Recital 27

Recital 27

Directive on the security of network and information systems · UE 2022/2555

(27)

Future sector-specific Union legal acts should take due account of the definitions and the supervisory and enforcement framework laid down in this Directive.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) transposes NIS 2 and designates the ILR as competent national authority for qualifying essential and important entities, inspections, incident notifications and administrative sanctions. The articulation with DORA is explicit: for financial entities supervised by the CSSF, DORA prevails on ICT risk but the Luxembourg NIS 2 law still applies for cross-cutting definitions and CSIRT cooperation.

Luxgap practice: for any Luxembourg multi-entity group (holding plus operational subsidiaries), we map entity by entity the ILR vs CSSF obligations matrix before any notification, avoiding duplicate filings and qualification blind spots.