Recital 80

Recital 80

Directive on the security of network and information systems · UE 2022/2555

(80)

For the purpose of demonstrating compliance with cybersecurity risk-management measures and in the absence of appropriate European cybersecurity certification schemes adopted in accordance with Regulation (EU) 2019/881 of the European Parliament and of the Council (18), Member States should, in consultation with the Cooperation Group and the European Cybersecurity Certification Group, promote the use of relevant European and international standards by essential and important entities or may require entities to use certified ICT products, ICT services and ICT processes.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority designated by the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) to supervise risk-management measures of essential and important entities. ILNAS is the national standardisation and accreditation body: it operates the OLAS accreditation scheme that qualifies the ISO 27001 certifiers recognised by ILR during inspections.

Luxgap practice: have your ISMS certified by an OLAS-accredited body and keep the ENISA Article 21 to ISO 27002:2022 mapping in an admissible form. This combination closes the file during an ILR inspection.