Recital 72

Recital 72

Directive on the security of network and information systems · UE 2022/2555

(72)

Cyberattacks are of a cross-border nature, and a significant incident can disrupt and damage critical information infrastructures on which the smooth functioning of the internal market depends. Recommendation (EU) 2017/1584 addresses the role of all relevant actors. Furthermore, the Commission is responsible, within the framework of the Union Civil Protection Mechanism, established by Decision No 1313/2013/EU of the European Parliament and of the Council (17), for general preparedness actions including managing the Emergency Response Coordination Centre and the Common Emergency Communication and Information System, maintaining and further developing situational awareness and analysis capability, and establishing and managing the capability to mobilise and dispatch expert teams in the event of a request for assistance from a Member State or third country. The Commission is also responsible for providing analytical reports for the IPCR arrangements under Implementing Decision (EU) 2018/1993, including in relation to cybersecurity situational awareness and preparedness, as well as for situational awareness and crisis response in the areas of agriculture, adverse weather conditions, conflict mapping and forecasts, early warning systems for natural disasters, health emergencies, infection disease surveillance, plant health, chemical incidents, food and feed safety, animal health, migration, customs, nuclear and radiological emergencies, and energy.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is designated as competent authority and GOVCERT.LU together with CIRCL act as national CSIRTs within the European CSIRTs Network. The law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) requires essential and important entities to notify significant incidents in two steps: early warning within 24h and full notification within 72h, with a final report within one month, those deadlines feeding the European escalation referred to in recital 72.

Luxgap practice: we configure the orchestrator on the official ILR and GOVCERT.LU channels and we test your 24h/72h chain through a documented annual table-top exercise.