NIS2 Luxembourg: Compliance, Authorities & Key Requirements
Learn how Luxembourg implements the NIS2 Directive, which sectors and entities are covered, how registration works via MyGuichet.lu, and what steps organisations must take to prepare for compliance.
Introduction
Luxembourg has implemented NIS2 by strengthening and extending the existing 2021 national cybersecurity law. Entities operating essential or important services must comply with enhanced cybersecurity, risk management, and reporting requirements.
NIS2 implementation in Luxembourg
Luxembourg transposed NIS2 through the Law of 29 July 2024, amending the national cybersecurity framework introduced in 2021.
Status
Transposed; in force since 29 July 2024.
Official law
Registration
Registration is made through MyGuichet: MyGuichet.lu Deadline: 1 October 2025.
| Sector | Luxembourg note |
|---|---|
| Finance | Closely aligned with DORA; supervised by CSSF and ILR depending on the service type. |
| Digital Infrastructure | Data centre & cloud operators supervised directly by ILR. |
| Public Administration | State & municipal entities included; oversight via HCPN / GOVCERT. |
Compliance & certification
Luxembourg follows NIS2’s “Essential” and “Important” entity structure.
Scope
- Annex I & II sectors
- ≥50 employees or ≥€10m annual turnover
- Small entities may still qualify if critical for the state
Obligations
- Risk management & policies
- Incident detection & reporting
- Business continuity
- Supply-chain security
- Access control & encryption
Recommended standards
ISO/IEC 27001:2023, NIST CSF 2.0, ETSI EN 303 645 for certain infrastructures.
Timeline & key dates
Sector-specific notes
- Finance: Strong overlap with DORA; CSSF supervises key actors.
- Cloud & data centres: Major presence in Luxembourg; supervised by ILR.
- Government & municipalities: Covered under HCPN & GOVCERT.
Penalties
Luxembourg applies NIS2’s turnover-based maximum penalties. Fines are administrative and may include mandatory corrective action plans.
How to prepare
- Determine if your entity falls under Annex I or II.
- Register on MyGuichet.lu.
- Perform a cybersecurity gap analysis.
- Align with ISO 27001/NIST CSF controls.
- Evaluate third-party & supply-chain dependencies.
- Prepare incident-reporting procedures with GOVCERT.
- Ensure management accountability & training.
