Recital 43

Recital 43

Directive on the security of network and information systems · UE 2022/2555

(43)

As regards personal data, the CSIRTs should be able to provide, in accordance with Regulation (EU) 2016/679, upon the request of an essential or important entity, a proactive scanning of the network and information systems used for the provision of the entity’s services. Where applicable, Member States should aim to ensure an equal level of technical capabilities for all sectoral CSIRTs. Member States should be able to request the assistance of ENISA in developing their CSIRTs.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the proactive scan referred to in recital 43 is mainly operated by GOVCERT.LU for the public sector and operators of vital importance, and by sectoral CSIRTs coordinated by ILR under the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025). ILR designates essential and important entities and formalises the procedure for engaging the competent CSIRT.

Luxgap practice: we prepare the scan agreement with GOVCERT.LU or the competent sectoral CSIRT, including the GDPR legal basis and confidentiality matrix, before any activation.