Recital 84

Recital 84

Directive on the security of network and information systems · UE 2022/2555

(84)

Taking account of their cross-border nature, DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, of online search engines and of social networking services platforms, and trust service providers should be subject to a high degree of harmonisation at Union level. The implementation of cybersecurity risk-management measures with regard to those entities should therefore be facilitated by an implementing act.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) is the competent authority for the providers covered by Recital 84, including major Luxembourg cloud and data centre players (eBRC, LuxConnect, POST). The Law of 28 July 2023 on cybersecurity, amended by the Law of 28 July 2025, directly refers to EU implementing acts for the technical content of measures, making Implementing Regulation 2024/2690 immediately enforceable during an ILR inspection.

Luxgap practice: if you are a Luxembourg hosting provider or MSP, never present the ILR with a mere ISO 27001 certification; prepare a line-by-line mapping of Regulation 2024/2690 with timestamped technical evidence, as this is what the ILR requests during inspections.