Where this stands
The state of play
- The law
- Luxembourg law of 5 May 2026 on measures to ensure a high level of cybersecurity, transposing directive (EU) 2022/2555 and repealing the NIS1 framework
- In force since
- 10 May 2026 — with no transitional runway for the substantive obligations
- Registration
- The two-month window closed on 10 July 2026; the ILR portal stays open and the obligation is continuing
- Default supervisor
- Institut Luxembourgeois de Régulation (ILR)
- Financial sector
- Commission de Surveillance du Secteur Financier (CSSF), with DORA taking precedence as lex specialis for financial entities
- Single point of contact
- Haut-Commissariat à la Protection nationale (HCPN), which also runs national cyber crisis management and hosts GOVCERT.LU; CIRCL is the CSIRT for everyone outside the State and critical perimeter
The registration window closing did not close the door. Registration remains a continuing obligation, with a duty to keep the data current, and the ILR is explicit that not registering does not relieve an entity of any of its other obligations. If you are in scope and did not register, the exposure is now the omission as well as whatever sits underneath it, and the correct move is to establish the position rather than wait to be found.
Applicability
Size decides whether you are in scope. Sector decides what you are.
This is the distinction organisations most often get wrong, and it is not a detail: it changes what kind of supervision you face.
Scope generally begins at the medium-enterprise threshold — broadly from 50 staff, or €10 million in turnover and balance sheet. That calculation is made at group level under the EU's linked-and-partner-enterprise rules, which pulls in a good number of Luxembourg subsidiaries whose local headcount looks far too small to matter.
Category then depends on the sector, not on being bigger. Large entities — broadly from 250 staff, or €50 million turnover with a €43 million balance sheet — are essential only in the highly critical sectors. A large entity in one of the other covered sectors is important, however large it is. And a set of entities is essential regardless of size at all, including qualified trust service providers, TLD name registries and DNS service providers, providers of public electronic communications networks and services, entities designated critical under the parallel CER framework, former NIS1 operators of essential services, and the sole provider of an essential service in a member state.
The practical difference: essential entities face proactive supervision — audits, inspections and scans on the authority's own initiative — while important entities are supervised after the fact, on cause.
These are statutory tests rather than rules of thumb, and both errors are expensive. Where the answer is genuinely marginal — a mixed-sector group, a service that might or might not be an electronic communications service — it is a legal question and belongs with counsel. The ILR publishes the scope criteria and the self-registration route.
The obligation
The ten measures, and what evidence each one really means
The law sets a minimum list of ten risk-management measures. In the organisations we work with, documents for all ten usually exist. Evidence for all ten usually does not, and the distance between those two states is the compliance problem in its entirety.
- Risk analysis and information system security policies — dated, approved, and demonstrably connected to the risks you actually recorded.
- Incident handling — a procedure that has been used, with the record of a real or exercised incident behind it.
- Business continuity, backup management, disaster recovery and crisis management — tested, with the test report and what failed in it.
- Supply-chain security — the register of who you depend on, maintained rather than compiled once.
- Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
- Policies to assess the effectiveness of the measures — the one most often missing, because it requires measuring yourself.
- Cyber hygiene practices and training — attendance and content, not a completion percentage.
- Cryptography and encryption policies — and the configuration that proves the policy is what is deployed.
- Human resources security, access control policies and asset management.
- Multi-factor authentication and secured communications — including the exceptions, and who approved each one.
The management body must approve these measures and supervise their implementation, must be trained itself, and can be held responsible for failures. That responsibility has a number attached: administrative fines reach €10 million or 2% of worldwide annual turnover, whichever is higher, for essential entities, and €7 million or 1.4% for important ones. For essential entities the authorities can additionally suspend a certification or authorisation and temporarily bar an individual from exercising management functions.
Which is why every one of the ten needs a named owner and a date, rather than a department.
A control you cannot evidence is, to a supervisor, a control you do not have.
This is the whole practical difference between a NIS2 programme that survives contact with a supervisor and one that does not. The work is not writing the policy. It is arranging for the policy to leave a trace every time it operates.
When something happens
The reporting chain, and where each clock actually starts
A significant incident triggers three filings: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month of that 72-hour notification — not one month from the incident. If the incident is still running at that point, a progress report takes its place and the final report follows a month after the incident is handled. The competent authority may also ask for an intermediate status update, and trust service providers and DNS or TLD entities have their own accelerated arrangements. Notifications go through the ILR's SERIMA platform.
Twenty-four hours sounds generous until you count what has to happen inside it: somebody has to notice, somebody has to judge significance, and somebody with authority has to decide to notify a regulator. That chain is what breaks, and it breaks on a Saturday. It is also why we treat the notification decision as a human approval point with a named person and a deputy, rather than a step in a runbook.
From the work
Where preparation usually breaks
The group calculation was never done
Headcount is counted locally, the linked and partner enterprises are not, and a subsidiary concludes it is out of scope. This is the most common false negative and the cheapest one to check.
The supplier register is a snapshot
Assembled once for the deadline, never updated, and already wrong. A register that is not maintained is worse than none, because it produces confident answers that are false.
Continuity is documented, not rehearsed
The plan describes a failover nobody has performed. The first real execution then happens during the incident, which is the most expensive possible time to discover the runbook was theoretical.
Nobody measures effectiveness
The law asks for policies to assess whether the measures work. This is the obligation most often absent entirely, and the easiest one for a supervisor to test.
Our part
What we do on NIS2, and what we do not
We work on the technical and operational side of the obligation: establishing the position, building registers your team can maintain, rehearsing continuity for real, implementing and evidencing controls in your own systems, and giving the incident chain a named owner and a tested route. That work sits mainly in ICT risk and resilience and cybersecurity.
This page is a practitioner summary, not legal advice. We do not advise on your legal position, we do not determine your category for you as a matter of law, and we do not represent you before the ILR, the CSSF or any other authority. Where a question is genuinely legal — and scope questions frequently are — it belongs with a Luxembourg law firm, and we will say so rather than improvise.
Regulation notes
Or start from what is on your desk.
The practitioner pages — dated, sourced, and written for engineers and risk officers rather than for search engines.