NIS2 Luxembourg: Loi du 5 mai 2026, ILR Registration & Fines
Luxembourg transposed NIS2 through the Loi du 5 mai 2026, which took effect on 10 May 2026 and repealed the previous NIS1 act outright. The ILR supervises most sectors, self-registration runs through myilr.lu, and the deadline to register was 10 July 2026.
Introduction
Luxembourg did not extend its old cybersecurity law to meet NIS2. It replaced it. The Loi du 5 mai 2026 is a standalone act that repealed the previous NIS1 law and Articles 42 and 43 of the Law of 17 December 2021 on electronic communications networks and services.
It was adopted by the Chambre des Députés on 28 April 2026, published in Mémorial A no. 225 on 6 May 2026, and took effect on 10 May 2026 — roughly nineteen months after the EU transposition deadline.
A second act of the same date, the Loi du 5 mai 2026 sur la résilience des entités critiques, transposes the CER Directive. Entities designated as critical under that law fall within NIS2 scope regardless of their size.
What you must do in Luxembourg
The obligations began on 10 May 2026 with no phase-in. The registration window was two months and has closed.
- Establish whether you are in scope. Luxembourg uses self-identification against Annexes I and II and the size-cap. The ILR publishes a free NIS 2 Simulator for an indicative answer, though it cannot be used to register.
- Self-register with the ILR. The deadline was 10 July 2026, two months after the Act took effect. See Self-registration with the ILR.
- Implement the Article 12 risk-management measures. These apply to all networks and information systems supporting your activities, not only those behind an essential service — a deliberate widening the ILR calls out explicitly.
- Be ready to notify within 24 hours through the SERIMA platform. See Incident reporting.
- Put your management body on the hook. The Act makes directors responsible; the ILR issued dedicated guidance, Guidelines NIS2 – Organes de direction, in March 2026.
- Keep your registration data current. Registrations filed before the Act took effect stay valid only while the data in them remains accurate.
NIS2 implementation in Luxembourg
Luxembourg transposed NIS2 through the Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité. Alongside the NIS2 rules it amends three existing laws: the e-commerce law of 14 August 2000, the HCPN law of 23 July 2016, and the electronic communications law of 17 December 2021.
Status
In force since 10 May 2026. Published in Mémorial A no. 225 on 6 May 2026. No transition period.
Official law
Légilux — Loi du 5 mai 2026, the full consolidated text.
Registration
Self-registration with the ILR through myilr.lu. Deadline was 10 July 2026.
| Sector | Luxembourg note |
|---|---|
| Finance | Supervised by the CSSF. Entities excluded from DORA's scope are outside this law altogether under Article 1(5). |
| Digital infrastructure | Data centre and cloud operators supervised by the ILR. Trust service providers, TLD registries and DNS providers are in scope regardless of size. |
| Domain name services | Entities providing domain name registration services are in scope whatever their size (Article 1(4)). |
| Public administration | State and municipal entities included; coordination via HCPN, incident response via GOVCERT.LU. |
Compliance & scope
Luxembourg follows the NIS2 split between entités essentielles (essential entities) and entités importantes (important entities). Which one you are decides the size of the maximum fine and how closely the ILR supervises you.
Scope and the size-cap
Sixteen sectors are covered across Annexes I and II. An entity is medium-sized, and so in scope by default, if it has:
- at least 50 and no more than 249 employees, or
- annual turnover between €10m and €50m, or
- an annual balance sheet total between €10m and €43m.
Exceed any of those and you count as large. Below all of them you are generally out of scope — unless one of the size-cap exceptions applies.
In scope regardless of size: public electronic communications networks and services, trust service providers, TLD registries, DNS providers, domain name registration services, and any entity designated critical under the companion resilience law.
Obligations (Article 12)
- Risk analysis and information system security policies
- Incident handling
- Business continuity, backup management and crisis management
- Supply-chain security, including direct supplier relationships
- Security in acquisition, development and maintenance, including vulnerability handling
- Policies to assess whether the measures are effective
- Basic cyber hygiene practices and security training
- Cryptography and encryption policies
- Human resources security, access control and asset management
- Multi-factor authentication and secured communications
These apply to all networks and information systems supporting your activities, not only those underpinning an essential service.
Standards & implementing rules
No certification is mandatory. ISO/IEC 27001:2023 and NIST CSF 2.0 are the usual reference frameworks.
