Recital 24
Directive on the security of network and information systems · UE 2022/2555
| (24) | Where provisions of a sector-specific Union legal act require essential or important entities to comply with reporting obligations that are at least equivalent in effect to the reporting obligations laid down in this Directive, the consistency and effectiveness of the handling of incident notifications should be ensured. To that end, the provisions relating to incident notifications of the sector-specific Union legal act should provide the CSIRTs, the competent authorities or the single points of contact on cybersecurity (single points of contact) under this Directive with an immediate access to the incident notifications submitted in accordance with the sector-specific Union legal act. In particular, such immediate access can be ensured if incident notifications are being forwarded without undue delay to the CSIRT, the competent authority or the single point of contact under this Directive. Where appropriate, Member States should put in place an automatic and direct reporting mechanism that ensures systematic and immediate sharing of information with the CSIRTs, the competent authorities or the single points of contact concerning the handling of such incident notifications. For the purpose of simplifying reporting and of implementing the automatic and direct reporting mechanism, Member States could, in accordance with the sector-specific Union legal act, use a single entry point. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) designates the ILR as competent authority and NIS 2 single point of contact, with GOVCERT.LU as national CSIRT. For financial entities, the CSSF remains competent under DORA, but recital 24 requires immediate sharing with the ILR: in practice, both authorities must be notified as long as the national automatic information mechanism is not fully deployed.
Luxgap practice: we configure the Incident Routing Orchestrator with the Luxembourg matrix (ILR, GOVCERT.LU, CSSF, CNPD, Ministry of Health) and set up parallel flows to ensure multi-authority coverage from the trigger.