Recital 40
Directive on the security of network and information systems · UE 2022/2555
| (40) | The single points of contact should ensure effective cross-border cooperation with relevant authorities of other Member States and, where appropriate, with the Commission and ENISA. The single points of contact should therefore be tasked with forwarding notifications of significant incidents with cross-border impact to the single points of contact of other affected Member States upon the request of the CSIRT or the competent authority. At national level, the single points of contact should enable smooth cross-sectoral cooperation with other competent authorities. The single points of contact could also be the addressees of relevant information about incidents concerning financial entities from the competent authorities under Regulation (EU) 2022/2554 which they should be able to forward, as appropriate, to the CSIRTs or the competent authorities under this Directive. |
In Luxembourg, the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, designates the ILR as competent authority and national single point of contact within the meaning of recital 40. The operational CSIRTs are GOVCERT.LU for public entities and CIRCL (Computer Incident Response Center Luxembourg, operated by SECURITYMADEIN.LU) for private entities. Financial entities subject to DORA notify in parallel to the CSSF, which can relay the information to the ILR SPOC for cross-border forwarding.
Luxgap practice: map upstream your three notification channels (competent CSIRT, ILR as SPOC, CSSF if applicable) and formalise in writing who triggers what in the first 24 hours, to avoid missing notification or inconsistent double notification.