For digital infrastructure and digital providers, Commission Implementing Regulation (EU) 2024/2690 sets the technical and methodological requirements directly, and the ILR flags it as applicable.
Self-registration with the ILR
Luxembourg puts the burden entirely on the entity. No authority writes to tell you that you are in scope: you assess yourself, and you register yourself.
Where
The self-registration form is on the ILR's portal, myilr.lu. This replaced the earlier MyGuichet.lu route.
When
10 July 2026 — two months after the Act took effect, as required by Article 11(4). That deadline has passed.
Already registered?
Registrations completed before the Act took effect remain valid, but only while the data stays accurate. Entities must keep it continuously up to date.
What the form asks for (Article 11(4))
- The name of the entity.
- Address and current contact details, including email addresses, IP address ranges and telephone numbers.
- The relevant sector and sub-sector from Annex I or II.
- A list of the EU member states in which you provide services falling within scope.
The ILR maintains the resulting list of essential and important entities, passes it to the relevant CSIRT and to the single point of contact, and is required to review and update it at least every two years.
If you are unsure whether you qualify, the ILR publishes a free NIS 2 Simulator covering sectors, EU presence and organisation size. Its result is indicative only, and it cannot be used to register.
Incident reporting: SERIMA and the 24 / 72 / one-month chain
Notifications go to the ILR through SERIMA, a centralised portal that handles NIS1 and NIS2, electronic communications, GDPR and CER notifications in one place. It has been live since May 2025.
One derogation is worth knowing: trust service providers notify incidents affecting their trust services within 24 hours, without the 72-hour step applying in the same way.
Timeline & key dates
Sector-specific notes
- Finance: the CSSF is the competent authority. Entities excluded from DORA's scope fall outside this law entirely under Article 1(5), so the first question for a Luxembourg financial entity is which regime applies, not how to comply with both.
- Cloud and data centres: a disproportionately large sector for a country this size, and supervised directly by the ILR. Commission Implementing Regulation (EU) 2024/2690 sets their technical requirements.
- Trust services, TLD registries and DNS: in scope regardless of size, so the size-cap gives no relief. Trust service providers also face the 24-hour notification derogation.
- Domain name registration services: in scope whatever their size under Article 1(4).
- Government and municipalities: coordination under the HCPN, incident response via GOVCERT.LU; private-sector entities deal with CIRCL instead.
- Critical entities: anything designated under the companion loi du 5 mai 2026 sur la résilience des entités critiques is in NIS2 scope regardless of size.
How Luxembourg differs from the NIS2 baseline
Luxembourg's transposition sticks close to the Directive's own wording, which makes the places where it does make a choice worth knowing — particularly if you also operate in Germany.
- The size-cap is applied at group level. To work out whether you are medium-sized you must count the headcount and turnover of partner and linked enterprises, not just your own. This is the standard EU approach, but it is worth stating because Germany does the opposite (see below).
- Percentage fines apply from the first euro. The maxima are €10m or 2% for essential entities and €7m or 1.4% for important ones, whichever is higher, with no turnover threshold before the percentage becomes available.
- The fine ceilings attach to two articles only. They bite for breaches of Article 12 (risk-management measures) or Article 14(1) to (4) (incident notification). Other failures are dealt with through supervisory measures rather than these maxima.
- Fines come on top of supervisory measures, not instead of them. Article 24(2) requires an administrative fine to accompany one of the enforcement measures in Articles 22 or 23.
- Two CSIRTs, split by who you are. GOVCERT.LU covers the state and critical operators; CIRCL serves the private sector. Most member states run one.
- One portal for everything. SERIMA consolidates NIS1/NIS2, electronic communications, GDPR and CER notifications. If you already report breaches in Luxembourg, you are likely on it already.
- The regulator has its own deadline. The ILR must respond to a preliminary notification within 24 hours where possible.
