Recital 73

Recital 73

Directive on the security of network and information systems · UE 2022/2555

(73)

The Union can, where appropriate, conclude international agreements, in accordance with Article 218 TFEU, with third countries or international organisations, allowing and organising their participation in particular activities of the Cooperation Group, the CSIRTs network and EU-CyCLONe. Such agreements should ensure the Union’s interests and the adequate protection of data. This should not preclude the right of Member States to cooperate with third countries on management of vulnerabilities and cybersecurity risk management, facilitating reporting and general information sharing in accordance with Union law.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) entrusts the ILR with supervision of essential and important entities, while CIRCL (Computer Incident Response Center Luxembourg), operated by securitymadein.lu, and GOVCERT.LU act as national CSIRTs and contact points for cross-border cyber exchanges. Luxembourg NIS 2 entities sharing IoCs with non-EU partners should favour the CIRCL/MISP channel rather than unframed bilateral sharing.

Luxgap practice: we map your outbound CTI flows and migrate those that can be moved to the CIRCL MISP platform, which legally secures the sharing while preserving operational value for your SOC analysts.