Recital 87

Recital 87

Directive on the security of network and information systems · UE 2022/2555

(87)

The competent authorities, in the context of their supervisory tasks, may also benefit from cybersecurity services such as security audits, penetration testing or incident responses.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent authority designated by the law of 28 July 2023 on cybersecurity (as amended by the law of 28 July 2025) to conduct inspections and commission technical audits, penetration tests or incident response exercises on essential and important entities. The ILR may rely on qualified providers (notably recognised PASSI or ENISA-certified providers) whose fees are borne by the audited entity.

Luxgap practice: prepare a pre-built audit file (asset inventory, latest pentest reports, remediation plans, incident register) to reduce the scope and duration of any ILR-mandated mission, and therefore its rebilled cost.