Recital 83

Recital 83

Directive on the security of network and information systems · UE 2022/2555

(83)

Essential and important entities should ensure the security of the network and information systems which they use in their activities. Those systems are primarily private network and information systems managed by the essential and important entities’ internal IT staff or the security of which has been outsourced. The cybersecurity risk-management measures and reporting obligations laid down in this Directive should apply to the relevant essential and important entities regardless of whether those entities maintain their network and information systems internally or outsource the maintenance thereof.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, confirms that the essential or important entity designated by the ILR remains solely liable under NIS 2, even if its IS is operated by a Luxembourg provider (eBRC, LuxConnect, POST Telecom, Proximus Luxembourg) or European one. The ILR conducts its inspections directly at the regulated entity and may require the production of MSP contracts and evidence of execution of article 21 measures on the outsourced perimeter.

Luxgap practice: before any MSP renegotiation, we conduct a NIS 2 contractual gap audit on your existing contracts and provide a template addendum aligned with ILR expectations, ready to integrate as an amendment without reopening the full framework contract.