Recital 39

Recital 39

Directive on the security of network and information systems · UE 2022/2555

(39)

In order to facilitate cross-border cooperation and communication among authorities and to enable this Directive to be implemented effectively, it is necessary for each Member State to designate a single point of contact responsible for coordinating issues related to the security of network and information systems and cross-border cooperation at Union level.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) acts as single point of contact under Recital 39 and Article 8(3) of NIS 2. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, explicitly designates ILR as the national SPOC and competent authority, and entrusts it with coordination with foreign SPOCs and reporting to the Cooperation Group and ENISA.

Luxgap practice: if your essential or important entity has its main establishment in Luxembourg under Article 26, all your cross-border notifications must flow from ILR. Make sure your incident playbook explicitly designates ILR as primary SPOC and integrates its dedicated notification portal, not only the CNPD or a sectoral CSIRT.