Recital 44
Directive on the security of network and information systems · UE 2022/2555
| (44) | The CSIRTs should have the ability, upon an essential or important entity’s request, to monitor the entity’s internet-facing assets, both on and off premises, in order to identify, understand and manage the entity’s overall organisational risks as regards newly identified supply chain compromises or critical vulnerabilities. The entity should be encouraged to communicate to the CSIRT whether it runs a privileged management interface, as this could affect the speed of undertaking mitigating actions. |
In Luxembourg, two CSIRTs coexist: GOVCERT.LU for public sector entities and state critical infrastructure operators, and CIRCL (Computer Incident Response Center Luxembourg, operated by SECURITYMADEIN.LU) for the private sector, SMEs and municipalities. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, designates the ILR as the competent authority to supervise essential and important entities, but the operational relay for exposed asset monitoring runs through the sector-appropriate CSIRT. The entity must therefore identify its reference CSIRT upstream and formalize the monitoring request channel set out in recital 44.
Luxgap practice: for each mandate we set up the relay agreement with CIRCL or GOVCERT and integrate their MISP feeds directly into the External Surface Sentinel dashboard, so your CVE alerts are enriched with the Luxembourg sector context.