Recital 4

Recital 4

Directive on the security of network and information systems · UE 2022/2555

(4)

The legal basis of Directive (EU) 2016/1148 was Article 114 of the Treaty on the Functioning of the European Union (TFEU), the objective of which is the establishment and functioning of the internal market by enhancing measures for the approximation of national rules. The cybersecurity requirements imposed on entities providing services or carrying out activities which are economically significant vary considerably among Member States in terms of type of requirement, their level of detail and the method of supervision. Those disparities entail additional costs and create difficulties for entities that offer goods or services across borders. Requirements imposed by one Member State that are different from, or even in conflict with, those imposed by another Member State, may substantially affect such cross-border activities. Furthermore, the possibility of the inadequate design or implementation of cybersecurity requirements in one Member State is likely to have repercussions at the level of cybersecurity of other Member States, in particular given the intensity of cross-border exchanges. The review of Directive (EU) 2016/1148 has shown a wide divergence in its implementation by Member States, including in relation to its scope, the delimitation of which was very largely left to the discretion of the Member States. Directive (EU) 2016/1148 also provided the Member States with very wide discretion as regards the implementation of the security and incident reporting obligations laid down therein. Those obligations were therefore implemented in significantly different ways at national level. There are similar divergences in the implementation of the provisions of Directive (EU) 2016/1148 on supervision and enforcement.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, transposes NIS 2 and entrusts the ILR with the designation of essential and important operators, incident notification reception, inspections and administrative sanctions. The Luxembourg specificity lies in the concentration of powers: a single transverse sectoral regulator, where France or Germany fragment between ANSSI, sectoral regulators and BSI.

Luxgap practice: for groups based in Luxembourg with European subsidiaries, build your NIS 2 programme on the ILR standard (the most integrated) then derive national variants, rather than the reverse. This reduces compliance costs by 30 to 40 percent.