French terms you will meet
The statute, the registration form and the ILR's forms are in French, even though the ILR publishes explanatory material in English.
| French | English |
|---|---|
| Loi du 5 mai 2026 | The NIS2 Act |
| entité essentielle | Essential entity |
| entité importante | Important entity |
| auto-enregistrement | Self-registration |
| notification préliminaire | Preliminary notification (the 24-hour one) |
| incident important | Significant incident |
| organe de direction | Management body |
| amende administrative | Administrative fine |
| Mémorial A | The official journal where laws are published |
| ILR | Institut luxembourgeois de régulation, the competent authority |
| CSSF | The financial sector regulator |
| HCPN | Haut-Commissariat à la Protection nationale, the single point of contact |
Penalties
Luxembourg applies the Directive's maxima without softening them, and without the turnover threshold some other member states added.
| Entity type | Maximum administrative fine |
|---|---|
| Entités essentielles (essential) | €10,000,000 or 2% of total worldwide annual turnover for the preceding financial year of the undertaking the entity belongs to — whichever is higher. |
| Entités importantes (important) | €7,000,000 or 1.4% of total worldwide annual turnover, on the same basis — whichever is higher. |
- The ILR must weigh the aggravating and mitigating factors set out in Article 22(7) when deciding whether to fine at all and how much.
- Fines follow the procedure in Article 25(2) to (5).
- Management bodies of in-scope entities carry direct responsibility for the measures. The ILR's March 2026 Guidelines NIS2 – Organes de direction is the authority's own statement of what that means.
How to prepare
- Run the ILR's NIS 2 Simulator for an indicative read on whether you are in scope. It is free and covers sectors, EU presence and size.
- Work the size-cap at group level. Count partner and linked enterprises. A small Luxembourg entity inside a large group is usually in scope.
- Check the DORA question first if you are a financial entity. Article 1(5) may put you outside this law altogether.
- Self-register on myilr.lu, even though the deadline has passed. Not registering does not remove any obligation, and the ILR maintains the list either way.
- Get onto SERIMA before you need it. Decide who can file a notification and make sure they can reach the platform outside office hours.
- Extend risk management to all systems supporting your activities, not only those behind an essential service. This is the change the ILR highlights most.
- Brief the management body against the ILR's own guidance. Guidelines NIS2 – Organes de direction tells you what the regulator expects of directors.
- Document your supply-chain assessment. Article 12 covers direct supplier relationships explicitly.
If you operate in more than one EU country
Luxembourg hosts a large number of holding structures, funds and data centres serving other markets, so the cross-border question comes up more often here than its size suggests.
- Registration asks where else you operate. Article 11(4) requires a list of the EU member states in which you provide in-scope services, so the ILR knows your footprint from the outset.
- Each member state has its own act. A group registered with the ILR still has to register separately in Germany with the BSI, and the deadlines and thresholds do not match.
- The same entity can be classified differently. Because Luxembourg aggregates group figures and Germany relieves that aggregation for IT-independent subsidiaries, a single subsidiary can be an important entity in one and out of scope in the other.
- Fines do not scale the same way. The turnover percentage applies here from the first euro; in Germany it applies only above €500 million in group turnover.
For the position in the other member states we cover, see the NIS2 country guides.
Official links & resources
FAQ
When did NIS2 take effect in Luxembourg?
Where do I register, and what was the deadline?
We missed the registration deadline. What now?
Does NIS2 apply to small companies?
Who supervises NIS2 in Luxembourg?
How do we report an incident?
We are covered by DORA. Does this law apply too?
How large can the fines be?
Sources & verification
Every date, figure and article reference on this page was read from the enacted statute on Légilux or from the ILR's own pages, and checked on 2 August 2026. Third-party NIS2 trackers contradict each other and are not used as sources.
- Loi du 5 mai 2026, Mémorial A no. 225 — the source for scope and the size-cap exceptions (Article 1), the competent authorities (Articles 3 and 4), the entity categories (Article 11), registration data and the two-month deadline (Article 11(4)), the risk-management measures (Article 12), the notification chain and the regulator's 24-hour response (Article 14), supervision (Articles 22 and 23) and the fine ceilings (Article 24).
- ILR — The NIS 2 Act — the source for the 10 May 2026 effective date, the repeal of the NIS1 act and of Articles 42 and 43 of the Law of 17 December 2021, and the applicability of Implementing Regulation (EU) 2024/2690.
- ILR — NIS 2 self-registration — the source for the 10 July 2026 deadline, the validity of earlier registrations, the statement that failing to register does not exempt an entity, the sixteen sectors, the size-cap figures and the group-level rule.
- ILR, Guidelines NIS2 – Organes de direction, 4 March 2026 — management body responsibilities.
