Recital 18

Recital 18

Directive on the security of network and information systems · UE 2022/2555

(18)

In order to ensure a clear overview of the entities falling within the scope of this Directive, Member States should establish a list of essential and important entities as well as entities providing domain name registration services. For that purpose, Member States should require entities to submit at least the following information to the competent authorities, namely, the name, address and up-to-date contact details, including the email addresses, IP ranges and telephone numbers of the entity, and, where applicable, the relevant sector and subsector referred to in the annexes, as well as, where applicable, a list of the Member States where they provide services falling within the scope of this Directive. To that end, the Commission, with the assistance of the European Union Agency for Cybersecurity (ENISA), should, without undue delay, provide guidelines and templates regarding the obligation to submit information. To facilitate the establishing and updating of the list of essential and important entities as well as entities providing domain name registration services, Member States should be able to establish national mechanisms for entities to register themselves. Where registers exist at national level, Member States can decide on the appropriate mechanisms that allow for the identification of entities falling within the scope of this Directive.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) is the designated competent authority to receive self-registration declarations from essential and important entities. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, organises the national registration mechanism via a dedicated ILR portal, with a 2-week update obligation in case of substantial change.

Luxgap practice: do not stop at the initial registration. Set up a quarterly review of the information submitted to the ILR (IP ranges, contacts, sector) and keep timestamped proof of each update to demonstrate diligence in case of inspection.