Recital 17

Recital 17

Directive on the security of network and information systems · UE 2022/2555

(17)

Member States should be able to decide that entities identified before the entry into force of this Directive as operators of essential services in accordance with Directive (EU) 2016/1148 are to be considered to be essential entities.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) transposes this recital by allowing the ILR to carry over the list of operators of essential services designated under the former law of 28 May 2019 (NIS 1 transposition) to directly qualify them as NIS 2 essential entities, without a new designation procedure. Historical operators (Creos, Enovos, CFL, Encevo, POST, hospitals, systemic banks) are therefore presumed essential from entry into force.

Luxgap practice: if you were already in contact with the ILR under NIS 1, immediately request written confirmation of your new NIS 2 status (essential or important) to calibrate your 24h/72h notification obligations and avoid an under-qualification that costs dearly in case of incident.