Recital 27
Directive on the security of network and information systems · UE 2022/2555
| (27) | Future sector-specific Union legal acts should take due account of the definitions and the supervisory and enforcement framework laid down in this Directive. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) transposes NIS 2 and designates the ILR as competent national authority for qualifying essential and important entities, inspections, incident notifications and administrative sanctions. The articulation with DORA is explicit: for financial entities supervised by the CSSF, DORA prevails on ICT risk but the Luxembourg NIS 2 law still applies for cross-cutting definitions and CSIRT cooperation.
Luxgap practice: for any Luxembourg multi-entity group (holding plus operational subsidiaries), we map entity by entity the ILR vs CSSF obligations matrix before any notification, avoiding duplicate filings and qualification blind spots.