Recital 82
Directive on the security of network and information systems · UE 2022/2555
| (82) | Cybersecurity risk-management measures should be proportionate to the degree of the essential or important entity’s exposure to risks and to the societal and economic impact that an incident would have. When establishing cybersecurity risk-management measures adapted to essential and important entities, due account should be taken of the divergent risk exposure of essential and important entities, such as the criticality of the entity, the risks, including societal risks, to which it is exposed, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact. |
In Luxembourg, the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, empowers the ILR to designate essential and important entities and to assess the proportionality of measures during inspections. The ILR publishes sectoral guidelines (energy, telecoms, digital infrastructure) that specify minimum expectations by size and criticality, and serve as the reading grid during audits.
Luxgap practice: we feed the proportionality matrix with the ILR sectoral guidelines published for your sector, so that your file directly answers the criteria the inspector will use on the ground.