Recital 22
Directive on the security of network and information systems · UE 2022/2555
| (22) | This Directive sets out the baseline for cybersecurity risk-management measures and reporting obligations across the sectors that fall within its scope. In order to avoid the fragmentation of cybersecurity provisions of Union legal acts, where further sector-specific Union legal acts pertaining to cybersecurity risk-management measures and reporting obligations are considered to be necessary to ensure a high level of cybersecurity across the Union, the Commission should assess whether such further provisions could be stipulated in an implementing act under this Directive. Should such an implementing act not be suitable for that purpose, sector-specific Union legal acts could contribute to ensuring a high level of cybersecurity across the Union, while taking full account of the specificities and complexities of the sectors concerned. To that end, this Directive does not preclude the adoption of further sector-specific Union legal acts addressing cybersecurity risk-management measures and reporting obligations that take due account of the need for a comprehensive and consistent cybersecurity framework. This Directive is without prejudice to the existing implementing powers that have been conferred on the Commission in a number of sectors, including transport and energy. |
In Luxembourg, the articulation of regimes is particularly sensitive because many entities combine financial activities (under CSSF and DORA) and support activities (under ILR and NIS 2). The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, confirms that the ILR is the NIS 2 authority but does not replace the CSSF for the DORA scope nor the ILR-telecom for the EECC. A CSSF-regulated fintech may therefore simultaneously have an ILR file (IT subsidiary) and a CSSF file (banking services).
Luxgap practice: for any dual-hat entity (bank + datacenter, insurer + e-health, telecom + cloud), we formalize a competence matrix signed by the executive committee that designates, for each incident type, the lead authority and secondary authorities to notify, with Luxembourg-specific deadlines.