The classic trap
Recital 31 prevents dual regulation for digital infrastructure entities (DNS, TLDs, datacenters, cloud, CDN, IXPs). Authorities, ILR in particular, penalise entities that believe they are exempt from physical security because they are 'digital'. NIS 2 absorbs the physical security of datacenters, server rooms and points of presence into its risk-management measures. The classic mistake: a Luxembourg cloud provider that documents encryption and IAM but forgets biometric access control to the datacenter, fire detection or power redundancy, believing this falls under CER (Directive 2022/2557) which does not apply.
The physical scope to cover in your NIS 2 measures
- Physical access control to server rooms and technical premises (badges, biometrics, retained access logs)
- Suitable fire detection and suppression (inert gas, VESDA) in technical rooms
- Redundant power supply (UPS, generators, dual feeds)
- Cooling and humidity control with 24/7 supervision
- Intrusion protection, video surveillance, security patrols
- Resilience of network points of presence and transport links (physically distinct paths)
- Secure destruction procedures for end-of-life media (disks, tapes)
- Continuity plans covering physical scenarios (fire, flooding, prolonged power outage)
This integration avoids documenting the same thing twice for two different authorities: everything flows to ILR under NIS 2.
How Luxgap automates this risk
Our Luxgap Physical-Cyber Fusion Audit eliminates the blind spot that brings down digital infrastructure operators during ILR inspections: the convergence between datacenter physical security and NIS 2 Article 21 measures. The tool merges into a single auditable repository your physical access control systems (Lenel, Bosch, Genetec), environmental sensors (APC, Schneider EcoStruxure), BMS/BAS and cyber tools (Defender, Sentinel, Wazuh), producing a unified view of the real security posture of your facilities.
- Automatically detects gaps between your declarative NIS 2 documentation and the ground truth of your datacenters via access control and BMS logs.
- Correlates physical events (forced door, power loss, fire alarm) with cyber events (node disconnect, heartbeat loss) to reveal hybrid attacks.
- Maps your eBRC, LuxConnect, Datacenter Luxembourg sites and points of presence against the physical criteria expected by ILR: N+1 redundancy, Tier certification, EN 50600 compliance.
- Generates a cryptographically sealed timestamped PDF report, opposable to ILR, demonstrating full Article 21 coverage including physical security per Recital 31.
- Alerts in real time via Teams or Slack when a physical measure degrades (generator not tested for 90 days, active orphan badge, temperature sensor out of range).
- Pre-fills the ILR incident notification within 24h by automatically aggregating relevant physical and cyber telemetry at time T.
Available as part of a Luxgap CISO mandate or as a dedicated SaaS module depending on your infrastructure scope. Request a tailored quote and our teams will prepare a demonstration on your actual datacenter, with a free white audit within 48h to measure your convergent exposure before any engagement.