Recital 32

Recital 32

Directive on the security of network and information systems · UE 2022/2555

(32)

Upholding and preserving a reliable, resilient and secure domain name system (DNS) are key factors in maintaining the integrity of the internet and are essential for its continuous and stable operation, on which the digital economy and society depend. Therefore, this Directive should apply to top-level-domain (TLD) name registries, and DNS service providers that are to be understood as entities providing publicly available recursive domain name resolution services for internet end-users or authoritative domain name resolution services for third-party usage. This Directive should not apply to root name servers.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority for NIS 2 and receives DNS incident notifications within 24h (early warning) then 72h (formal notification), under the law of 28 July 2023 on cybersecurity as amended by the law of 28 July 2025. The .lu registry is operated by DNS-LU (Restena), qualified as an essential entity, and local practice requires active DNSSEC on essential operators' domains.

Luxgap practice: we document your DNS chain up to the DNS-LU registry and embed the ILR notification channel directly into the incident workflow, to meet the 24h deadline without improvisation.