NIS2 in Luxembourg: the concrete obligations and where to start

NIS2 compliance is not declared, it is evidenced through documents. Since 3 August, the ILR has published the templates for those documents: they show precisely what is expected.

By

11 min read

Empty boardroom table and chairs in a meeting room
Photo: Benjamin Child on Unsplash

NIS2 compliance is not declared. It is evidenced, through documents the authority can ask for at any time. The question is which documents, and in how much detail.

Since 3 August 2026, the answer is public: the Institut Luxembourgeois de Régulation, Luxembourg’s regulatory authority, has published four deliverable templates showing exactly what it expects (ILR). No legal text goes into that level of detail.

This article assumes you already know you are in scope. If you do not, start with the two-question test that tells you whether your company is affected. What follows is the next step: what to do, in which order, and how to prove it.

Key takeaways

  • The law requires ten families of measures, proportionate to the size and exposure of the company.
  • The risk analysis is the mandatory starting point: article 12 of the law requires every entity to carry out its own, using the method of its choice.
  • A significant incident triggers an early warning within 24 hours, a formal notification within 72 hours and a final report within one month.
  • Essential entities submit three deliverables to the ILR each year; important entities are exempt unless non-compliance is suspected.
  • The Fit4Cybersecurity self-assessment and the MONARC risk analysis tool are Luxembourgish, free, and enough to get started.

The ten families of measures, in business language

The law does not ask you to buy ten tools. It asks that ten areas be covered and documented. The list comes from article 21 of the European directive, which the law of 5 May 2026 transposes (EUR-Lex).

What the text saysWhat it means for an SME
Policies on risk analysis and information system securityA document listing what can go wrong, and what you do to prevent it
Incident handlingWho does what when it happens, written down before it happens
Business continuity, backup management, disaster recovery, crisis managementBackups that are tested, not merely configured
Supply chain securityYou answer for the risk introduced by your direct suppliers
Security in acquisition, development and maintenance, vulnerability handling and disclosureA channel to receive vulnerability reports, and a patching procedure
Policies to assess the effectiveness of the measuresYou check that the measures work, and keep evidence of the check
Basic cyber hygiene and cybersecurity trainingPasswords, updates, staff awareness
Cryptography and encryptionA written position on what is encrypted, and why
Human resources security, access control, asset managementKnowing who has access to what, and removing access when people leave
Multi-factor authentication, secured communicationsStrong authentication on sensitive access

The operative word is proportionate. The text explicitly requires the entity’s degree of exposure, its size and the cost of implementation to be taken into account. A forty-person SME is not held to a bank’s arrangements. It is held to being able to explain why its arrangements match its risk, which is a different requirement.

Where to start from zero

With the risk analysis. The other nine areas follow from it: without it, you do not know what to protect first, and above all you cannot justify your choices.

Step 1 — Measure where you stand. The Fit4Cybersecurity self-assessment from SECURITYMADEIN.LU is anonymous and free. Thirteen pages of questions, about fifteen minutes, available in French, German and English. Above 65 out of 100 you can request a fuller CASES diagnosis, carried out free of charge by an expert (SECURITYMADEIN.LU). It is the cheapest entry point available, and it is Luxembourgish.

Step 2 — Carry out your own risk analysis. This is an obligation under article 12 of the law. The ILR states that the choice of method rests with the entity, and that it may request the detailed analysis together with evidence of its effective implementation (ILR). In other words, a dormant document will not do. MONARC, a risk analysis method and platform developed in Luxembourg, is built for precisely this exercise.

Step 3 — Describe the measures already in place. Many companies discover at this stage that they already cover six or seven of the ten areas without ever having formalised it. The work is to write it down, not to start over.

Step 4 — Write the multi-year action plan. What is missing, with a timeline. A plan spreading measures over three years is defensible; the absence of a plan is not.

Step 5 — Have the board approve all of it. This is not a closing formality: it is an obligation resting on the management body by name, and it conditions the validity of everything else.

The ILR’s four templates, and what they reveal

Three of the four templates correspond to the deliverables that essential entities notify annually: the description of measures in place, the analysis of the main cyber risk scenarios in multiple-choice form, and the multi-year action plan. The fourth, the list of dependencies on direct suppliers and service providers, will be requested only from certain entities, on a risk-based approach.

The templates are offered as a reference. Their value goes well beyond the entities required to complete them: they are, today, the best public indication of the level of detail the authority considers sufficient. An important entity that uses them to structure its documentation is working in its supervisor’s own format.

One misreading to avoid. The analysis of main risk scenarios is a lightweight supervisory tool, limited to predefined scenarios. The ILR states in plain terms that it does not exempt the entity from carrying out its own risk analysis under article 12. Completing the questionnaire and considering the obligation discharged would be an expensive mistake.

A final point, and it is temporary: the deadlines and technical arrangements will be set by ILR regulations still in preparation. The public consultations CP/N26/1 and CP/N26/2, which cover security measures and incident notification precisely, have been extended to 31 August 2026. A company in scope can still respond, and should at minimum read the drafts: they prefigure its obligations for next year.

What starts the clock: the notion of a significant incident

This is the point most guides skip, in favour of the table of deadlines. Yet the table is useless until you know what triggers it.

The law first defines an incident as an event compromising the availability, authenticity, integrity or confidentiality of data or services. Its article 14 then restricts notification to significant incidents, defined by two alternative criteria (ILR):

  • the incident has caused or is capable of causing severe operational disruption of the services, or financial loss for the entity;
  • it has affected or is capable of affecting other natural or legal persons by causing considerable material, bodily or non-material damage.

