“We see that the calculation of the entity’s size is very often wrong, because partner entities, meaning the group, have not been taken into account,” said Sheila Becker, head of ILR’s NISS service. From left: Maïa Nicté Mazariegos, communications officer at ILR; Luc Tapella, ILR director; and Becker, during the regulator’s NIS2 press briefing. Photo: Paperjam

“We see that the calculation of the entity’s size is very often wrong, because partner entities, meaning the group, have not been taken into account,” said Sheila Becker, head of ILR’s NISS service. From left: Maïa Nicté Mazariegos, communications officer at ILR; Luc Tapella, ILR director; and Becker, during the regulator’s NIS2 press briefing. Photo: Paperjam

Luxembourg’s new NIS2 cybersecurity regime could bring thousands of companies, public bodies and service providers into scope, with ILR warning that organisations may be covered automatically and that cyber-risk duties now reach the management body.

Between 1,500 and 2,000 entities could be covered by Luxembourg’s new NIS2 cybersecurity law, the country’s regulatory institute, ILR, said at a Monday 6 July press conference, days before a 10 July self-registration deadline for affected organisations.

“Responsibility lies with the companies, of course, if something happens,” said Luc TapellaLuc Tapella, ILR director. “But with NIS2, responsibility goes up to the management bodies.”

The law, dated 5 May 2026 and in force since 10 May, transposes the EU’s NIS2 directive into Luxembourg law. It broadens the country’s cybersecurity regime from a smaller group of previously identified operators to a wider set of businesses, public bodies and service providers whose activities are considered important for the economy or public life.

The law was meant to push organisations to look beyond cyberattacks and think more broadly about operational resilience, including disruption caused by software updates, new systems or human error, Tapella said.

“Being compliant does not just mean being compliant with the law,” Tapella said. “It also means being aware of the risks facing the entity, where those risks lie and what can be done to become better and more resilient.”

Wider reach

The law covers 16 sectors under ILR’s remit, excluding banking and financial-market infrastructure, where the CSSF is the competent authority. Covered sectors include energy, transport, health, water, digital infrastructure, public administration, space, postal services, food, manufacturing, digital providers and research.

The move from NIS1 to NIS2 changes not only the number of sectors covered but also the way entities fall within the regime, said Sheila BeckerSheila Becker, head of ILR’s NISS service. “Under NIS1, you had to be identified by ILR,” Becker said. “Now, depending on the criteria you meet, you automatically fall under the NIS2 obligations.”

Medium-sized and large organisations can therefore be covered by default if they operate in one of the relevant sectors. Under ILR’s presentation, medium-sized entities have at least 50 employees, annual turnover above €10m or a balance-sheet total above €10m. Large companies start at 250 employees, annual turnover above €50m or a balance-sheet total above €43m.

Companies must also look at linked or partner entities when assessing their size, a point Becker said was already a frequent source of mistakes in self-registration. “We see that the calculation of the entity’s size is very often wrong, because partner entities, meaning the group, have not been taken into account,” she said.

Not just IT

Public administrations can fall under the law regardless of size. Becker said a useful practical indicator was whether an entity was subject to public-procurement rules, while stressing that the detailed definitions sit in the law and ILR guidance.

Entities should not look only at their main business. A secondary activity in a covered sector may be enough to bring an organisation into scope, according to ILR.

NIS2 also introduces direct duties for management bodies, including approving security measures and receiving cybersecurity training. “It can no longer be considered only an IT issue,” Becker said. “It is also a governance issue.”

“The major change is the responsibility of the management body,” Becker went on. “They must approve the measures and they must also have training themselves.”

The law requires covered entities to prepare measures such as security policies, incident-management procedures and supply-chain controls. Outsourcing does not remove responsibility from the entity that remains accountable for its services or data, Becker said: “If I outsource, in the end I remain responsible for my services or for my data.”

First deadline

The first immediate obligation is self-registration. ILR has put an auto-registration form and an applicability simulator on its website for organisations that are unsure whether they fall within scope.

Some entities were already making errors when completing the form, Becker said, including failing to select all the sectors in which they are active or providing contact details that no longer work.

Covered entities must also notify significant incidents within 24 hours through a preliminary notification. ILR said the concept can include cyberattacks, human error, technical failures or physical events affecting systems and data.

That obligation reflects the fact that service disruption may come from more than a deliberate attack, Tapella said.

“We also see that problems arise during software updates or when new software equipment is implemented,” he said, adding that mishandling those changes can mean some services are no longer guaranteed.

Step by step

ILR said it wanted to work with entities step by step rather than treat NIS2 as a compliance switch that could be turned on overnight. It has published guidance, including six basic security measures covering asset and risk management, system protection, access controls, software updates, incident management, business continuity and training.

“We cannot, from 10 July or from 5 May, cover everything 100% from one day to the next,” Becker said. “It is much more about looking at how we improve over the next years.”

Two public consultations were expected shortly, one on incident notification and one on security measures. Becker said they should run until early August, with the first reporting exercise for essential entities expected in March 2027.

The regulator said sanctions for non-compliance can range from warnings to fines of up to €10m or 2% of worldwide turnover. Affected entities should complete their self-registration by 10 July and use ILR’s simulator if they are unsure whether the law applies to them.

Caption: From left: Maïa Nicté Mazariegos, communications officer at ILR; Luc Tapella, ILR director; and Sheila Becker, head of ILR’s NISS service, during the regulator’s NIS2 press briefing.