Skip to main content
NIS2 · LUXEMBOURG

NIS2 in Luxembourg — the last transposition, a regulator borrowed from telecoms, and two CSIRTs.

Luxembourg was the Union's last mover: the law of 5 May 2026 entered into force on 10 May 2026 — roughly nineteen months after the directive's deadline — repealing the NIS1 law of 28 May 2019. The lead competent authority is the ILR, the Institut luxembourgeois de Régulation: a regulator built for telecoms and utilities, now supervising most NIS2 sectors and running both the registration portal and SERIMA, the incident-notification platform. The CSSF carves out banking, financial-market infrastructure and the digital-infrastructure entities it already supervises.

The CSIRT structure is split by sector: CIRCL, operated by the Luxembourg House of Cybersecurity, serves private-sector entities and municipalities and coordinates vulnerability disclosure, while GOVCERT.LU — run by the HCPN — remains the governmental CSIRT for the public sector. HCPN's own role under the new law narrows to crisis-management contact.

Who it applies to

Essential and important entities across the NIS2 sectors, self-registering with the competent authority via the ILR's online portal by 10 July 2026 — two months after entry into force, with failure to register itself a sanctionable breach. Incident reporting follows the directive standard — 24-hour early warning, 72-hour notification, one-month final report — filed through SERIMA; for CSSF-supervised financial entities, DORA's four-hour initial notification satisfies the NIS2 early warning.

The clock

Competent authority: ILR (lead) · CSSF (financial sector). Transposition: Loi du 5 mai 2026 (Mémorial A n° 225).

NIS2 in Luxembourg · timeline
WhenWhat happens
5 May 2026NIS2 law adopted · repeals the NIS1 law of 28 May 2019
10 May 2026Law enters into force · ILR portal opens
10 Jul 2026Self-registration deadline — failure is itself sanctionable
OngoingIncident reporting via SERIMA · 24 h, 72 h, one month

A financial center supervised by a telecoms regulator

Luxembourg's institutional choices surprise twice. First, the ILR — a multi-sector utility regulator — leads NIS2 supervision for most of the economy, while the CSSF keeps the financial sector that dominates the country's profile. Second, incident response splits along public and private lines: CIRCL for companies and municipalities, GOVCERT.LU for the state. For the financial entities that make Luxembourg outsized in NIS2 terms, the DORA interaction does real work: the CSSF's four-hour DORA notification doubles as the NIS2 24-hour early warning, so one clock serves both regimes — but only if the filing discipline is built once and shared. TruSecure maps NIS2 and DORA onto the same control model per entity: CSSF or ILR routing recorded, SERIMA reporting staged, and overlapping obligations evidenced once.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Luxembourg transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Luxembourg requirements · how TruSecure answers them
What the law asksWhere it is answered
Self-register via the ILR portal by 10 Jul 2026Entity profile · registration filed, authority routing recorded
Resolve ILR vs CSSF supervision per entityApplicability engine · sector routing, DORA overlap flagged
Report incidents via SERIMA: 24 h, 72 h, one monthIncident workflow · SERIMA stages pre-built, DORA 4 h clock where applicable
Meet the security-measures duty with evidenceControl library · continuously monitored, evidence attached
Coordinate vulnerability disclosure via CIRCLSupplier-risk workspace · disclosure channel and contacts recorded

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Luxembourg NIS2 readiness file · excerptSample data
ILR registration
filed 02 Jun 2026 · within the two-month window
Supervision routing
CSSF · DORA overlap mapped, one shared clock
Controls evidenced
83/97 · 14 open, each with an owner and a date
Incident reports
1 filed · SERIMA, DORA 4 h satisfied the 24 h warning
Export
sealed · sha256:5a47...c812

Compliance roadmap

Typical timeline: 3–6 months to full compliance readiness

  1. 1Weeks 1–4

    Assessment

    Gap analysis against NIS2, risk review, remediation plan.

  2. 2Weeks 5–12

    Implementation

    Controls deployed, policies written, evidence flowing.

  3. 3Weeks 13–16

    Audit prep

    Gaps closed, evidence package assembled for the authority.

  4. 4Weeks 17–24

    Steady state

    Continuous evidence, reports on demand, drift alerts.

With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.

Where teams usually start

With a demo walked through by TruSecure — your supervision routing across ILR and CSSF resolved, your registration confirmed against the 10 July 2026 deadline, and your NIS2 and DORA obligations mapped onto one control model. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Luxembourg by ILR (lead) · CSSF (financial sector). TruSecure determines applicability against Luxembourg's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

If we're a Luxembourg financial entity, do NIS2 and DORA both apply?
Often yes — Luxembourg's outsized financial-services sector means NIS2 and DORA frequently overlap for the same entity. CSSF-supervised entities' four-hour DORA initial notification counts as the NIS2 24-hour early warning, and TruSecure maps both regimes onto the same control model so overlapping obligations don't mean duplicated evidence.