NIS2 in Luxembourg: which companies are affected?

The law transposing NIS2 came into force on 10 May 2026, and the obligation to register with the ILR expired on 10 July. Many companies within scope still do not know it.

By

7 min read

Server racks and network cabling inside a data centre
Photo: Tyler on Unsplash

If you run a company of more than fifty people in Luxembourg, there is a date you may have let slip without noticing: 10 July 2026. That was the deadline to register with the Institut Luxembourgeois de Régulation, Luxembourg’s regulatory authority, under the NIS 2 law.

That deadline passed several weeks ago. And contrary to what many assume, failing to register does not release you from anything: the ILR states explicitly that the absence of self-registration does not exempt an entity from its obligations.

Here is how to tell whether you are in scope, and what to do if you are.

Key takeaways

  • The law of 5 May 2026 transposing NIS2 came into force on 10 May 2026.
  • Self-registration with the ILR had to be completed by 10 July 2026 at the latest.
  • Two conditions determine whether you are in scope: operating in a sector listed in the annexes, and exceeding the size threshold.
  • Companies with fewer than 50 employees are in principle outside scope, with exceptions for certain digital providers.
  • Failing to register removes no obligation.

What the law of 5 May 2026 changed

Luxembourg transposed the European NIS2 directive through the law of 5 May 2026 on measures to ensure a high level of cybersecurity, published in Mémorial A no. 225 and in force since 10 May 2026 (Deloitte Luxembourg).

The Institut Luxembourgeois de Régulation is the competent authority for supervision and enforcement. It presented the framework at a press conference on 6 July 2026 (Luxembourg Government).

The main change from the previous regime is scope. NIS2 no longer targets a handful of vital operators: it covers entire sectors, and brings in a large number of mid-sized companies that had never dealt with cybersecurity regulation before.

Is your company in scope? The two-question test

Scope turns on two cumulative conditions. You need to answer yes to both.

Question 1: is your sector listed in the annexes?

The law adopts the directive’s two annexes. Annex I covers what are termed highly critical sectors, Annex II other critical sectors.

Annex I, highly critical sectorsAnnex II, other critical sectors
EnergyPostal and courier services
TransportWaste management
BankingChemicals
Financial market infrastructuresFood
HealthManufacturing (medical devices, electronics, machinery, vehicles)
Drinking water and waste waterDigital providers (marketplaces, search engines, social networks)
Digital infrastructureResearch
ICT service management, business to business
Public administration
Space

Two entries deserve attention from any director who assumes they are outside scope.

ICT service management between businesses sits in Annex I. A company that manages other companies’ systems is therefore in scope, even if its activity looks nothing like critical infrastructure in the everyday sense.

Manufacturing in Annex II covers thoroughly ordinary industries: electronic equipment, machinery, vehicles. Many Luxembourg industrial companies fall into that category without ever having thought of themselves as regulatory targets.

Question 2: do you exceed the size threshold?

The law applies the size-cap rule. Only medium and large companies in covered sectors fall under automatic application (ILR).

The financial criteria matter as much as headcount:

CategoryHeadcountTurnoverBalance sheet
Smallunder 50
Medium50 to 249€10m to €50m€10m to €43m
Large250 and aboveabove €50mabove €43m

Mind the logic of these thresholds. They work as alternatives, not as a cumulative test: crossing any one of them moves you up a category. A company of sixty people turning over twelve million euros is a medium company, and therefore in scope if its sector is covered.

And mind the exceptions. Certain digital service providers fall under the law regardless of size. A very small DNS or domain name registration provider can be in scope without meeting any threshold.

Essential or important entity: what the distinction changes

Companies in scope split into two categories. The distinction is not about security obligations, which are largely common, but about supervisory intensity and the ceiling on penalties.

