Recital 31

Recital 31

Directive on the security of network and information systems · UE 2022/2555

(31)

Entities belonging to the digital infrastructure sector are in essence based on network and information systems and therefore the obligations imposed on those entities pursuant to this Directive should address in a comprehensive manner the physical security of such systems as part of their cybersecurity risk-management measures and reporting obligations. Since those matters are covered by this Directive, the obligations laid down in Chapters III, IV and VI of Directive (EU) 2022/2557 do not apply to such entities.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the single competent authority for digital infrastructure operators designated as essential or important under the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025). The Luxembourg market concentrates an exceptional density of Tier IV datacenters (eBRC, LuxConnect, Datacenter Luxembourg) and ILR expects a documented demonstration of physical security per Recital 31, without referral to another regime.

Luxgap practice: require your colocation providers to issue an NIS 2-specific attestation covering Article 21 physical measures, distinct from their generic ISO 27001 or EN 50600 certification.