Recital 29
Directive on the security of network and information systems · UE 2022/2555
| (29) | In order to avoid gaps between or duplications of cybersecurity obligations imposed on entities in the aviation sector, national authorities under Regulations (EC) No 300/2008 (11) and (EU) 2018/1139 (12) of the European Parliament and of the Council and the competent authorities under this Directive should cooperate in relation to the implementation of cybersecurity risk-management measures and the supervision of compliance with those measures at national level. The compliance of an entity with the security requirements laid down in Regulations (EC) No 300/2008 and (EU) 2018/1139 and in the relevant delegated and implementing acts adopted pursuant to those Regulations could be considered by the competent authorities under this Directive to constitute compliance with the corresponding requirements laid down in this Directive. |
In Luxembourg, the cooperation referred to in recital 29 concretely involves the ILR (NIS 2 competent authority) and the Civil Aviation Directorate (DAC) of the Ministry of Mobility and Public Works (aviation authority). The law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025, transposes NIS 2 without creating any automatic exemption for the aviation sector: ILR's qualification of an entity as essential or important remains discretionary, even for actors already certified under EASA Part-IS. LuxAirport, Cargolux and operators based at Findel must therefore register with the ILR, regardless of their aviation status.
Luxgap practice: we establish a documented cooperation protocol between your aviation compliance team and your NIS 2 referent, and formalise with the ILR the Part-IS / Article 21 NIS 2 equivalence matrix to limit parallel audits.