Recital 85

Recital 85

Directive on the security of network and information systems · UE 2022/2555

(85)

Addressing risks stemming from an entity’s supply chain and its relationship with its suppliers, such as providers of data storage and processing services or managed security service providers and software editors, is particularly important given the prevalence of incidents where entities have been the victim of cyberattacks and where malicious perpetrators were able to compromise the security of an entity’s network and information systems by exploiting vulnerabilities affecting third-party products and services. Essential and important entities should therefore assess and take into account the overall quality and resilience of products and services, the cybersecurity risk-management measures embedded in them, and the cybersecurity practices of their suppliers and service providers, including their secure development procedures. Essential and important entities should in particular be encouraged to incorporate cybersecurity risk-management measures into contractual arrangements with their direct suppliers and service providers. Those entities could consider risks stemming from other levels of suppliers and service providers.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority to assess the supply chain risk management compliance of designated essential and important entities. The law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025, transposes Article 21(2)(d) of NIS 2 and empowers the ILR to directly inspect contractual documentation and supplier assessments. For operators hosted at eBRC, LuxConnect or POST Telecom, the ILR expects a specific assessment of the national supplier, with enforceable audit or certification proof.

Luxgap practice: we pre-fill your critical supplier file with the public certifications of Luxembourg hosts (eBRC ISO 27001, LuxConnect Tier IV, POST CSPN) to accelerate the response to an ILR inspection.