Recital 81

Recital 81

Directive on the security of network and information systems · UE 2022/2555

(81)

In order to avoid imposing a disproportionate financial and administrative burden on essential and important entities, the cybersecurity risk-management measures should be proportionate to the risks posed to the network and information system concerned, taking into account the state-of-the-art of such measures, and, where applicable, relevant European and international standards, as well as the cost for their implementation.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR applies the proportionality principle taking into account the highly heterogeneous economic landscape: a 15-person CSSF-regulated fintech and a systemic bank are not assessed on the same grid. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, transposes this principle and allows the ILR to modulate its expectations depending on the profile of the designated essential or important entity, based on a documented risk analysis.

Luxgap practice: permanently keep a dated, management-signed risk analysis aligned with ISO 27005 or EBIOS RM, justifying why each article 21(2) measure is implemented, deferred or excluded. This is the first document requested during an ILR inspection.