying out its tasks and meeting expectations.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent NIS 2 authority and explicitly relies on ENISA publications to assess whether technical and organisational measures are 'appropriate and proportionate'. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, grants the ILR inspection, incident notification and administrative sanction powers, and refers to ENISA guidance as the state of the art benchmark during audits.

Luxgap practice: align your internal framework with the latest ENISA guidance relevant to your sector (energy, transport, health, digital infrastructure) and keep a timestamped record of your regulatory watch, which will be requested by the ILR from the first inspection exchange.