NIS2 in Luxembourg: who is accountable, and what to do first
Published
If you run a company in Luxembourg, you have probably heard that "NIS2" is now something you are supposed to deal with. What is usually missing from that sentence is the part that matters most to you: who inside the company actually carries the obligation, and what the first sensible move is.
The short version is that this is not only an IT topic, and it is not something you can fully delegate and forget. Luxembourg transposed NIS2 through the Act of 5 May 2026, which has applied since 10 May 2026 1. The Institut Luxembourgeois de Régulation (ILR) is the competent authority for most sectors. The CSSF is competent for banking, financial-market infrastructure and certain digital-infrastructure and ICT-service activities that fall under its supervision 1. In other words, the Luxembourg framework is now in force—and the correct regulator depends on what your entity does 2.
This article helps you answer three practical questions: are we likely to be in scope under Luxembourg law, who inside our organisation is accountable, and what should we do now? It provides a first-pass scope check and links to the official Luxembourg tools. Borderline cases may still need confirmation from the relevant authority or a qualified adviser.
Registration deadline already passed. Entities within scope were required to self-register with their competent authority by 10 July 2026. If you believe your organisation is in scope and has not registered, complete the relevant process promptly. For most organisations the starting point is the ILR; entities supervised by the CSSF should confirm the applicable route with the CSSF 2.
1. The management body is accountable — not the IT team alone
Luxembourg's NIS2 Act places cybersecurity governance with the management bodies of essential and important entities. They must approve the organisation's cybersecurity risk-management measures and oversee their implementation. Their members must also follow appropriate training so that they can understand the risks and make informed decisions 1 3.
Read that again with your own role in mind. The first step is therefore to identify the management body under your organisation's legal form and governance documents. Depending on the organisation, that may be its board of directors, board of managers or authorised management. An owner is included only where that person also holds the relevant management role. Your IT lead, security team or external partner can design and run the measures. What remains with the management body is approving the approach, providing appropriate resources, reviewing material risks and overseeing whether the measures are working.
This is usually the moment the topic stops feeling abstract. It is no longer "should IT look at this?" It is "what am I, as the person accountable, expected to have reviewed and approved?"
2. What being "in scope" should trigger — operationally
Let us separate two questions that often get tangled together.
The first question is whether the organisation is in scope under Luxembourg's NIS2 Act. Start with the legal entity's actual services and activities—not just its general industry label. Match them against the entity types in Annex I or II of the Luxembourg Act, apply the size rules, and then check whether an exception or individual designation brings the entity into scope regardless of size 1.
For a first check, use the ILR applicability simulator and the ILR scope guidance. Then compare the result with the Luxembourg Act and its annexes. If the result remains unclear, confirm it with the relevant authority or a qualified adviser 2.
Scope comes first because it determines your legal duties, competent authority and registration route. But you do not need to pause sensible security work while resolving a borderline case. Risk assessment, incident preparation, access control, reliable backups and management oversight are good practices for any organisation—and required building blocks for organisations covered by the Luxembourg Act. In practice that means you have assigned day-to-day responsibility and clear decision rights, while the management body retains approval and oversight.
The Luxembourg Act is already in force. A documented plan is useful, but an organisation in scope must also implement the applicable measures, complete its registration and be ready to meet the incident-reporting deadlines.
3. Quick reference: what "in scope" looks like vs. what it doesn't
Two things generally have to line up before NIS2 applies to your company: you operate in one of the regulated sectors, and you are at least a medium-sized business — unless you fall into one of a few special categories that are covered whatever your size. As a rule, "medium-sized or large" under the applicable calculation rules means generally at least 50 staff, or annual turnover or annual balance-sheet total above €10 million; partner and linked enterprises may need to be included in the calculation 4. Annexes I and II of Luxembourg's NIS2 Act cover specified entity types across 18 sectors: 11 sectors in Annex I and seven in Annex II 1. Being broadly active in one of those sectors is not enough by itself; the organisation must match one of the listed types of entity, service or activity.
Any "not in scope" conclusion is conditional, not permanent. Scope is assessed for the legal entity, but its size calculation may have to include data from partner and linked enterprises: the ILR explains that linked-enterprise data is generally included in full, while partner-enterprise data is included proportionately 2 4, so a business that looks small on its own can cross the line. An organisation can also be covered regardless of size where the Luxembourg Act expressly includes its type of activity or where the competent authority identifies it on grounds such as being the sole provider in Luxembourg of a service essential to critical societal or economic activities 1. There is no single headcount or revenue figure that decides scope on its own.
