Recital 48
Directive on the security of network and information systems · UE 2022/2555
| (48) | For the purpose of achieving and maintaining a high level of cybersecurity, the national cybersecurity strategies required under this Directive should consist of coherent frameworks providing strategic objectives and priorities in the area of cybersecurity and the governance to achieve them. Those strategies can be composed of one or more legislative or non-legislative instruments. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) transposes NIS 2 and confirms the National Cybersecurity Strategy led by HCPN as the reference framework. The ILR designates essential and important operators and expects their internal policies to be explicitly linked to national strategic objectives, failing which non-compliance is flagged during inspections.
Luxgap practice: we reconcile your ISMS policy with the LU national strategy and ILR / GOVCERT.lu guidance, and we produce an alignment matrix opposable during an audit.