Recital 74

Recital 74

Directive on the security of network and information systems · UE 2022/2555

(74)

In order to facilitate the effective implementation of this Directive with regard, inter alia, to the management of vulnerabilities, cybersecurity risk-management measures, reporting obligations and cybersecurity information-sharing arrangements, Member States can cooperate with third countries and undertake activities that are considered to be appropriate for that purpose, including information exchange on cyber threats, incidents, vulnerabilities, tools and methods, tactics, techniques and procedures, cybersecurity crisis management preparedness and exercises, training, trust building and structured information-sharing arrangements.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR coordinates international cyber cooperation through GOVCERT.LU (a unit of the High Commission for National Protection) and CIRCL (the historic global MISP operator, based in Luxembourg). The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, explicitly authorises these exchanges but requires essential and important entities to document their participation in MISP communities and their flows to third-country CERTs.

Luxgap practice: if you are an essential or important entity in Luxembourg, you almost certainly have MISP access via CIRCL. Formally document your membership, the TLP policy applied, and trace each IOC shared outside the EU in a register enforceable before the ILR.