NIS2 Country Guide

NIS2 Luxembourg: Loi du 5 mai 2026, ILR Registration & Fines

Luxembourg transposed NIS2 through the Loi du 5 mai 2026, which took effect on 10 May 2026 and repealed the previous NIS1 act outright. The ILR supervises most sectors, self-registration runs through myilr.lu, and the deadline to register was 10 July 2026.

In force: 10 May 2026 Law: Loi du 5 mai 2026 (Mémorial A no. 225) Authority: ILR Registration deadline: passed Last updated: 2 Aug 2026

Introduction

Luxembourg did not extend its old cybersecurity law to meet NIS2. It replaced it. The Loi du 5 mai 2026 is a standalone act that repealed the previous NIS1 law and Articles 42 and 43 of the Law of 17 December 2021 on electronic communications networks and services.

It was adopted by the Chambre des Députés on 28 April 2026, published in Mémorial A no. 225 on 6 May 2026, and took effect on 10 May 2026 — roughly nineteen months after the EU transposition deadline.

A second act of the same date, the Loi du 5 mai 2026 sur la résilience des entités critiques, transposes the CER Directive. Entities designated as critical under that law fall within NIS2 scope regardless of their size.

Quick link: See What is NIS2? and NIS vs NIS2.

What you must do in Luxembourg

The obligations began on 10 May 2026 with no phase-in. The registration window was two months and has closed.

  1. Establish whether you are in scope. Luxembourg uses self-identification against Annexes I and II and the size-cap. The ILR publishes a free NIS 2 Simulator for an indicative answer, though it cannot be used to register.
  2. Self-register with the ILR. The deadline was 10 July 2026, two months after the Act took effect. See Self-registration with the ILR.
  3. Implement the Article 12 risk-management measures. These apply to all networks and information systems supporting your activities, not only those behind an essential service — a deliberate widening the ILR calls out explicitly.
  4. Be ready to notify within 24 hours through the SERIMA platform. See Incident reporting.
  5. Put your management body on the hook. The Act makes directors responsible; the ILR issued dedicated guidance, Guidelines NIS2 – Organes de direction, in March 2026.
  6. Keep your registration data current. Registrations filed before the Act took effect stay valid only while the data in them remains accurate.
Not registering does not make the duties go away. The ILR states plainly that failure to self-register does not exempt an entity from its obligations under the Act. The risk-management and reporting duties bind you from the moment you meet the criteria, registered or not.

NIS2 implementation in Luxembourg

Luxembourg transposed NIS2 through the Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité. Alongside the NIS2 rules it amends three existing laws: the e-commerce law of 14 August 2000, the HCPN law of 23 July 2016, and the electronic communications law of 17 December 2021.

Status

In force since 10 May 2026. Published in Mémorial A no. 225 on 6 May 2026. No transition period.

Official law

Légilux — Loi du 5 mai 2026, the full consolidated text.

Registration

Self-registration with the ILR through myilr.lu. Deadline was 10 July 2026.

SectorLuxembourg note
Finance Supervised by the CSSF. Entities excluded from DORA's scope are outside this law altogether under Article 1(5).
Digital infrastructure Data centre and cloud operators supervised by the ILR. Trust service providers, TLD registries and DNS providers are in scope regardless of size.
Domain name services Entities providing domain name registration services are in scope whatever their size (Article 1(4)).
Public administration State and municipal entities included; coordination via HCPN, incident response via GOVCERT.LU.

Compliance & scope

Luxembourg follows the NIS2 split between entités essentielles (essential entities) and entités importantes (important entities). Which one you are decides the size of the maximum fine and how closely the ILR supervises you.

Scope and the size-cap

Sixteen sectors are covered across Annexes I and II. An entity is medium-sized, and so in scope by default, if it has:

  • at least 50 and no more than 249 employees, or
  • annual turnover between €10m and €50m, or
  • an annual balance sheet total between €10m and €43m.

Exceed any of those and you count as large. Below all of them you are generally out of scope — unless one of the size-cap exceptions applies.

