The original NIS Directive (2016) established the European Union's first common cybersecurity framework for critical infrastructure operators. NIS2 (Directive (EU) 2022/2555), adopted in December 2022, significantly expands its scope and strengthens cybersecurity, governance and incident reporting requirements across a broader range of sectors.
NIS2 also forms part of a wider European resilience framework alongside the CER Directive, DORA and the Cyber Resilience Act. For certain regulated sectors, such as financial services, sector-specific frameworks may already impose equivalent cybersecurity and incident reporting obligations, helping avoid unnecessary regulatory overlap.
NIS2 applies automatically where an entity falls within the scope of the Luxembourg NIS2 Law. As a general rule, the law applies to public or private entities operating in the sectors listed in Annex I or Annex II and qualifying as medium-sized enterprises or exceeding the applicable SME thresholds. However, the law also applies to certain entities regardless of size, including specific electronic communications providers, trust service providers, DNS providers, TLD registries, domain-name registration service providers, entities considered critical at national or regional level, entities identified as critical under the Luxembourg law on the resilience of critical entities, and entities of the public administration.
The Luxembourg NIS2 Law distinguishes between essential and important entities. Essential entities include, among others, large entities in Annex I sectors, certain digital and trust-service providers regardless of size, public administration entities, entities designated as essential by the competent authority, entities identified as critical under the Luxembourg law on the resilience of critical entities, and former operators of essential services identified under the previous NIS framework.
In-scope entities that do not qualify as essential are considered important entities. Both categories must implement the Article 12 cybersecurity risk-management measures, but they are subject to different supervisory regimes and sanction ceilings.
NIS2 introduces a comprehensive cybersecurity risk management framework designed to strengthen the resilience of organisations providing essential or important services across the European Union. Rather than prescribing specific technologies, the Directive adopts a risk-based approach requiring organisations to implement appropriate technical, operational and organisational measures proportionate to their risk exposure and criticality.
For a number of regulated digital service providers, these obligations are further detailed by Commission Implementing Regulation (EU) 2024/2690, which translates the high-level NIS2 requirements into more granular implementation expectations. Together, these frameworks establish a structured cybersecurity baseline covering governance, risk management, incident response, business continuity, supply chain security, access management and operational resilience.
The NIS2 cybersecurity framework is organised around 11 security domains and 46 supporting sub-domains, providing organisations with a comprehensive set of controls designed to improve cyber resilience, strengthen governance and enable supervisory authorities to assess compliance in a consistent manner. The figure below summarises the key domains that regulated entities are expected to address as part of their cybersecurity risk management programme.
Minimum Measures
NIS2 (Directive (EU) 2022/2555) requires Regulated Service Providers to implement cybersecurity risk management measures, further specified by Commission Implementing Regulation (EU) 2024/2690, across the following areas:
When a significant incident occurs, one capable of causing severe operational disruption, financial loss or considerable damage: entities must follow a structured four-step reporting timeline. Missing a deadline is itself a sanctionable breach.
When a significant incident occurs, entities must follow a structured four-step reporting timeline. Missing a deadline is itself a sanctionable breach.
One of the most significant changes introduced by NIS2 is the shift towards governance-driven cybersecurity. Management bodies must formally approve cybersecurity risk management measures, supervise their implementation and undergo regular training. For essential entities, senior managers can face a temporary ban from exercising management functions for serious failures.
Temporary management bans may be requested for essential entities in specific circumstances, but the law expressly states that these temporary suspension or prohibition measures do not apply to public administration entities.
Cybersecurity is no longer an IT problem; it is a governance responsibility at board level.
While Luxembourg's supervisory authorities have consistently promoted a pragmatic and educational approach to cybersecurity compliance, NIS2 introduces a significantly strengthened enforcement framework. Organisations are expected to demonstrate continuous progress towards compliance and maintain adequate cybersecurity risk management measures proportionate to their criticality and risk exposure.
Failure to comply may nevertheless lead to a range of supervisory and enforcement actions, including warnings, reprimands and administrative sanctions. For breaches of cybersecurity risk management and incident reporting obligations, fines may reach EUR 10 million or 2% of worldwide annual turnover for Essential Entities, and EUR 7 million or 1.4% of worldwide annual turnover for Important Entities, whichever is higher.
In addition, the Luxembourg NIS2 Law provides for administrative fines of up to EUR 250,000 for certain other regulatory obligations, as well as periodic penalty payments of up to EUR 1,250 per day (capped at EUR 25,000) to compel remediation of non-compliance. These provisions reinforce the expectation that cybersecurity should be treated as a governance and operational priority rather than a purely technical matter.
Luxembourg's NIS2 framework relies on a coordinated multi-authority model combining regulatory supervision, national coordination and operational response capabilities. While the ILR and CSSF are responsible for supervision and enforcement, the HCPN ensures national coordination and cyber crisis management, supported by dedicated incident response teams serving both public and private sector entities.
| Category | Authority | Role (refined & Luxembourg‑specific) |
Primary supervisory authority |
ILR (Institut Luxembourgeois de Régulation) |
Main NIS2 authority responsible for supervision, registration, and enforcement across most sectors, with defined legal powers and state-funded operational mandate |
| Financial sector authority | CSSF (Commission de Surveillance du Secteur Financier) |
Competent authority for banking, financial market infrastructures, and ICT providers under financial supervision, ensuring alignment with sectoral regulation (e.g., DORA overlap) |
| Sectoral authorities | Relevant ministries / regulators (e.g. Health, Aviation) |
Provide sector-specific supervision and expertise, complementing ILR depending on the criticality and nature of services |
| National coordination authority | HCPN (Haut-Commissariat à la Protection nationale) |
Central coordination body acting as Single Point of Contact (SPOC), national cyber crisis authority, and ensuring cross-sector coordination and EU-level cooperation |
Government CSIRT |
GOVCERT.LU |
Government CSIRT responsible for incident handling, detection, and response for public sector entities and critical state infrastructure, integrated under HCPN governance |
Private / non-government CSIRT |
CIRCL (Computer Incident Response Center Luxembourg) |
CSIRT supporting private sector entities and municipalities, providing threat intelligence, incident response, and vulnerability management, operating under a Luxembourg-specific hybrid model (public-private structure) |
The law is in force. Supervision is active from day one. Here is a structured path to compliance, in order of urgency.
ISO 27001 is not sufficient on its own. If your organisation is already certified, that is a strong foundation. But NIS 2 adds specific notification timelines (24 hours/72 hours/1 month), mandatory board governance obligations, and ILR-specific compliance evidence that an ISO certificate alone does not cover. A gap analysis against NIS 2's specific requirements is always needed.
PwC Luxembourg provides end-to-end support across your NIS2 compliance journey, including: