Recital 52
Directive on the security of network and information systems · UE 2022/2555
| (52) | Open-source cybersecurity tools and applications can contribute to a higher degree of openness and can have a positive impact on the efficiency of industrial innovation. Open standards facilitate interoperability between security tools, benefitting the security of industrial stakeholders. Open-source cybersecurity tools and applications can leverage the wider developer community, enabling diversification of suppliers. Open source can lead to a more transparent verification process of cybersecurity related tools and a community-driven process of discovering vulnerabilities. Member States should therefore be able to promote the use of open-source software and open standards by pursuing policies relating to the use of open data and open-source as part of security through transparency. Policies promoting the introduction and sustainable use of open-source cybersecurity tools are of particular importance for small and medium-sized enterprises facing significant costs for implementation, which could be minimised by reducing the need for specific applications or tools. |
In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) is the competent authority designated by the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) to supervise essential and important entities. The Luxembourg transposition does not impose specific obligations on open source but the ILR recognizes, in line with recital 52, open-source stacks provided that governance, patch management and CVE monitoring are documented. GovCERT.lu and CIRCL provide MISP feeds natively usable by these stacks, which is an additional maturity argument.
Luxgap practice: feed your MISP instance with CIRCL and GovCERT.lu flows from deployment, and keep synchronization logs as proof of integration with the national CSIRT during an ILR inspection.