Recital 92
Directive on the security of network and information systems · UE 2022/2555
| (92) | In order to streamline the obligations imposed on providers of public electronic communications networks or of publicly available electronic communications services, and trust service providers, related to the security of their network and information systems, as well as to enable those entities and the competent authorities under Directive (EU) 2018/1972 of the European Parliament and of the Council (20) and Regulation (EU) No 910/2014 respectively to benefit from the legal framework established by this Directive, including the designation of a CSIRT responsible for incident handling, the participation of the competent authorities concerned in the activities of the Cooperation Group and the CSIRTs network, those entities should fall within the scope of this Directive. The corresponding provisions laid down in Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 related to the imposition of security and notification requirements on those types of entity should therefore be deleted. The rules on reporting obligations laid down in this Directive should be without prejudice to Regulation (EU) 2016/679 and Directive 2002/58/EC. |
In Luxembourg, ILR is the competent authority for electronic communications operators (historical telecom regulator) and also becomes the NIS 2 authority. This concentration is an asset: one single ILR interlocutor for historical telecom and NIS 2 obligations. For trust service providers, ILNAS remains the eIDAS supervisory body but cybersecurity and incident notification obligations shift to ILR via the Law of 28 July 2023 on cybersecurity (amended by the Law of 28 July 2025).
Luxgap practice: we recommend Luxembourg telecom operators and TSPs to formally map the ILR / ILNAS / CNPD split in their incident response plan, since the classic trap in Luxembourg is to keep notifying ILNAS for security incidents that now fall exclusively under ILR.