Recital 17
Directive on the security of network and information systems · UE 2022/2555
| (17) | Member States should be able to decide that entities identified before the entry into force of this Directive as operators of essential services in accordance with Directive (EU) 2016/1148 are to be considered to be essential entities. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) transposes this recital by allowing the ILR to carry over the list of operators of essential services designated under the former law of 28 May 2019 (NIS 1 transposition) to directly qualify them as NIS 2 essential entities, without a new designation procedure. Historical operators (Creos, Enovos, CFL, Encevo, POST, hospitals, systemic banks) are therefore presumed essential from entry into force.
Luxgap practice: if you were already in contact with the ILR under NIS 1, immediately request written confirmation of your new NIS 2 status (essential or important) to calibrate your 24h/72h notification obligations and avoid an under-qualification that costs dearly in case of incident.