Essential entitiesImportant entities
Typical profileLarge companies in Annex I sectorsMedium companies, and Annex II companies
SupervisionProactive, the authority may act without a prior incidentReactive, triggered by a report or an incident
Maximum penalty€10 million or 2% of worldwide annual turnover, whichever is higherLower ceiling, set by the law

For an important entity, this means in practice that the authority is unlikely to come knocking unprompted. But an incident, a complaint or a report is enough to trigger scrutiny, and the company will then have to show it was meeting its obligations all along.

The deadline has passed. What now?

Self-registration had to be completed within two months of entry into force, so by 10 July 2026 at the latest. It is now August.

If you are in scope and unregistered, here is the sequence.

Check your situation first. The ILR provides a simulation tool to determine whether the law applies to your company. That tool is for diagnosis, not for registration itself.

Then register, through the online form on the guichet.ilr.lu portal, available in French and English. Late is better than never: the step is public and dated, and a late filing is easier to defend than continued silence.

Do not mistake registration for compliance. It is a declaratory formality. The substantive obligations have been running since entry into force, whether you registered or not. A separate article sets out where to start when nothing is in place yet.

What the law actually requires

Beyond registration, three families of obligations apply to entities in scope.

Management accountability. This is the most significant cultural shift. Management bodies must approve risk management measures and oversee their implementation. Cybersecurity stops being something delegated to IT: it engages the leadership itself.

Proportionate technical and organisational measures. The law cites risk analysis, multi-factor authentication, encryption and supply chain security. That last point deserves attention: you are accountable for the risk introduced by your suppliers, including those not themselves subject to NIS2.

These three families break down into ten areas to cover and document: see the detail of the measures and the order in which to take them.

Incident notification, on a tight schedule:

DeadlineWhat is expected
24 hoursEarly warning to the authority
72 hoursDetailed incident notification
1 monthFinal report

Twenty-four hours is short. In practice it means knowing in advance who reports, with what information, and through which channel. An organisation discovering the procedure on the day of the incident will not meet the deadline.

Penalties, and who carries them

For essential entities, administrative fines can reach €10 million or 2% of worldwide annual turnover, whichever is higher.

But the amount is not the only lever. NIS2 provides that management liability can be engaged, and that in the most serious cases the authority may temporarily suspend individuals from management functions. It is that personal dimension, more than the financial ceiling, that changed how the subject is handled in European boardrooms.

This article is not legal advice. It sets out the general framework as it appears in the public sources cited. Whether it applies to a given company depends on its actual activity and structure: have your analysis confirmed by qualified counsel.

Frequently asked questions

Is my 30-person company in scope?

In principle no: small companies, under 50 employees, fall outside automatic application. Two caveats. Certain digital providers are covered whatever their size. And the financial criteria can pull in a small company with high turnover.

I am a subcontractor to a company in scope. Does NIS2 apply to me?

Not automatically. But your client is required to secure its supply chain. You will therefore see contractual security requirements, questionnaires and audit clauses arriving. The obligation does not target you directly; its effects reach you regardless.

What happens if I did not register?

Failing to register does not exempt you from any obligation under the law. Rectifying it remains possible, and preferable to inaction.

Is GDPR compliance enough?

No. GDPR protects personal data, NIS2 targets service continuity and security. The two overlap in part, notably on risk analysis, but a compliant GDPR programme covers neither the 24-hour notification, nor supply chain security, nor management accountability.

In short

NIS2 has been in force in Luxembourg since 10 May 2026, and the July registration deadline has passed. Two questions settle whether you are in scope: is your sector in the annexes, and do you exceed fifty employees or the financial thresholds.

If the answer is yes to both, the priority is not to become fully compliant at once. It is to register, then to establish your incident notification procedure, because that is the only obligation whose deadline is measured in hours.

Sources

  1. Cybersecurity: the ILR presents the new NIS 2 law — Luxembourg Government
  2. NIS 2 self-registration — Institut Luxembourgeois de Régulation
  3. NIS2 transposed into Luxembourgish law: what organizations need to know — Deloitte Luxembourg