Recital 15
Directive on the security of network and information systems · UE 2022/2555
| (15) | Entities falling within the scope of this Directive for the purpose of compliance with cybersecurity risk-management measures and reporting obligations should be classified into two categories, essential entities and important entities, reflecting the extent to which they are critical as regards their sector or the type of service they provide, as well as their size. In that regard, due account should be taken of any relevant sectoral risk assessments or guidance by the competent authorities, where applicable. The supervisory and enforcement regimes for those two categories of entities should be differentiated to ensure a fair balance between risk-based requirements and obligations on the one hand, and the administrative burden stemming from the supervision of compliance on the other. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) grants the ILR exclusive competence to formally designate essential and important operators. The designation takes the form of an individual notified decision, which triggers the obligation to register in the national NIS 2 entities register within 30 days. Self-classification is not sufficient: an ILR decision confirming the category is required.
Luxgap practice: we prepare the qualification file (argued note, group organizational chart, NACE, thresholds) that you proactively submit to the ILR to avoid surprise reclassification during an unannounced inspection.