Recital 26
Directive on the security of network and information systems · UE 2022/2555
| (26) | Where sector-specific Union legal acts require or provide incentives to entities to notify significant cyber threats, Member States should also encourage the sharing of significant cyber threats with the CSIRTs, the competent authorities or the single points of contact under this Directive, in order to ensure an enhanced level of those bodies’ awareness of the cyber threat landscape and to enable them to respond effectively and in a timely manner should the significant cyber threats materialise. |
In Luxembourg, voluntary sharing of significant cyber threats revolves around GovCERT.LU and CIRCL (Computer Incident Response Center Luxembourg), which operate the reference MISP platform for IOC exchange between essential and important entities. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, designates the ILR as competent authority and single point of contact, and confirms that voluntary sharing with national CSIRTs triggers no administrative sanction.
Luxgap practice: connect your SIEM to the CIRCL MISP instance from day one of your NIS 2 onboarding, it is the historical channel recognised by the ILR and immediately materialises your cooperative posture during inspections.