The classic trap
Recital 23 is the interpretive key for the lex specialis articulation between NIS 2 and sector-specific regimes (DORA for finance, the CER Regulation, the Electronic Communications Code). In practice, the ILR sanctions two symmetrical mistakes: believing you are covered by DORA and therefore exempt from NIS 2 while one of your group entities falls outside DORA's scope, or conversely applying NIS 2 to a CSSF-regulated financial entity that fully falls under DORA. Mixed groups (industrial holding plus fintech subsidiary plus datacenter) are the primary victims of this regulatory layering.
The 'at least equivalent in effect' test: the analytical grid to document
For each entity in the group, recital 23 mandates a formalized regulatory mapping. The ILR expects you to justify, entity by entity, which regime applies and why:
- Identify the sector of each legal entity (NIS 2 annexes I and II) and verify whether a sector-specific EU act actually covers that specific entity.
- Run the equivalence test on both pillars: cybersecurity risk-management measures (NIS 2 article 21) and incident notification (NIS 2 article 23).
- Verify the equivalence of supervision and sanction regimes, not just substantive obligations.
- Document the reasoning in an opposable memo, signed by legal management, updated at each evolution of the group's perimeter.
- For grey zones (ICT in a bank: DORA or NIS 2?), default to the stricter provision pending a formal position from the ILR or CSSF.
- Track entities not covered by any sector-specific act: they automatically fall back under NIS 2 with no transitional regime.
How Luxgap automates this risk
Our Luxgap Regulatory Mapper eliminates the regulatory grey zone by automatically mapping, for each legal entity of your group, the applicable cyber regime and producing the equivalence memo opposable to the ILR. The tool queries the Luxembourg RCS registry, the CSSF registry, the ESMA database and your Odoo or SAP data to rebuild the group structure, then cross-references each entity with an up-to-date legal matrix of EU sector-specific acts (DORA, CER, EECC, eIDAS 2).
- Automatically scans your group structure via official registries (RCS, CSSF, BaFin, AMF) and rebuilds the regulatory org chart entity by entity.
- Applies the recital 23 test on each entity by comparing sector-specific obligations to NIS 2 articles 21 and 23, point by point, with a reasoned equivalence score.
- Detects coverage gaps, those group entities covered by no sector-specific act and automatically falling under NIS 2.
- Alerts in real time via Teams or Slack as soon as a new EU delegated act or ILR opinion modifies the equivalence perimeter.
- Generates a timestamped legal memo, cryptographically signed, opposable during an ILR or CSSF inspection, justifying the regime retained for each entity.
- Tracks the position of authorities (ILR, CSSF, ENISA, ESMA) on grey zones and proposes a pragmatic arbitration based on the stricter provision.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on the size of your group. Request a tailored quote and our teams prepare a free regulatory mapping within 48h on your actual perimeter, to materialize double-coverage zones before any engagement.