The classic trap
Recital 59 invites the Commission, ENISA and Member States to align cyber risk management with international standards (ISO/IEC 27001, NIST CSF, ISO/IEC 27036 for supply chain). In practice, the ILR and Luxembourg sector authorities assess NIS 2 compliance against these frameworks: an entity without a formalised ISMS based on a recognised standard cannot demonstrate that its measures are 'appropriate and proportionate' during an inspection. The trap is not the absence of measures, it is the absence of a structuring normative framework that makes those measures auditable.
The de facto standard: ISO 27001, ENISA and NIST
Recital 59 does not name standards but clearly orients the reading of Articles 21 (risk management measures) and 22 (supply chain). Frameworks the ILR considers acceptable to materialise this alignment:
- ISO/IEC 27001:2022 for the overall ISMS and cyber governance.
- ISO/IEC 27036 for supply chain security assessments (explicitly mentioned by the recital).
- ENISA guides on supply chain risk management and baseline security recommendations.
- ISO/IEC 29147 and 30111 for coordinated vulnerability disclosure.
- Traffic Light Protocol (TLP) from ENISA for information sharing with the national CSIRT (GOVCERT.LU / CIRCL).
- NIST SP 800-161 for cyber supply chain risk management, complementary to ISO 27036.
How Luxgap automates this risk
Our Luxgap Standards Alignment Engine turns the abstract injunction to align with best practices into a living mapping between your real controls and the frameworks the ILR expects. The tool cross-references your technical inventory (Microsoft Defender, Azure Sentinel, CrowdStrike, Wazuh, Active Directory, Microsoft 365) with ISO 27001:2022, ISO 27036, NIST CSF 2.0 and ENISA guides to produce a real-time coverage matrix, without any questionnaire to fill in.
- Automatically detects your deployed technical controls and maps them to the 93 controls of ISO 27001:2022 Annex A and to NIST CSF categories.
- Identifies gaps between your real posture and the ENISA baseline for NIS 2 essential and important entities.
- Scans your IT supply chain (M365, Salesforce, AWS, eBRC, LuxConnect, POST) and rates each vendor against ISO 27036 and NIST SP 800-161.
- Generates a coordinated vulnerability disclosure procedure aligned with ISO 29147 / 30111, ready to publish on your website and notify to GOVCERT.LU.
- Produces a timestamped, cryptographically sealed PDF report that demonstrates to the ILR your alignment with the international standards referenced in Recital 59.
- Sends real-time Teams alerts when a new version of an ENISA guide or ISO standard impacts your compliance matrix.
Available alongside a Luxgap CISO engagement or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real perimeter, with a free 48-hour benchmark audit to measure your current alignment before any engagement.