Recital 67
Directive on the security of network and information systems · UE 2022/2555
| (67) | The competent authorities and the CSIRTs should be able to participate in exchange schemes for officials from other Member States, within a specific framework and, where applicable, subject to the required security clearance of officials participating in such exchange schemes, in order to improve cooperation and strengthen trust among Member States. The competent authorities should take the necessary measures to enable officials from other Member States to play an effective role in the activities of the host competent authority or the host CSIRT. |
In Luxembourg, the ILR is the NIS 2 competent authority and GOVCERT.LU is the designated national CSIRT. The law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025, governs their participation in exchange schemes and the required security clearances, with respect to sectoral professional secrecy (notably article 41 of the LSF for the financial sector).
Luxgap practice: check that your SOC, MSSP and forensics contractual clauses expressly authorise sharing with ILR, GOVCERT.LU and seconded officials from other European CSIRTs, and that applicable banking or professional secrecy is pre-mapped artefact by artefact.