Recital 91
Directive on the security of network and information systems · UE 2022/2555
| (91) | The coordinated security risk assessments of critical supply chains, in light of the features of the sector concerned, should take into account both technical and, where relevant, non-technical factors including those defined in Recommendation (EU) 2019/534, in the EU coordinated risk assessment of the cybersecurity of 5G networks and in the EU Toolbox on 5G cybersecurity agreed by the Cooperation Group. To identify the supply chains that should be subject to a coordinated security risk assessment, the following criteria should be taken into account: (i) the extent to which essential and important entities use and rely on specific critical ICT services, ICT systems or ICT products; (ii) the relevance of specific critical ICT services, ICT systems or ICT products for performing critical or sensitive functions, including the processing of personal data; (iii) the availability of alternative ICT services, ICT systems or ICT products; (iv) the resilience of the overall supply chain of ICT services, ICT systems or ICT products throughout their lifecycle against disruptive events; and (v) for emerging ICT services, ICT systems or ICT products, their potential future significance for the entities’ activities. Furthermore, particular emphasis should be placed on ICT services, ICT systems or ICT products that are subject to specific requirements stemming from third countries. |
In Luxembourg, the ILR (Institut Luxembourgeois de Régulation) is the national cybersecurity authority participating in the NIS 2 Cooperation Group and relays the conclusions of coordinated supply chain assessments to designated essential and important entities. The law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025, requires designated entities to integrate recommendations from these coordinated assessments into their supplier risk management, with particular focus on cloud operators hosting financial data (interaction with the CSSF and DORA) and digital infrastructures hosted at eBRC, LuxConnect or POST Telecom.
Luxgap practice: during each ILR inspection, demonstrate that your supplier mapping explicitly integrates the Cooperation Group's conclusions on 5G and cloud services, and that you reassess your dependencies at least every 12 months with timestamped traceability.