The classic trap
Recital 84 announces an EU implementing act that harmonises cybersecurity measures for cross-border providers (DNS, TLD, cloud, data centres, CDN, MSP, MSSP, marketplaces, search engines, social networks, trust services). In practice, the ILR will not accept your own local interpretation of Article 21: it will apply Implementing Regulation (EU) 2024/2690 of 17 October 2024 which sets the precise technical requirements. The trap? Many Luxembourg cloud and MSP entities have built their compliance on the generic ANSSI grid or ISO 27001, without finely mapping the 13 technical domains imposed by the implementing act.
What Implementing Act 2024/2690 actually requires
- Information system security policy with explicitly named roles and responsibilities, mandatory annual review.
- Incident handling with detection, classification and response procedures aligned with notification trigger thresholds.
- Business continuity and backup management with documented restoration tests.
- Supply chain security with critical subcontractor assessment (cloud-on-cloud, cascading hyperscalers).
- Security in acquisition, development and maintenance of IS (SDLC, vulnerability management, patch management).
- Effectiveness evaluation policies: metrics, indicators, penetration tests.
- Basic cyber hygiene and continuous staff training.
- Cryptography: key management policy, authorised algorithms.
- HR security, access control and asset management.
- Multi-factor authentication and secured communications (voice, video, text).
If you are a Luxembourg-based cloud or MSP provider (eBRC, LuxConnect, Telindus, POST Cyberforce and their hosted clients), your NIS 2 compliance will be assessed on this very precise grid, not on a self-declared ISO 27001.
How Luxgap automates this risk
Our Luxgap Implementing Act Mapper turns the 13 requirements of Implementing Regulation 2024/2690 into a living compliance score, computed in real time on your actual cloud/MSP infrastructure. The tool cross-references your Azure, AWS, GCP, Defender XDR, CrowdStrike, Wazuh, Active Directory consoles and your subcontractor contracts to materialise exactly which technical requirements are covered, partially covered or missing, without asking the CISO to fill a single Excel questionnaire.
- Automatically scans your cloud tenants and detects compliance with each of the 13 requirements of Regulation 2024/2690 (MFA, encryption, logging, tested backups, segmentation).
- Classifies each gap by severity and proposes a remediation plan costed in man-days with ILR priority.
- Generates a technical file opposable to the ILR during an inspection, mapping each control to its article in the Implementing Regulation and to its technical evidence (Sentinel extract, pentest report, AD audit log).
- Instantly alerts on Teams or Slack as soon as a critical control deviates (MFA disabled on an admin account, TLS 1.0 reappeared, backup not tested for 90 days).
- Tracks the cloud-on-cloud outsourcing chain and flags US hyperscalers not covered by DPF, a finding raised in the supply chain category of the implementing act.
- Produces a timestamped PDF report, cryptographically signed, opposable to the ILR and reusable in B2B client due diligence.
Available alongside a Luxgap CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual infrastructure, with a free 48-hour blind audit to measure your exposure to the 13 technical requirements before any commitment.