Recital 5
Directive on the security of network and information systems · UE 2022/2555
| (5) | All those divergences entail a fragmentation of the internal market and can have a prejudicial effect on its functioning, affecting in particular the cross-border provision of services and the level of cyber resilience due to the application of a variety of measures. Ultimately, those divergences could lead to the higher vulnerability of some Member States to cyber threats, with potential spill-over effects across the Union. This Directive aims to remove such wide divergences among Member States, in particular by setting out minimum rules regarding the functioning of a coordinated regulatory framework, by laying down mechanisms for effective cooperation among the responsible authorities in each Member State, by updating the list of sectors and activities subject to cybersecurity obligations and by providing effective remedies and enforcement measures which are key to the effective enforcement of those obligations. Therefore, Directive (EU) 2016/1148 should be repealed and replaced by this Directive. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) transposes the harmonization intent of recital 5 by designating the ILR as single competent authority for essential and important entities, with a one-stop incident notification channel. Any LU subsidiary of a European group must notify the ILR and not the parent's authority, even if the group applies a harmonized baseline.
Luxgap practice: we establish your single point of contact with the ILR and synchronize your group notification procedures to trigger ILR, BSI, ANSSI and CCB in parallel during a cross-border incident, with no break in the 24h and 72h deadlines.