Recital 95
Directive on the security of network and information systems · UE 2022/2555
| (95) | Where appropriate and in order to avoid unnecessary disruption, existing national guidelines adopted for the transposition of the rules related to security measures laid down in Articles 40 and 41 of Directive (EU) 2018/1972 should be taken into account in the transposition of this Directive, thereby building on the knowledge and skills already acquired under Directive (EU) 2018/1972 concerning security measures and incident notifications. ENISA can also develop guidance on security requirements and on reporting obligations for providers of public electronic communications networks or of publicly available electronic communications services to facilitate harmonisation and transition and to minimise disruption. Member States can assign the role of the competent authorities for electronic communications to the national regulatory authorities under Directive (EU) 2018/1972 in order to ensure the continuation of current practices and to build on the knowledge and experience gained as a result of the implementation of that Directive. |
In Luxembourg, the ILR is both the national regulatory authority under the Electronic Communications Code (law of 17 December 2021 on electronic communications networks and services) and the NIS 2 competent authority for the digital infrastructure sector. The law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025, implements the institutional continuity intended by recital 95: a single interlocutor for telecom operators, both for security obligations under the Code and for NIS 2 obligations.
Luxgap practice: for a Luxembourg telecom operator, document your Article 40/41 framework upstream and present the ILR with a single continuity file demonstrating the extension to NIS 2 requirements, rather than two parallel files.