Recital 23

Recital 23

Directive on the security of network and information systems · UE 2022/2555

(23)

Where a sector-specific Union legal act contains provisions requiring essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents, and where those requirements are at least equivalent in effect to the obligations laid down in this Directive, those provisions, including on supervision and enforcement, should apply to such entities. If a sector-specific Union legal act does not cover all entities in a specific sector falling within the scope of this Directive, the relevant provisions of this Directive should continue to apply to the entities not covered by that act.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the articulation between NIS 2 and DORA is particularly sensitive: the law of 28 July 2023 on cybersecurity (as amended by the law of 28 July 2025) designates the ILR as the competent authority for essential and important entities, while the CSSF remains the sole authority for financial entities falling under DORA. For mixed groups (private bank with IT subsidiary, fintech with dedicated datacenter), ILR-CSSF coordination is governed by a national protocol that favors the stricter sectoral supervision.

Luxgap practice: for each Luxembourg group entity, explicitly document the competent authority retained (ILR or CSSF) and as a courtesy notify both authorities during a cross-regime incident, to avoid the reproach of an incomplete notification.