NIS2 in Luxembourg
What binds you in Luxembourg is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.
Reviewed . Verify against the national official journal before relying on this for a filing.
National transposition
Status of the national text · Published and in force
Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité
The law replaces the NIS1 law of 28 May 2019 outright rather than amending it, and entered into force five days after signature. Supervision sits with the ILR, which also receives incident notifications through its SERIMA platform on the article 23 timeline of 24 hours, 72 hours and one month. Luxembourg left itself the shortest runway in the Union: two months between entry into force and the registration deadline.
ILR self-registration form
Self-registration with the ILR was due by 10 July 2026 — a statutory window of two months from entry into force, now closed. An entity that came into scope after that date registers on coming into scope, not on the original deadline, but one that was in scope on 10 May 2026 and did not register is already late.
Who supervises you
ILR / HCPN is the competent authority designated by Luxembourg. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.
Incident notifications under article 23 normally go to CIRCL / GOVCERT.LU, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.
What differs from the directive
Because NIS2 is a directive, Luxembourg legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:
- Registration. The portal, the information required and the deadline are national.
- Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
- Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
- Reporting format. Deadlines are fixed by the directive; the form and the language are national.
If you operate in several member states
You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.