Recital 7

Recital 7

Directive on the security of network and information systems · UE 2022/2555

(7)

Under Directive (EU) 2016/1148, Member States were responsible for identifying the entities which met the criteria to qualify as operators of essential services. In order to eliminate the wide divergences among Member States in that regard and ensure legal certainty as regards the cybersecurity risk-management measures and reporting obligations for all relevant entities, a uniform criterion should be established that determines the entities falling within the scope of this Directive. That criterion should consist of the application of a size-cap rule, whereby all entities which qualify as medium-sized enterprises under Article 2 of the Annex to Commission Recommendation 2003/361/EC (5), or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, and which operate within the sectors and provide the types of service or carry out the activities covered by this Directive fall within its scope. Member States should also provide for certain small enterprises and microenterprises, as defined in Article 2(2) and (3) of that Annex, which fulfil specific criteria that indicate a key role for society, the economy or for particular sectors or types of service to fall within the scope of this Directive.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative à la cybersécurité, modifiée par la loi du 28 juillet 2025

In Luxembourg, the ILR is the national authority that designates essential and important entities under the law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025. Self-registration of in-scope entities is done through the ILR portal within the deadlines set by the regulator, and failure to register is itself a sanctionable breach, independent of compliance with technical measures.

Luxgap practice: do not wait for an ILR notification to register. Complete your self-qualification, file your dossier on the ILR portal, and keep the timestamped filing receipt as the first piece of evidence in your NIS 2 accountability file.