Recital 144
Directive on the security of network and information systems · UE 2022/2555
| (144) | The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (25) and delivered an opinion on 11 March 2021 (26), |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) designates the ILR as the NIS 2 competent authority and the national CSIRT (GOVCERT.LU / CIRCL) as the technical recipient. Essential and important entities in the financial sector also have the CSSF as a sectoral authority, which can create a triple notification (ILR + CNPD + CSSF) for a single incident.
Luxgap practice: for CSSF-regulated entities, the orchestrator integrates CSSF circular 24/847 on ICT incident notification from the outset, preventing the CSSF notification from drifting out of sync with ILR and CNPD.