Recital 38

Recital 38

Directive on the security of network and information systems · UE 2022/2555

(38)

In view of the differences in national governance structures and in order to safeguard already existing sectoral arrangements or Union supervisory and regulatory bodies, Member States should be able to designate or establish one or more competent authorities responsible for cybersecurity and for the supervisory tasks under this Directive.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, designates ILR as the national NIS 2 competent authority, in charge of designating essential and important entities, receiving incident notifications, conducting inspections and imposing administrative sanctions. However, supervision remains stacked: CSSF retains competence over financial actors (DORA, circular 24/847), CNPD over the personal data dimension, and BCL over certain payment infrastructures.

Luxgap practice: establish, from day one of NIS 2 qualification, a written matrix of competent authorities signed by executive management, and rehearse it during every crisis exercise. This matrix is the first document ILR asks for during an inspection.