Recital 20
Directive on the security of network and information systems · UE 2022/2555
| (20) | The Commission should, in cooperation with the Cooperation Group and after consulting the relevant stakeholders, provide guidelines on the implementation of the criteria applicable to microenterprises and small enterprises for the assessment of whether they fall within the scope of this Directive. The Commission should also ensure that appropriate guidance is given to microenterprises and small enterprises falling within the scope of this Directive. The Commission should, with the assistance of the Member States, make information available to microenterprises and small enterprises in that regard. |
In Luxembourg, the ILR (Luxembourg Regulatory Institute) designates essential and important entities under the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025). Microenterprises and small enterprises operating critical infrastructure (DNS, .lu registrar, qualified eIDAS provider, cloud provider, Tier IV datacenter such as LuxConnect or eBRC) remain in scope despite their size, and must notify their qualification to the ILR via the dedicated portal.
Luxgap practice: verify your NACE code and actual activities with a documented qualification audit before the next ILR inspection, as ex-officio requalification triggers a full catch-up of obligations (governance, risk management, 24h incident notification) with no transitional period.