Recital 93
Directive on the security of network and information systems · UE 2022/2555
| (93) | The cybersecurity obligations laid down in this Directive should be considered to be complementary to the requirements imposed on trust service providers under Regulation (EU) No 910/2014. Trust service providers should be required to take all appropriate and proportionate measures to manage the risks posed to their services, including in relation to customers and relying third parties, and to report incidents under this Directive. Such cybersecurity and reporting obligations should also concern the physical protection of the services provided. The requirements for qualified trust service providers laid down in Article 24 of Regulation (EU) No 910/2014 continue to apply. |
In Luxembourg, the ILR is simultaneously the NIS 2 supervisory authority (law of 28 July 2023 on cybersecurity, amended by the law of 28 July 2025) AND the eIDAS supervisory body for qualified trust service providers established in the territory. This institutional duality simplifies the single point of contact but requires heightened vigilance: the same incident may trigger two distinct legal qualifications (significant NIS 2 incident and breach of a qualified eIDAS trust service) with two deadlines and two forms.
Luxgap practice: for qualified Luxembourg TSPs (LuxTrust and similar players), we recommend a unified notification playbook that triggers both ILR notifications in parallel through a single internal contact point, to avoid any desynchronisation between the two investigation files.