Essential or important: what changes?
Once you know that you are in scope, determine whether Luxembourg's Act classifies the organisation as an essential or important entity. Both categories must implement the applicable cybersecurity risk-management measures and report significant incidents. The main difference is supervision: essential entities can be supervised proactively and after an issue, while important entities are generally supervised after the authority receives evidence that they may not be complying 1 2.
A note for regulated financial firms. If your organisation is supervised by the CSSF, check the applicable route with the CSSF before relying on the ILR process described here. For financial entities covered by DORA, the CSSF's DORA rules and reporting process may govern ICT risk and major-incident reporting. Those incidents are reported through the CSSF's eDesk or API process—not through the ILR route described below 5.
When it matters, confirm your position against the ILR's published scope guidance and applicability simulator and the Act itself, not a summary like this one.
4. A practical NIS2 record: decisions, measures, gaps and evidence
When owners ask "what do I actually do first?", start here. Complete and document a first-pass scope assessment immediately. In parallel, you can begin building a practical record of the security work that is useful regardless of scope. Once scope and classification are confirmed, align that record with the requirements and reporting route of the ILR or CSSF.
The management review. Bring the management body together with the people who run IT, security and business continuity. Confirm the main cyber risks, the measures already in place, the gaps that remain, and the decisions or resources that management must approve. Record the decisions, owners and target dates.
The customer-evidence pack. Reuse selected parts of that record to answer security questions from customers and procurement teams. This is a commercial benefit of doing the work well, not a separate requirement of Luxembourg's NIS2 Act.
The compliance record. Keep one clear record of your scope assessment, risk analysis, management approvals, measures in place, open gaps and remediation dates. If the ILR or CSSF asks how you manage cyber risk, you should be able to show both what was decided and what has actually been implemented.
Essential entities supervised by the ILR should also prepare for the annual information the ILR says it will require: a questionnaire covering the main cyber-risk scenarios, the organisation's security objectives and an action plan for outstanding improvements. The exact submission dates and technical process will be set in the ILR's implementing rules 2.
These are not three separate binders. They are three uses of the same reliable evidence base: management uses it to make decisions, customers may see selected assurance material, and the competent authority can request evidence relevant to its supervision.
Set up the incident-reporting route now
For organisations supervised by the ILR, a significant incident triggers an early warning through SERIMA within 24 hours of becoming aware of it, an updated notification within 72 hours, and a final report within one month of the 72-hour notification. Decide in advance who can assess significance, who can submit the report and who is available outside normal working hours 6.
CSSF-supervised organisations should follow the CSSF process that applies to them, including the dedicated DORA reporting route where relevant 5.
5. Where Cyvalent fits — software, services, or both
If the management review shows that you need help turning decisions, measures and evidence into a maintained NIS2 record, that is where Cyvalent can help.
Cyvalent works through software and services together. Cyvalent RGX (Risk, Governance & eXecution), our platform, is designed to help organise the NIS2 record: the controls you rely on, the evidence behind them, the risks you have decided to manage, and the readiness follow-up that keeps the record current. Where you need people rather than tooling — to run the owner review, structure the evidence, or stand up governance you can defend — Cyvalent 360 Cyber Services provides expert-led support, and the same team can pair the two so the software and the services reinforce each other.
To be clear about what this is and is not: this is help organising your operating file and your readiness work. It is not a compliance guarantee, and it does not replace the legal determination of whether NIS2 applies to your company. That determination remains your organisation's responsibility and should be checked against the Act and guidance from the relevant authority—the ILR or CSSF, as applicable. What we can do is make sure that once you know where you stand, the work of staying there is organised, current, and defensible.
That is the difference between scrambling to prove something under deadline pressure and running a security program you can stand behind.
In short
- Luxembourg's NIS2 Act places approval and oversight with the organisation's management body—not with IT alone.
- Scope depends on the legal entity’s activities, size, applicable exceptions and any individual designation; use the ILR tools and confirm borderline cases.
- If you are in scope, identify the correct authority and registration route immediately. The 10 July 2026 registration deadline has passed.
- Build the risk-management measures, management record and incident-reporting process together; evidence is useful only when it reflects measures that are actually operating.
