Recital 30
Directive on the security of network and information systems · UE 2022/2555
| (30) | In view of the interlinkages between cybersecurity and the physical security of entities, a coherent approach should be ensured between Directive (EU) 2022/2557 of the European Parliament and of the Council (13) and this Directive. To achieve this, entities identified as critical entities under Directive (EU) 2022/2557 should be considered to be essential entities under this Directive. Moreover, each Member State should ensure that its national cybersecurity strategy provides for a policy framework for enhanced coordination within that Member State between its competent authorities under this Directive and those under Directive (EU) 2022/2557 in the context of information sharing about risks, cyber threats, and incidents as well as on non-cyber risks, threats and incidents, and the exercise of supervisory tasks. The competent authorities under this Directive and those under Directive (EU) 2022/2557 should cooperate and exchange information without undue delay, in particular in relation to the identification of critical entities, risks, cyber threats, and incidents as well as in relation to non-cyber risks, threats and incidents affecting critical entities, including the cybersecurity and physical measures taken by critical entities as well as the results of supervisory activities carried out with regard to such entities. Furthermore, in order to streamline supervisory activities between the competent authorities under this Directive and those under Directive (EU) 2022/2557 and in order to minimise the administrative burden for the entities concerned, those competent authorities should endeavour to harmonise incident notification templates and supervisory processes. Where appropriate, the competent authorities under Directive (EU) 2022/2557, should be able to request the competent authorities under this Directive to exercise their supervisory and enforcement powers in relation to an entity that is identified as a critical entity under Directive (EU) 2022/2557. The competent authorities under this Directive and those under Directive (EU) 2022/2557 should, where possible in real time, cooperate and exchange information for that purpose. |
In Luxembourg, the coordination required by recital 30 involves two distinct authorities: the ILR for NIS 2 (law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025) and the High Commission for National Protection (HCPN) for the CER Directive (transposed by the law on the resilience of critical entities). The law of 28 July 2023 enshrines the assimilation principle: any entity designated as critical by the HCPN is de jure an essential entity under NIS 2, with no additional designation procedure by the ILR.
Luxgap practice: establish a single mapping matrix between your ILR and HCPN obligations, and appoint a common referent who centralises exchanges with both authorities to avoid divergent notifications during a hybrid incident.