“Capable of causing” widens the scope considerably. Ransomware contained before encryption, but which could have halted production, falls within the definition.

Then comes the notification chain, addressed to the ILR through the SERIMA platform.

DeadlineDeliverableDetails
24 hours after detectionEarly warningMay be sent while the impact is still unmeasured, and even if the incident is not certainly significant. The authority or the CSIRT responds within 24 hours
72 hours after detectionFormal notificationUpdates the previous one. Intermediate information may be requested
1 month after the notificationFinal reportIf the incident is not closed, a one-month extension may be requested; an intermediate report then replaces the final report

The first row of that table is the most useful in practice: when in doubt, notify. The system is designed to receive an incomplete alert, not to punish excessive caution.

That leaves what you will have to write. The form asks you to qualify what makes the incident significant, using criteria known in advance: number and percentage of users affected, duration of the disruption, geographical spread, direct financial loss, bodily, non-material or material damage, reputational harm. A company that knows, before the incident, how many users it serves and what an hour of downtime costs will meet the 24-hour deadline. The others will spend the first night looking for the figures.

What the board has to do itself

Three obligations rest on the management body, and none can be delegated to the IT department.

It approves the risk-management measures. It supervises their implementation. And its members must follow training in cybersecurity.

That last obligation is frequently misread. The European text imposes training on the members of the management body, and merely encourages entities to offer similar training to their staff. It is the opposite of the common intuition, which treats awareness as an employee matter. The legislator’s reasoning is consistent: a director who does not understand the risk cannot arbitrate on the resources.

Essential or important: what the category really changes

It does not change the measures to be taken. It changes the supervision, and the administrative work that comes with it.

Essential entityImportant entity
Supervisory regimeEx ante and ex postEx post
Notification of security measuresMandatory, annualNot upfront
Notification of significant incidentsMandatoryMandatory
Non-significant incidents, near misses, cyber threatsVoluntaryVoluntary

An important entity is therefore not supervised upfront, but the exemption falls away in the presence of “evidence, indications or information” of non-compliance with the law. In plain terms: the first incident you notify can open scrutiny of everything else.

The fine ceilings follow the same graduated logic, 10 million euros or 2 % of worldwide turnover for essential entities, 7 million or 1.4 % for important ones, whichever is higher. The penalty regime is set out in detail in our analysis of the scope.

What it costs, and what costs nothing

No reliable costing specific to the Luxembourg market is publicly available. The ranges in circulation come from French providers selling the very service they are pricing: they are worthless as a benchmark. We will not invent others.

What can be stated, on the other hand, is what is free:

  • the Fit4Cybersecurity self-assessment and, above 65 out of 100, the CASES diagnosis carried out by an expert;
  • MONARC, to conduct the risk analysis;
  • the ILR’s four templates and the NIS Cooperation Group’s reference document on security measures.

The first real cost is therefore not the audit, it is internal time: someone has to own the subject. To fund it, the Fit 4 Digital diagnosis, co-financed by the State, includes a cybersecurity component in its digital maturity assessment.

One special case deserves the attention of IT service providers: European implementing regulation 2024/2690 of 17 October 2024 sets technical requirements that apply directly to certain categories of digital entities, including managed service providers and managed security service providers. For them, the expected level is already written down, and it is not open to negotiation.

Frequently asked questions

Do you need to hire a security officer to be compliant?

The law imposes no named function. It requires that the measures be taken, approved by the board and documented. In an SME this usually means an identified point person who owns the file, not a full-time role.

Can my IT provider carry the compliance for me?

It can carry out the measures. It cannot assume the obligation: that rests on the entity and its management body. It is also worth noting that your provider is itself part of your supply chain, and therefore of your risk analysis.

What if an incident happens on a Friday evening?

The 24-hour deadline runs from detection, weekends included. That is precisely why the early warning is designed to be sent with incomplete information: an imprecise alert on time beats a complete file that is late.

Does ISO 27001 certification amount to NIS2 compliance?

No, but it covers a large part of the ground. A certified security management system provides most of the ten areas and the documentation that goes with them. What remains are the obligations specific to NIS2, notably registration, incident notification within the statutory deadlines, and the formal involvement of the management body.

In short

Three things to do this week, if the subject has not yet been opened: take the Fit4Cybersecurity self-assessment, download the ILR’s four templates to see what will be asked for, and put the approval of the measures on the agenda of the next board meeting. The rest is built on those three.

This article is not legal advice. It sets out the general framework as it appears from the public sources cited, as at 20 August 2026. The ILR regulations setting the deadlines were still under consultation at that date. How the rules apply to a given company depends on its actual activity and structure: have your analysis validated by competent counsel.

Sources

  1. Security measures — Institut Luxembourgeois de Régulation
  2. Incident notification under NIS 2 — Institut Luxembourgeois de Régulation
  3. NIS 2: extension of the public consultations and templates for security-measure deliverables — Institut Luxembourgeois de Régulation
  4. Law of 5 May 2026 on measures for a high level of cybersecurity — Legilux, Official Journal of the Grand Duchy of Luxembourg
  5. Directive (EU) 2022/2555 — Official Journal of the European Union
  6. Fit4Cybersecurity — SECURITYMADEIN.LU
  7. MONARC risk assessment method and platform — SECURITYMADEIN.LU