Recital 34

Recital 34

Directive on the security of network and information systems · UE 2022/2555

(34)

Given the emergence of innovative technologies and new business models, new cloud computing service and deployment models are expected to appear in the internal market in response to evolving customer needs. In that context, cloud computing services may be delivered in a highly distributed form, even closer to where data are being generated or collected, thus moving from the traditional model to a highly distributed one (edge computing).

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority for NIS 2 inspections and requires, in practice, an up-to-date map of distributed processing nodes when the entity is designated essential or important. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, transposes NIS 2 article 21 and requires technical measures to cover all assets processing information, including edge nodes hosted at third-party providers (eBRC, LuxConnect, POST, Proximus, Cloudflare via Luxembourg POPs).

Luxgap practice: require from each edge provider a monthly inventory of POPs used to process your data and integrate it into your ILR register, otherwise your NIS 2 maturity score will be capped during the next audit.