Recital 76
Directive on the security of network and information systems · UE 2022/2555
| (76) | The Cooperation Group should establish a self-assessment methodology for Member States, aiming to cover factors such as the level of implementation of the cybersecurity risk-management measures and reporting obligations, the level of capabilities and the effectiveness of the exercise of the tasks of the competent authorities, the operational capabilities of the CSIRTs, the level of implementation of mutual assistance, the level of implementation of the cybersecurity information-sharing arrangements, or specific issues of cross-border or cross-sector nature. Member States should be encouraged to carry out self-assessments on a regular basis, and to present and discuss the results of their self-assessment within the Cooperation Group. |
In Luxembourg, the ILR is the national authority responsible for reporting self-assessment indicators to the NIS 2 Cooperation Group, in coordination with GOVCERT.LU (governmental CSIRT) and CIRCL (CSIRT for the private sector and municipalities). The law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025, gives the ILR the power to require essential and important entities to provide the metrics needed for this national self-assessment.
Luxgap practice: continuously prepare a KPI set aligned with the ENISA grid and maintain an active MISP sharing channel with CIRCL; these are the two first signals the ILR looks at to qualify your actual maturity level.