In scope regardless of size: public electronic communications networks and services, trust service providers, TLD registries, DNS providers, domain name registration services, and any entity designated critical under the companion resilience law.

Obligations (Article 12)

  • Risk analysis and information system security policies
  • Incident handling
  • Business continuity, backup management and crisis management
  • Supply-chain security, including direct supplier relationships
  • Security in acquisition, development and maintenance, including vulnerability handling
  • Policies to assess whether the measures are effective
  • Basic cyber hygiene practices and security training
  • Cryptography and encryption policies
  • Human resources security, access control and asset management
  • Multi-factor authentication and secured communications

These apply to all networks and information systems supporting your activities, not only those underpinning an essential service.

Standards & implementing rules

No certification is mandatory. ISO/IEC 27001:2023 and NIST CSF 2.0 are the usual reference frameworks.

For digital infrastructure and digital providers, Commission Implementing Regulation (EU) 2024/2690 sets the technical and methodological requirements directly, and the ILR flags it as applicable.

Competent authorities

Luxembourg splits the roles across four bodies. Supervision sits with the ILR for most of the economy and with the CSSF for the financial sector, while incident response is handled by two separate CSIRTs depending on who you are.

RoleAuthorityNotes
Competent authority ILR — Institut luxembourgeois de régulation Named in Article 4. Supervises most sectors, runs self-registration on myilr.lu and receives incident notifications through SERIMA.
Financial sector CSSF — Commission de Surveillance du Secteur Financier Competent authority for banking and financial market infrastructure. Professional secrecy rules do not block information exchange with the ILR and the CSIRTs for the purposes of this law.
Single point of contact HCPN — Haut-Commissariat à la Protection nationale National coordination and EU-level liaison.
CSIRT — state and critical operators GOVCERT.LU Incident response for government and critical operators.
CSIRT — private sector CIRCL Computer Incident Response Center Luxembourg, serving private-sector entities.

Self-registration with the ILR

Luxembourg puts the burden entirely on the entity. No authority writes to tell you that you are in scope: you assess yourself, and you register yourself.

Where

The self-registration form is on the ILR's portal, myilr.lu. This replaced the earlier MyGuichet.lu route.

When

10 July 2026 — two months after the Act took effect, as required by Article 11(4). That deadline has passed.

Already registered?

Registrations completed before the Act took effect remain valid, but only while the data stays accurate. Entities must keep it continuously up to date.

What the form asks for (Article 11(4))

  • The name of the entity.
  • Address and current contact details, including email addresses, IP address ranges and telephone numbers.
  • The relevant sector and sub-sector from Annex I or II.
  • A list of the EU member states in which you provide services falling within scope.
Failing to register does not put you outside the law. The ILR states this directly: not self-registering does not exempt an entity from its obligations. Risk management and incident reporting bind you from the moment you meet the criteria. Registering late is straightforwardly better than not registering.

The ILR maintains the resulting list of essential and important entities, passes it to the relevant CSIRT and to the single point of contact, and is required to review and update it at least every two years.

If you are unsure whether you qualify, the ILR publishes a free NIS 2 Simulator covering sectors, EU presence and organisation size. Its result is indicative only, and it cannot be used to register.

Incident reporting: SERIMA and the 24 / 72 / one-month chain

Notifications go to the ILR through SERIMA, a centralised portal that handles NIS1 and NIS2, electronic communications, GDPR and CER notifications in one place. It has been live since May 2025.

Within 24 hours of becoming aware of a significant incident — a preliminary notification, indicating where relevant whether the incident is suspected to result from unlawful or malicious acts, or could have cross-border impact.
Within 72 hours — an incident notification updating the preliminary one, with an initial assessment of severity and impact and any available indicators of compromise.
On request from a CSIRT or the competent authority — an intermediate report on relevant status updates.
Within one month of the incident being handled — a final report covering the incident in detail, its severity and impact, the underlying threat or root cause, mitigation applied and any cross-border effects.
The regulator answers on the clock too. Under Article 14(5) the ILR must respond to your preliminary notification without undue delay and, where possible, within 24 hours — providing initial feedback and, if you ask, operational guidance on mitigation, issued in cooperation with the relevant CSIRT. Few member states wrote a response time for the authority into their own transposition.

One derogation is worth knowing: trust service providers notify incidents affecting their trust services within 24 hours, without the 72-hour step applying in the same way.

Timeline & key dates

27 Dec 2022 — Directive (EU) 2022/2555 (NIS2) published in the EU Official Journal.
17 Oct 2024 — EU transposition deadline. Luxembourg missed it by about nineteen months.
May 2025 — The ILR launches SERIMA, a single incident-notification portal covering NIS1/NIS2, electronic communications, GDPR and CER.
4 Mar 2026 — ILR publishes Guidelines NIS2 – Organes de direction, its guidance on management body responsibilities.
28 Apr 2026 — The Chambre des Députés adopts the bill.
6 May 2026 — Published in Mémorial A no. 225.
10 May 2026The Act takes effect, repealing the NIS1 act and Articles 42 and 43 of the Law of 17 December 2021. All duties begin here.
10 Jul 2026 — Self-registration deadline, two months after entry into force.
By May 2028 — The ILR must have reviewed and updated its list of essential and important entities, a duty recurring at least every two years.

Sector-specific notes

  • Finance: the CSSF is the competent authority. Entities excluded from DORA's scope fall outside this law entirely under Article 1(5), so the first question for a Luxembourg financial entity is which regime applies, not how to comply with both.
  • Cloud and data centres: a disproportionately large sector for a country this size, and supervised directly by the ILR. Commission Implementing Regulation (EU) 2024/2690 sets their technical requirements.
  • Trust services, TLD registries and DNS: in scope regardless of size, so the size-cap gives no relief. Trust service providers also face the 24-hour notification derogation.
  • Domain name registration services: in scope whatever their size under Article 1(4).
  • Government and municipalities: coordination under the HCPN, incident response via GOVCERT.LU; private-sector entities deal with CIRCL instead.
  • Critical entities: anything designated under the companion loi du 5 mai 2026 sur la résilience des entités critiques is in NIS2 scope regardless of size.

How Luxembourg differs from the NIS2 baseline

Luxembourg's transposition sticks close to the Directive's own wording, which makes the places where it does make a choice worth knowing — particularly if you also operate in Germany.

  1. The size-cap is applied at group level. To work out whether you are medium-sized you must count the headcount and turnover of partner and linked enterprises, not just your own. This is the standard EU approach, but it is worth stating because Germany does the opposite (see below).
  2. Percentage fines apply from the first euro. The maxima are €10m or 2% for essential entities and €7m or 1.4% for important ones, whichever is higher, with no turnover threshold before the percentage becomes available.
  3. The fine ceilings attach to two articles only. They bite for breaches of Article 12 (risk-management measures) or Article 14(1) to (4) (incident notification). Other failures are dealt with through supervisory measures rather than these maxima.
  4. Fines come on top of supervisory measures, not instead of them. Article 24(2) requires an administrative fine to accompany one of the enforcement measures in Articles 22 or 23.
  5. Two CSIRTs, split by who you are. GOVCERT.LU covers the state and critical operators; CIRCL serves the private sector. Most member states run one.
  6. One portal for everything. SERIMA consolidates NIS1/NIS2, electronic communications, GDPR and CER notifications. If you already report breaches in Luxembourg, you are likely on it already.
  7. The regulator has its own deadline. The ILR must respond to a preliminary notification within 24 hours where possible.
If you operate in both Luxembourg and Germany, two rules point in opposite directions. On group aggregation, Luxembourg counts partner and linked enterprises towards the size-cap, while Germany's Section 28(4) BSIG disapplies that aggregation where the entity is genuinely independent in how its IT is built and run — so the same subsidiary can be in scope in Luxembourg and out of scope in Germany. On fines, Luxembourg applies the turnover percentage from the first euro, while Germany only applies its percentages to entities above €500 million in group turnover. Neither difference is visible if you read the Directive alone. See our NIS2 Germany guide.