Not sure where your NIS2 accountability sits?
Cyvalent helps Luxembourg management bodies run the review and turn the results into a clear, maintained NIS2 record — through founder-led 360 Cyber Services / CISOaaS and the Cyvalent RGX cyber GRC platform.
Frequently asked questions
Who is accountable for NIS2 in a Luxembourg company?
Under Luxembourg’s NIS2 Act, the management body of an essential or important entity must approve the cybersecurity risk-management measures and oversee their implementation. Which people that includes depends on the company’s legal form and governance arrangements. The IT team or an external partner can run the work, but the management body retains approval and oversight.
Has Luxembourg transposed NIS2, and when did it take effect?
Yes. Luxembourg transposed the EU NIS2 Directive through the Act of 5 May 2026, which entered into force on 10 May 2026. The framework is now in force, with named competent authorities behind it—the ILR for most sectors and the CSSF for the financial sector and certain supervised activities.
Who is the NIS2 regulator in Luxembourg?
Luxembourg has two competent authorities under its NIS2 Act. The ILR covers most sectors. The CSSF covers banking, financial-market infrastructure and certain digital-infrastructure and ICT-service activities that fall under its supervision. Most SMEs should start with the ILR’s guidance, while CSSF-supervised firms should confirm their route with the CSSF.
How do I know if my company is in scope of NIS2?
Check four things: the services or activities performed by the legal entity; whether they match an entity type in Annex I or II of Luxembourg’s Act; the entity’s size after applying the partner- and linked-enterprise rules; and any inclusion or designation that applies regardless of size. Use the ILR simulator as a first check, then document the conclusion and confirm borderline cases.
What should I do first if NIS2 might apply to us?
First, complete and document the scope assessment. If you are in scope, identify the competent authority and complete registration immediately if it is still outstanding. Next, confirm the management body, assign day-to-day responsibility, arrange management training, assess gaps in the required measures, establish the incident-reporting process and approve a remediation plan with owners and dates.
Can I fully delegate NIS2 to my IT team?
No. NIS2 is not only an IT topic and cannot be fully delegated and forgotten. Luxembourg’s NIS2 Act makes approval and oversight of the cybersecurity risk-management measures the management body’s responsibility. You can — and should — rely on your IT lead or a partner to do the work; what you cannot do is treat cybersecurity governance as something that happens entirely below your level.
Sources & References
Last checked:
EU legislation
[3] European Parliament & Council. Directive (EU) 2022/2555 (NIS2) — Art. 20 (management-body approval, oversight, training), Art. 21 (risk-management measures), Annexes I-II (sectors: 11 high-criticality and 7 other critical). Status/date: in force; adopted 14 Dec 2022. Source: EUR-Lex. https://eur-lex.europa.eu/eli/dir/2022/2555/oj
[4] European Commission. Commission Recommendation 2003/361/EC concerning the definition of micro, small and medium-sized enterprises — SME size thresholds and linked-enterprise assessment referenced for NIS2 size criteria. Status/date: adopted 6 May 2003. Source: EUR-Lex. https://eur-lex.europa.eu/eli/reco/2003/361/oj
Luxembourg authorities
[1] Grand-Duché de Luxembourg. Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité (Mém. A no 225) — Luxembourg NIS2 transposition; ILR competent for most sectors, CSSF for the financial sector and certain supervised activities; HCPN national single point of contact. Status/date: in force 10 May 2026; initial self-registration deadline passed on 10 July 2026. Source: Legilux. https://legilux.public.lu/eli/etat/leg/loi/2026/05/05/a225/jo
[2] ILR. NIS2 — scope, security measures, incident notification (SERIMA) — Luxembourg NIS2 guidance for scope, self-registration, security measures, and incident notification. Status/date: accessed July 2026. Source: ILR. https://www.ilr.lu/en/sectors/niss/nis-2/
[5] CSSF. ICT and cyber risk – for DORA entities — DORA applicability, Luxembourg competent authorities (CSSF and CAA), and the eDesk reporting process for DORA entities. Source: CSSF. https://www.cssf.lu/en/ict-and-cyber-risk-for-dora-entities/
[6] ILR. Incident notification (SERIMA) — Luxembourg NIS2 incident-reporting process and the SERIMA reporting portal. Source: ILR. https://www.ilr.lu/en/sectors/niss/incident-notification/

