Recital 8
Directive on the security of network and information systems · UE 2022/2555
| (8) | The exclusion of public administration entities from the scope of this Directive should apply to entities whose activities are predominantly carried out in the areas of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences. However, public administration entities whose activities are only marginally related to those areas should not be excluded from the scope of this Directive. For the purposes of this Directive, entities with regulatory competences are not considered to be carrying out activities in the area of law enforcement and are therefore not excluded on that ground from the scope of this Directive. Public administration entities that are jointly established with a third country in accordance with an international agreement are excluded from the scope of this Directive. This Directive does not apply to Member States’ diplomatic and consular missions in third countries or to their network and information systems, insofar as such systems are located in the premises of the mission or are operated for users in a third country. |
In Luxembourg, the ILR formally designates essential and important entities under the law of 28 July 2023 on cybersecurity (as amended by the law of 28 July 2025). A Luxembourg public administration self-excluding under recital 8 must be able to produce to the ILR a motivated qualification memo: the law of 28 July 2023 grounds the ILR's inspection powers, which include re-qualifying an entity ex officio and applying the administrative sanctions provided.
Luxgap practice: run the qualification BEFORE ILR designation, not after. A qualification memo produced upstream, archived and opposable, prevents you from falling into emergency mode if the ILR notifies you as an essential entity with a tight compliance deadline.