Recital 59

Recital 59

Directive on the security of network and information systems · UE 2022/2555

(59)

The Commission, ENISA and the Member States should continue to foster alignments with international standards and existing industry best practices in the area of cybersecurity risk management, for example in the areas of supply chain security assessments, information sharing and vulnerability disclosure.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the national authority designated by the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) to assess NIS 2 compliance of essential and important entities. The ILR explicitly relies on ENISA guides and the ISO 27001 framework to qualify the 'appropriate' nature of Article 21 measures. The national CSIRT (GOVCERT.LU for the public sector, CIRCL for the private sector) is the contact point for information sharing and coordinated vulnerability disclosure referenced in Recital 59.

Luxgap practice: we calibrate your alignment directly on the triptych expected by the ILR (ISO 27001:2022 + ENISA guides + CVD procedure to CIRCL/GOVCERT.LU) and produce the evidence file usable during an inspection.