Recital 19

Recital 19

Directive on the security of network and information systems · UE 2022/2555

(19)

Member States should be responsible for submitting to the Commission at least the number of essential and important entities for each sector and subsector referred to in the annexes, as well as relevant information about the number of identified entities and the provision, from among those laid down in this Directive, on the basis of which they were identified, and the type of service that they provide. Member States are encouraged to exchange with the Commission information about essential and important entities and, in the case of a large-scale cybersecurity incident, relevant information such as the name of the entity concerned.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) is the designated competent authority to qualify essential and important entities, receive incident notifications and conduct inspections. The law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025, transposes NIS 2 and requires concerned entities to register with the ILR via the dedicated portal, precisely declaring their services falling under Annex I or II.

Luxgap practice: do not wait for an ILR letter to register. Proactive self-qualification with a reasoned dossier (NACE code, technical services, CCSS headcount) on the ILR portal is the best protection against retroactive requalification with sanction effect.