NIS2 in Luxembourg — the last transposition, a regulator borrowed from telecoms, and two CSIRTs.
Luxembourg was the Union's last mover: the law of 5 May 2026 entered into force on 10 May 2026 — roughly nineteen months after the directive's deadline — repealing the NIS1 law of 28 May 2019. The lead competent authority is the ILR, the Institut luxembourgeois de Régulation: a regulator built for telecoms and utilities, now supervising most NIS2 sectors and running both the registration portal and SERIMA, the incident-notification platform. The CSSF carves out banking, financial-market infrastructure and the digital-infrastructure entities it already supervises.
The CSIRT structure is split by sector: CIRCL, operated by the Luxembourg House of Cybersecurity, serves private-sector entities and municipalities and coordinates vulnerability disclosure, while GOVCERT.LU — run by the HCPN — remains the governmental CSIRT for the public sector. HCPN's own role under the new law narrows to crisis-management contact.
Who it applies to
Essential and important entities across the NIS2 sectors, self-registering with the competent authority via the ILR's online portal by 10 July 2026 — two months after entry into force, with failure to register itself a sanctionable breach. Incident reporting follows the directive standard — 24-hour early warning, 72-hour notification, one-month final report — filed through SERIMA; for CSSF-supervised financial entities, DORA's four-hour initial notification satisfies the NIS2 early warning.
The clock
Competent authority: ILR (lead) · CSSF (financial sector). Transposition: Loi du 5 mai 2026 (Mémorial A n° 225).
| When | What happens |
|---|---|
| 5 May 2026 | NIS2 law adopted · repeals the NIS1 law of 28 May 2019 |
| 10 May 2026 | Law enters into force · ILR portal opens |
| 10 Jul 2026 | Self-registration deadline — failure is itself sanctionable |
| Ongoing | Incident reporting via SERIMA · 24 h, 72 h, one month |
A financial center supervised by a telecoms regulator
Luxembourg's institutional choices surprise twice. First, the ILR — a multi-sector utility regulator — leads NIS2 supervision for most of the economy, while the CSSF keeps the financial sector that dominates the country's profile. Second, incident response splits along public and private lines: CIRCL for companies and municipalities, GOVCERT.LU for the state. For the financial entities that make Luxembourg outsized in NIS2 terms, the DORA interaction does real work: the CSSF's four-hour DORA notification doubles as the NIS2 24-hour early warning, so one clock serves both regimes — but only if the filing discipline is built once and shared. TruSecure maps NIS2 and DORA onto the same control model per entity: CSSF or ILR routing recorded, SERIMA reporting staged, and overlapping obligations evidenced once.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Luxembourg transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Self-register via the ILR portal by 10 Jul 2026 | Entity profile · registration filed, authority routing recorded |
| Resolve ILR vs CSSF supervision per entity | Applicability engine · sector routing, DORA overlap flagged |
| Report incidents via SERIMA: 24 h, 72 h, one month | Incident workflow · SERIMA stages pre-built, DORA 4 h clock where applicable |
| Meet the security-measures duty with evidence | Control library · continuously monitored, evidence attached |
| Coordinate vulnerability disclosure via CIRCL | Supplier-risk workspace · disclosure channel and contacts recorded |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- ILR registration
- filed 02 Jun 2026 · within the two-month window
- Supervision routing
- CSSF · DORA overlap mapped, one shared clock
- Controls evidenced
- 83/97 · 14 open, each with an owner and a date
- Incident reports
- 1 filed · SERIMA, DORA 4 h satisfied the 24 h warning
- Export
- sealed · sha256:5a47...c812
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIS2, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Where teams usually start
With a demo walked through by TruSecure — your supervision routing across ILR and CSSF resolved, your registration confirmed against the 10 July 2026 deadline, and your NIS2 and DORA obligations mapped onto one control model. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Luxembourg by ILR (lead) · CSSF (financial sector). TruSecure determines applicability against Luxembourg's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.