Recital 36
Directive on the security of network and information systems · UE 2022/2555
| (36) | Research activities play a key role in the development of new products and processes. Many of those activities are carried out by entities that share, disseminate or exploit the results of their research for commercial purposes. Those entities can therefore be important players in value chains, which makes the security of their network and information systems an integral part of the overall cybersecurity of the internal market. Research organisations should be understood to include entities which focus the essential part of their activities on the conduct of applied research or experimental development, within the meaning of the Organisation for Economic Cooperation and Development’s Frascati Manual 2015: Guidelines for Collecting and Reporting Data on Research and Experimental Development, with a view to exploiting their results for commercial purposes, such as the manufacturing or development of a product or process, the provision of a service, or the marketing thereof. |
In Luxembourg, the ILR is the competent authority designated by the Law of 28 July 2023 on cybersecurity (as amended by the Law of 28 July 2025) to qualify research organisations as essential or important entities. Given the dense Luxembourg ecosystem (LIST, LIH, LISER, Luxinnovation, House of BioHealth, Technoport), the boundary between academic research and commercial exploitation is particularly blurred: an FNR-funded project can shift into NIS 2 scope as soon as a spin-off files an exploitable patent.
Luxgap practice: we advise Luxembourg research centres to produce a documented Frascati qualification per project and proactively notify the ILR rather than wait for an ex officio designation, which triggers a constrained 21-month compliance timeline without a negotiated preparation phase.