Recital 60
Directive on the security of network and information systems · UE 2022/2555
| (60) | Member States, in cooperation with ENISA, should take measures to facilitate coordinated vulnerability disclosure by establishing a relevant national policy. As part of their national policy, Member States should aim to address, to the extent possible, the challenges faced by vulnerability researchers, including their potential exposure to criminal liability, in accordance with national law. Given that natural and legal persons researching vulnerabilities could in some Member States be exposed to criminal and civil liability, Member States are encouraged to adopt guidelines as regards the non-prosecution of information security researchers and an exemption from civil liability for their activities. |
In Luxembourg, the law of 28 July 2023 on cybersecurity (as amended by the law of 28 July 2025) does not provide an explicit non-prosecution regime for security researchers, contrary to recital 60's recommendation. The competent national CSIRT is GOVCERT.LU for the public sector and critical operators, and CIRCL for the private sector. The ILR recommends, without formally imposing, adopting a CVD policy aligned with the ENISA standard.
Luxgap practice: in the absence of an explicit legal safe harbor in Luxembourg, we contractually document the non-prosecution commitment via a publicly enforceable Safe Harbor Statement, and we interface your CVD channel directly with CIRCL via their MISP API to guarantee CSIRT coordination in under 4h.