Recital 71

Recital 71

Directive on the security of network and information systems · UE 2022/2555

(71)

EU-CyCLONe should work as an intermediary between the technical and political level during large-scale cybersecurity incidents and crises and should enhance cooperation at operational level and support decision-making at political level. In cooperation with the Commission, having regard to the Commission’s competence in the area of crisis management, EU-CyCLONe should build on the CSIRTs network findings and use its own capabilities to create impact analysis of large-scale cybersecurity incidents and crises.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the national competent authority for NIS 2 and GOVCERT.LU acts as the national CSIRT contributing to EU-CyCLONe. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, designates both entities as single entry points for incident notifications and liaison with the European network. Any large-scale incident reporting goes through GOVCERT.LU before reaching EU-CyCLONe.

Luxgap practice: configure your notification channels to target both ILR (regulatory side) and GOVCERT.LU (technical CSIRT side) simultaneously, using STIX 2.1 format already accepted by both entities to avoid duplicate entry under pressure.