French terms you will meet

The statute, the registration form and the ILR's forms are in French, even though the ILR publishes explanatory material in English.

FrenchEnglish
Loi du 5 mai 2026The NIS2 Act
entité essentielleEssential entity
entité importanteImportant entity
auto-enregistrementSelf-registration
notification préliminairePreliminary notification (the 24-hour one)
incident importantSignificant incident
organe de directionManagement body
amende administrativeAdministrative fine
Mémorial AThe official journal where laws are published
ILRInstitut luxembourgeois de régulation, the competent authority
CSSFThe financial sector regulator
HCPNHaut-Commissariat à la Protection nationale, the single point of contact

Penalties

Luxembourg applies the Directive's maxima without softening them, and without the turnover threshold some other member states added.

Entity typeMaximum administrative fine
Entités essentielles (essential) €10,000,000 or 2% of total worldwide annual turnover for the preceding financial year of the undertaking the entity belongs to — whichever is higher.
Entités importantes (important) €7,000,000 or 1.4% of total worldwide annual turnover, on the same basis — whichever is higher.
These ceilings attach to two obligations, not to everything. Article 24(4) and (5) apply them to breaches of Article 12 (risk-management measures) and Article 14(1) to (4) (incident notification). Other failures are addressed through the supervisory and enforcement measures in Articles 22 and 23. Note also that a fine is imposed in addition to one of those measures rather than as an alternative — so a fine normally arrives alongside a binding instruction, not on its own.
  • The ILR must weigh the aggravating and mitigating factors set out in Article 22(7) when deciding whether to fine at all and how much.
  • Fines follow the procedure in Article 25(2) to (5).
  • Management bodies of in-scope entities carry direct responsibility for the measures. The ILR's March 2026 Guidelines NIS2 – Organes de direction is the authority's own statement of what that means.

How to prepare

  1. Run the ILR's NIS 2 Simulator for an indicative read on whether you are in scope. It is free and covers sectors, EU presence and size.
  2. Work the size-cap at group level. Count partner and linked enterprises. A small Luxembourg entity inside a large group is usually in scope.
  3. Check the DORA question first if you are a financial entity. Article 1(5) may put you outside this law altogether.
  4. Self-register on myilr.lu, even though the deadline has passed. Not registering does not remove any obligation, and the ILR maintains the list either way.
  5. Get onto SERIMA before you need it. Decide who can file a notification and make sure they can reach the platform outside office hours.
  6. Extend risk management to all systems supporting your activities, not only those behind an essential service. This is the change the ILR highlights most.
  7. Brief the management body against the ILR's own guidance. Guidelines NIS2 – Organes de direction tells you what the regulator expects of directors.
  8. Document your supply-chain assessment. Article 12 covers direct supplier relationships explicitly.

If you operate in more than one EU country

Luxembourg hosts a large number of holding structures, funds and data centres serving other markets, so the cross-border question comes up more often here than its size suggests.

  • Registration asks where else you operate. Article 11(4) requires a list of the EU member states in which you provide in-scope services, so the ILR knows your footprint from the outset.
  • Each member state has its own act. A group registered with the ILR still has to register separately in Germany with the BSI, and the deadlines and thresholds do not match.
  • The same entity can be classified differently. Because Luxembourg aggregates group figures and Germany relieves that aggregation for IT-independent subsidiaries, a single subsidiary can be an important entity in one and out of scope in the other.
  • Fines do not scale the same way. The turnover percentage applies here from the first euro; in Germany it applies only above €500 million in group turnover.

For the position in the other member states we cover, see the NIS2 country guides.

Official links & resources

Loi du 5 mai 2026 — full text on Légilux — the operative law: Article 1 scope, Article 11 registration, Article 12 measures, Article 14 incident notification, Articles 22–23 supervision, Article 24 fines.
ILR — The NIS 2 Act — the regulator's own hub, published in English as well as French.
ILR — NIS 2 self-registration — the registration duty, the deadline and the NIS 2 Simulator.
myilr.lu — the portal where self-registration is filed.
SERIMA — the centralised incident-notification platform.

