Recital 75

Recital 75

Directive on the security of network and information systems · UE 2022/2555

(75)

Peer reviews should be introduced to help learn from shared experiences, strengthen mutual trust and achieve a high common level of cybersecurity. Peer reviews can lead to valuable insights and recommendations strengthening the overall cybersecurity capabilities, creating another functional path for the sharing of best practices across Member States and contributing to enhance the Member States’ levels of maturity in cybersecurity. Furthermore, peer reviews should take account of the results of similar mechanisms, such as the peer-review system of the CSIRTs network, and should add value and avoid duplication. The implementation of peer reviews should be without prejudice to Union or national law on the protection of confidential or classified information.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the national competent authority designated by the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) and participates directly in the peer review mechanism provided for in Article 19 NIS 2. The outputs of peer reviews in which the ILR and the national CSIRT (GOVCERT.LU / CIRCL depending on scope) participate directly influence the inspection reference applied to Luxembourgish essential and important operators.

Luxgap practice: for entities supervised by the ILR, we recommend mapping today your posture against the best practices surfaced in published ENISA peer reviews, in order to anticipate ILR inspection questions 12 to 18 months before their formalisation.