Recital 142
Directive on the security of network and information systems · UE 2022/2555
| (142) | Since the objective of this Directive, namely to achieve a high common level of cybersecurity across the Union, cannot be sufficiently achieved by the Member States but can rather, by reason of the effects of the action, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality as set out in that Article, this Directive does not go beyond what is necessary in order to achieve that objective. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) transposes NIS 2 and designates the ILR as the main competent authority, with notification deadlines aligned with Article 23 (early warning within 24h, incident notification within 72h, final report within one month). The ILR cooperates directly with the national CSIRT (GOVCERT.LU) and with sectoral authorities (CSSF for finance, ITM for certain operators).
Luxgap practice: if your main establishment is in Luxembourg, the ILR centralises notifications even for incidents occurring in other Member States; document this articulation in your incident response plan to avoid redundant notifications.