Recital 46

Recital 46

Directive on the security of network and information systems · UE 2022/2555

(46)

Ensuring adequate resources to meet the objectives of this Directive and to enable the competent authorities and the CSIRTs to carry out the tasks laid down herein is essential. The Member States can introduce at the national level a financing mechanism to cover necessary expenditure in relation to the conduct of tasks of public entities responsible for cybersecurity in the Member State pursuant to this Directive. Such mechanism should comply with Union law and should be proportionate and non-discriminatory and should take into account different approaches to providing secure services.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) is the competent authority designated by the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025. The Luxembourg law explicitly provides for a financing mechanism through fees borne by essential and important operators, in line with recital 46. Administrative sanctions can reach EUR 10 million or 2% of worldwide turnover for essential entities.

Luxgap practice: budget the ILR fee as a distinct annual line separate from technical investments, and keep documentary proof of your compliance trajectory to support a proportionality argument during an inspection.