The classic trap
Recital 38 lets Member States designate several sector-specific competent authorities. In practice, many essential or important entities do not know which authority actually supervises them: ILR for the NIS 2 baseline in Luxembourg, but CSSF for financial actors under DORA, BCL for certain payment infrastructures, CNPD when the incident involves personal data. This plurality produces misrouted notifications, missed deadlines and stacked sanctions.
The supervision map to establish before any incident
- Identify the primary NIS 2 authority based on Annex I or II sector (energy, transport, health, digital infrastructure, banking...).
- List parallel sectoral regulators: CSSF for finance, ILR for telecoms and cyber, CNPD for personal data, ITM for occupational safety, BCL for payments.
- Document crossed notification obligations: a single incident can trigger 3 to 4 notifications (NIS 2, GDPR Article 33, DORA, CSSF circular 22/806).
- Build an internal coordination matrix: who notifies what, to whom, within which deadline, using which form.
- Test the matrix through a crisis management exercise at least once a year.
The Luxembourg-specific trap
Luxembourg chose a multi-authority supervision model. A CSSF-regulated fintech hit by ransomware must notify ILR (NIS 2), CSSF (circular 24/847 and DORA), CNPD (GDPR if personal data), and possibly BCL. Each authority has its own channel, deadline and form. A missed or late notification is a standalone breach.
How Luxgap automates this risk
Our Luxgap Regulator Router eliminates the risk of misrouted notifications by mapping upfront, for your entity, the full set of competent authorities to alert based on incident typology. The tool continuously polls your systems (Azure Sentinel, Defender XDR, Wazuh, CrowdStrike, ServiceNow ITSM) and, as soon as an incident is qualified, triggers the right notification channel with the right pre-filled form, within the right legal deadline.
- Classifies each group entity by NIS 2 sector (Annex I or II), DORA status, CSSF supervision, and identifies the stacked competent authorities.
- Detects qualifying incidents in real time through native integration with Sentinel, Defender, CrowdStrike and Wazuh, and assesses each regime's notification thresholds.
- Generates pre-filled notifications in ILR, CSSF, CNPD and BCL formats, with mandatory fields already populated from the SIEM ticket.
- Counts parallel legal deadlines (24h NIS 2 early warning, 72h GDPR, 4h DORA major) on a single dashboard with Teams alerts.
- Produces a time-stamped, cryptographically sealed PDF report, admissible during an ILR or CSSF inspection, demonstrating that each authority was notified within deadlines.
- Automatically updates the supervision matrix when Luxembourg transposition evolves (law of 28 July 2025).
Available as a complement to a Luxgap CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams prepare a demonstration on your actual map of competent authorities, with a free blank audit within 48h to measure your multi-regulator exposure before any engagement.