What every organisation in Luxembourg needs to know

NIS 2

Directive NIS 2

Europe's landmark cybersecurity directive is now law in the Grand Duchy. On 6 May 2026, the law transposing the NIS2 Directive (EU 2022/2555) was published in the Mémorial and entered into application on 10 May 2026. Here is what changed, who it covers, and what your organisation must do next. 

Why NIS 2?

The original NIS Directive (2016) established the European Union's first common cybersecurity framework for critical infrastructure operators. NIS2 (Directive (EU) 2022/2555), adopted in December 2022, significantly expands its scope and strengthens cybersecurity, governance and incident reporting requirements across a broader range of sectors.

NIS2 also forms part of a wider European resilience framework alongside the CER Directive, DORA and the Cyber Resilience Act. For certain regulated sectors, such as financial services, sector-specific frameworks may already impose equivalent cybersecurity and incident reporting obligations, helping avoid unnecessary regulatory overlap.

Who is in scope?

NIS2 applies automatically where an entity falls within the scope of the Luxembourg NIS2 Law. As a general rule, the law applies to public or private entities operating in the sectors listed in Annex I or Annex II and qualifying as medium-sized enterprises or exceeding the applicable SME thresholds. However, the law also applies to certain entities regardless of size, including specific electronic communications providers, trust service providers, DNS providers, TLD registries, domain-name registration service providers, entities considered critical at national or regional level, entities identified as critical under the Luxembourg law on the resilience of critical entities, and entities of the public administration.

  • Energy (electricity, gas, oil, hydrogen)
  • Transport (air, rail, road, maritime)
  • Banking sector
  • Financial market infrastructure
  • Health & pharmaceutical
  • Drinking water & waste water
  • Digital infrastructure (DNS, cloud, CDN, data centres)
  • ICT service management (B2B)
  • Public administration
  • Space
  • Postal & courier services
  • Waste management
  • Chemical manufacturing
  • Food production & processing
  • Manufacturing (medical devices, electronics, machinery, vehicles)
  • Digital service providers (marketplaces, search engines, social platforms)
  • Research organisations

Essential vs important: two tiers, same obligations

The Luxembourg NIS2 Law distinguishes between essential and important entities. Essential entities include, among others, large entities in Annex I sectors, certain digital and trust-service providers regardless of size, public administration entities, entities designated as essential by the competent authority, entities identified as critical under the Luxembourg law on the resilience of critical entities, and former operators of essential services identified under the previous NIS framework. 

In-scope entities that do not qualify as essential are considered important entities. Both categories must implement the Article 12 cybersecurity risk-management measures, but they are subject to different supervisory regimes and sanction ceilings.

Large organisations in Annex I sectors, exceeding 250 employees and either €50 million in annual turnover or €43 million in annual balance sheet. Subject to proactive supervision, with audits possible at any time without a prior incident. Senior managers can face a temporary ban from exercising management functions for serious failures. Maximum sanction: €10 million or 2% of global turnover.

Medium-sized organisations in Annex I sectors and all qualifying Annex II entities. Subject to reactive supervision, with controls triggered by incidents or complaints. Maximum sanction: €7 million or 1.4% of global turnover.

What does NIS 2 require?

NIS2 introduces a comprehensive cybersecurity risk management framework designed to strengthen the resilience of organisations providing essential or important services across the European Union. Rather than prescribing specific technologies, the Directive adopts a risk-based approach requiring organisations to implement appropriate technical, operational and organisational measures proportionate to their risk exposure and criticality.

For a number of regulated digital service providers, these obligations are further detailed by Commission Implementing Regulation (EU) 2024/2690, which translates the high-level NIS2 requirements into more granular implementation expectations. Together, these frameworks establish a structured cybersecurity baseline covering governance, risk management, incident response, business continuity, supply chain security, access management and operational resilience.

The NIS2 cybersecurity framework is organised around 11 security domains and 46 supporting sub-domains, providing organisations with a comprehensive set of controls designed to improve cyber resilience, strengthen governance and enable supervisory authorities to assess compliance in a consistent manner. The figure below summarises the key domains that regulated entities are expected to address as part of their cybersecurity risk management programme.

Essential Elements of NIS2

Minimum Measures

NIS2 (Directive (EU) 2022/2555) requires Regulated Service Providers to implement cybersecurity risk management measures, further specified by Commission Implementing Regulation (EU) 2024/2690, across the following areas:

Essential Elements of NIS2
Incident reporting: the 24 hour / 72 hour / 1 month rule

When a significant incident occurs, one capable of causing severe operational disruption, financial loss or considerable damage: entities must follow a structured four-step reporting timeline. Missing a deadline is itself a sanctionable breach.

When a significant incident occurs, entities must follow a structured four-step reporting timeline. Missing a deadline is itself a sanctionable breach.

  • 24 hours: preliminary notification to ILR or CSSF, flagging any suspected malicious cause and cross-border impact.
  • 72 hours: formal notification with initial severity and impact assessment and indicators of compromise where available.
  • On request: interim status report at the request of the competent authority.
  • 1 month: final report including root cause analysis, corrective measures deployed and cross-border impact if any.