FAQ

When did NIS2 take effect in Luxembourg?
The Loi du 5 mai 2026 was published in Mémorial A no. 225 on 6 May 2026 and took effect on 10 May 2026. It repealed the previous NIS1 act rather than amending it.
Where do I register, and what was the deadline?
Self-registration is filed on the ILR portal at myilr.lu. The deadline was 10 July 2026, two months after the Act took effect. Older guidance pointing to MyGuichet.lu is out of date.
We missed the registration deadline. What now?
Register anyway. The ILR is explicit that failing to self-register does not exempt an entity from its obligations, so the duties already apply to you. The ILR can also compile its list of entities independently.
Does NIS2 apply to small companies?
Usually only to medium and large entities — at least 50 staff, or turnover of €10m to €50m, or a balance sheet total of €10m to €43m. But the size-cap is measured at group level, counting partner and linked enterprises, and it does not apply at all to trust service providers, TLD registries, DNS and domain name registration services, public electronic communications providers, or entities designated critical under the companion resilience law.
Who supervises NIS2 in Luxembourg?
The ILR is the competent authority for most sectors and the CSSF for banking and financial market infrastructure. Incident response is split between GOVCERT.LU for the state and critical operators and CIRCL for the private sector, with the HCPN as single point of contact.
How do we report an incident?
Through SERIMA, the ILR's centralised platform. A preliminary notification is due within 24 hours, a fuller notification within 72 hours, an intermediate report on request, and a final report within one month of the incident being handled. The ILR aims to respond to your preliminary notification within 24 hours.
We are covered by DORA. Does this law apply too?
Possibly not. Article 1(5) provides that entities excluded from DORA's scope fall outside this law. For a Luxembourg financial entity the first question is which regime governs, not how to satisfy both.
How large can the fines be?
Up to €10 million or 2% of worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities, whichever is higher in each case. Those ceilings apply to breaches of Article 12 or Article 14(1) to (4), and a fine is imposed alongside a supervisory measure rather than on its own.

Sources & verification

Every date, figure and article reference on this page was read from the enacted statute on Légilux or from the ILR's own pages, and checked on 2 August 2026. Third-party NIS2 trackers contradict each other and are not used as sources.

  • Loi du 5 mai 2026, Mémorial A no. 225 — the source for scope and the size-cap exceptions (Article 1), the competent authorities (Articles 3 and 4), the entity categories (Article 11), registration data and the two-month deadline (Article 11(4)), the risk-management measures (Article 12), the notification chain and the regulator's 24-hour response (Article 14), supervision (Articles 22 and 23) and the fine ceilings (Article 24).
  • ILR — The NIS 2 Act — the source for the 10 May 2026 effective date, the repeal of the NIS1 act and of Articles 42 and 43 of the Law of 17 December 2021, and the applicability of Implementing Regulation (EU) 2024/2690.
  • ILR — NIS 2 self-registration — the source for the 10 July 2026 deadline, the validity of earlier registrations, the statement that failing to register does not exempt an entity, the sixteen sectors, the size-cap figures and the group-level rule.
  • ILR, Guidelines NIS2 – Organes de direction, 4 March 2026 — management body responsibilities.
Four things we deliberately do not state. We give no number of entities in scope or registered: unlike Germany, neither the ILR nor the government has published one, and we would rather say so than borrow an estimate from an advisory firm. We say sixteen sectors, which is the ILR's own list, and not the fifteen that several secondary sources print. We make no enforcement claims — no fines under this law have been published, and it is less than three months old. And we do not present MyGuichet.lu as a registration route, despite widespread older guidance saying so, because the ILR's current instruction is myilr.lu and we could not verify any alternative.
General guidance, not legal advice. The Loi du 5 mai 2026 is only months old and ILR guidance is still being issued — check the primary sources listed above before acting on a deadline.