Recital 41
Directive on the security of network and information systems · UE 2022/2555
| (41) | Member States should be adequately equipped, in terms of both technical and organisational capabilities, to prevent, detect, respond to and mitigate incidents and risks. Member States should therefore establish or designate one or more CSIRTs under this Directive and ensure that they have adequate resources and technical capabilities. The CSIRTs should comply with the requirements laid down in this Directive in order to guarantee effective and compatible capabilities to deal with incidents and risks and to ensure efficient cooperation at Union level. Member States should be able to designate existing computer emergency response teams (CERTs) as CSIRTs. In order to enhance the trust relationship between the entities and the CSIRTs, where a CSIRT is part of a competent authority, Member States should be able to consider functional separation between the operational tasks provided by the CSIRTs, in particular in relation to information sharing and assistance provided to the entities, and the supervisory activities of the competent authorities. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) designates the ILR as NIS 2 competent authority and recognises two operational CSIRTs: GOVCERT.LU (HCPN, State sector and OIV) and CIRCL (SECURITYMADEIN.LU, private sector and municipalities). The functional separation mentioned in recital 41 is concrete: the ILR supervises and sanctions, the competent CSIRT assists and shares information without contaminating the inspection file.
Luxgap practice: in your incident playbooks, explicitly codify the dual notification (CSIRT for operations, ILR for regulatory) and test it every year through a documented crisis exercise, defensible during an ILR inspection.