Cybersecurity as a board-level responsibility

One of the most significant changes introduced by NIS2 is the shift towards governance-driven cybersecurity. Management bodies must formally approve cybersecurity risk management measures, supervise their implementation and undergo regular training. For essential entities, senior managers can face a temporary ban from exercising management functions for serious failures. 

Temporary management bans may be requested for essential entities in specific circumstances, but the law expressly states that these temporary suspension or prohibition measures do not apply to public administration entities.

Cybersecurity is no longer an IT problem; it is a governance responsibility at board level.  

A progressive but enforceable supervisory regime

While Luxembourg's supervisory authorities have consistently promoted a pragmatic and educational approach to cybersecurity compliance, NIS2 introduces a significantly strengthened enforcement framework. Organisations are expected to demonstrate continuous progress towards compliance and maintain adequate cybersecurity risk management measures proportionate to their criticality and risk exposure.

Failure to comply may nevertheless lead to a range of supervisory and enforcement actions, including warnings, reprimands and administrative sanctions. For breaches of cybersecurity risk management and incident reporting obligations, fines may reach EUR 10 million or 2% of worldwide annual turnover for Essential Entities, and EUR 7 million or 1.4% of worldwide annual turnover for Important Entities, whichever is higher. 

In addition, the Luxembourg NIS2 Law provides for administrative fines of up to EUR 250,000 for certain other regulatory obligations, as well as periodic penalty payments of up to EUR 1,250 per day (capped at EUR 25,000) to compel remediation of non-compliance. These provisions reinforce the expectation that cybersecurity should be treated as a governance and operational priority rather than a purely technical matter.

The Luxembourg supervisory landscape

Luxembourg's NIS2 framework relies on a coordinated multi-authority model combining regulatory supervision, national coordination and operational response capabilities. While the ILR and CSSF are responsible for supervision and enforcement, the HCPN ensures national coordination and cyber crisis management, supported by dedicated incident response teams serving both public and private sector entities.

Category Authority Role (refined & Luxembourg‑specific)

Primary supervisory authority

ILR (Institut Luxembourgeois de Régulation)

Main NIS2 authority responsible for supervision, registration, and enforcement across most sectors, with defined legal powers and state-funded operational mandate

Financial sector authority

CSSF (Commission de Surveillance du Secteur Financier)

Competent authority for banking, financial market infrastructures, and ICT providers under financial supervision, ensuring alignment with sectoral regulation (e.g., DORA overlap)

Sectoral authorities

Relevant ministries / regulators (e.g. Health, Aviation)

Provide sector-specific supervision and expertise, complementing ILR depending on the criticality and nature of services

National coordination authority

HCPN (Haut-Commissariat à la Protection nationale)

Central coordination body acting as Single Point of Contact (SPOC), national cyber crisis authority, and ensuring cross-sector coordination and EU-level cooperation

Government CSIRT

GOVCERT.LU

Government CSIRT responsible for incident handling, detection, and response for public sector entities and critical state infrastructure, integrated under HCPN governance

Private / non-government CSIRT

CIRCL (Computer Incident Response Center Luxembourg)

CSIRT supporting private sector entities and municipalities, providing threat intelligence, incident response, and vulnerability management, operating under a Luxembourg-specific hybrid model (public-private structure)

Your next steps

The law is in force. Supervision is active from day one. Here is a structured path to compliance, in order of urgency.

Check your NACE code against the 18 covered sectors and assess headcount and turnover at consolidated group level. FEDIL's NIS2 Forum and the ILR FAQ are good starting points if your situation is unclear.

Registration is a legal obligation. Non-registration does not exempt you from compliance and is itself a sanctionable breach. The ILR portal has been open since April 2026 at ilr.lu.

Map your current cybersecurity posture against the 10 required domains. Prioritise quick wins (MFA, patch management, incident response playbook) alongside longer-term structural work like supply chain audits.

NIS 2 requires management bodies to formally approve security measures. Bring the topic to your board before an auditor does. Frame it as a governance and legal risk, not just an IT matter.

The early warning deadline is demanding. Test your ability to detect, escalate and notify the ILR within 24 hours before an incident forces you to do it for the first time under pressure.

NIS 2 holds you accountable for your suppliers' security posture. Review direct vendors and service providers; update contracts to include minimum security requirements and audit rights.

ISO 27001 is not sufficient on its own. If your organisation is already certified, that is a strong foundation. But NIS 2 adds specific notification timelines (24 hours/72 hours/1 month), mandatory board governance obligations, and ILR-specific compliance evidence that an ISO certificate alone does not cover. A gap analysis against NIS 2's specific requirements is always needed.

Our services

PwC Luxembourg provides end-to-end support across your NIS2 compliance journey, including:

  • Scoping assessments to determine your classification as an essential or important entity.
  • Gap analysis against Article 12 requirements and remediation planning.
  • Governance and operating model design, including board-level accountability frameworks.
  • Implementation of cybersecurity risk management frameworks aligned with NIS2.
  • Preparation for ILR and CSSF supervision, including SERIMA incident notification readiness.

Contact us

Simon Petitjean

Partner, Cybersecurity Leader, PwC Luxembourg

Tel: +352 62133 43 74

Frédéric Chapelle

Advisory Partner, Technology, PwC Luxembourg

Tel: +352 62133 41 85

Maxime Pallez

Cybersecurity Director, PwC Luxembourg

Tel: +352 62133 41 66

Follow us