# NIS2 in Luxembourg: the law of 5 May 2026, who is in scope and what the ILR and CSSF expect

> Luxembourg transposed NIS2 by the law of 5 May 2026, in force since 10 May 2026: scope, ILR and CSSF supervision, registration, incident reporting and DORA.

Published: 2026-09-30 · Dataplaz editorial team · https://dataplaz.lu/en/nis2-luxembourg-law-scope-obligations/

## Key takeaways
- Luxembourg transposed the NIS2 Directive by the law of 5 May 2026 on measures to ensure a high level of cybersecurity, which entered into force on 10 May 2026 and replaced the 2019 NIS1 law.
- The ILR is the competent authority for the large majority of sectors; the CSSF is competent for the banking sector and financial market infrastructures.
- In-scope entities had to self-register with the ILR by 10 July 2026 and must report significant incidents within 24 hours (early warning), 72 hours (notification) and one month (final report).
- Management bodies must approve and oversee cybersecurity risk-management measures and follow training; fines reach €10 million or 2% of worldwide turnover for essential entities.
- For financial entities, DORA, applicable since 17 January 2025, generally prevails over NIS2 for ICT risk management and incident reporting.

Luxembourg transposed the EU NIS2 Directive through the [law of 5 May 2026](https://legilux.public.lu/eli/etat/leg/loi/2026/05/05/a225/jo) on measures to ensure a high level of cybersecurity, which entered into force on 10 May 2026. The Institut Luxembourgeois de Régulation (ILR) supervises most sectors and the CSSF the banking sector and financial market infrastructures. In-scope entities had to self-register by 10 July 2026 and must report significant incidents within 24 hours.

## From bill 8364 to law

The text was tabled as bill 8364. The Chamber of Deputies adopted it on 28 April 2026, and the Council of State agreed on 5 May 2026, unanimously, to [waive the second constitutional vote](https://wdocs-pub.chd.lu/docs/Dossiers_parlementaires/8364/20260720_AccordDispenseSecondVote.pdf). The law was published in Mémorial A under number 225 and repeals the NIS1 framework of 2019.

| Item | Luxembourg rule |
|---|---|
| Legal basis | Law of 5 May 2026 (Mémorial A n° 225), transposing Directive (EU) 2022/2555 |
| Entry into force | 10 May 2026 |
| Self-registration | By 10 July 2026, with the ILR (two months after entry into force) |
| Competent authorities | ILR (most sectors); CSSF (banking, financial market infrastructures); HCPN (cyber-crisis management) |
| Incident reporting | Early warning 24 h, notification 72 h, final report one month; to the ILR via the SERIMA platform |
| Supervision | Essential entities: ex ante and ex post; important entities: ex post |
| Maximum fines | Essential: €10m or 2% of worldwide turnover; important: €7m or 1.4% |

## Who is in scope

The law follows the directive's size-cap logic. According to the [ILR's press release of 6 July 2026](https://www.ilr.lu/wp-content/uploads/publication/ILR_communique-de-presse_NIS2_06072026-1.pdf), it applies in particular to medium-sized entities, meaning at least 50 employees or annual turnover or balance sheet above €10 million, operating in the sectors listed in its annexes. Some entity types are covered regardless of size.

- **Essential entities** are, among others, large enterprises (at least 250 employees, or turnover above €50 million, or balance sheet above €43 million) in the highly critical sectors of Annex I.
- **Important entities** are, with exceptions, medium-sized enterprises in Annex I sectors and large or medium-sized enterprises in the other critical sectors of Annex II.

The perimeter is considerably wider than under NIS1. The ILR names manufacturing, online platforms, the space sector and food production as examples of sectors where organisations may be covered without yet being aware of it, and offers an [applicability simulator](http://nis2.ilr.lu/). Paperjam reported an estimate of 1,500 to 2,000 entities in scope.

## Supervisors and reporting channel

The ILR describes itself as the competent cybersecurity authority for "the large majority" of NIS2 sectors. The CSSF remains competent for the banking sector and financial market infrastructures, and the Haut-Commissariat à la Protection nationale (HCPN) is responsible for cyber-crisis management, according to the law-firm briefings by Elvinger Hoss Prussen and Simmons & Simmons.

Incidents are reported to the ILR through [SERIMA](https://www.ilr.lu/secteurs-activites/niss/nis-2/). The ILR stresses that the notion of incident is deliberately broad: cyberattacks, human error, technical failures and physical events that can affect systems and data all count. Reporting runs in three stages: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month.

## Management liability

NIS2 moves cybersecurity to board level. Management bodies must approve and oversee the implementation of cybersecurity risk-management measures, follow training and ensure their staff are trained. The ILR states that the law gives management bodies direct obligations and responsibilities, and law-firm briefings note that members can be held liable for non-compliance. Sanctions range from warnings to fines of up to €10 million or 2% of annual worldwide turnover for essential entities, and €7 million or 1.4% for important entities, whichever amount is higher.

## How NIS2 relates to DORA

Financial entities supervised by the CSSF have been subject to the Digital Operational Resilience Act since [17 January 2025](https://www.cssf.lu/en/2025/01/entry-in-application-of-dora-regulation-on-17-january-2025/), reporting major ICT-related incidents to the CSSF via eDesk. DORA acts as lex specialis: for financial entities it generally prevails over NIS2 for ICT risk management and incident reporting, while NIS2 continues to apply to areas DORA does not cover. Groups that combine financial and non-financial legal entities should therefore check each entity separately against the NIS2 annexes.

## What it means now

The registration window closed on 10 July 2026. An entity that discovers only now that it is in scope should register with the ILR without further delay, since registration is a legal obligation under the law. Incident reporting obligations have applied since 10 May 2026. The next practical step for most organisations is documenting board approval of the risk-management measures and the training of management; the ILR's list of [six fundamental security measures](https://www.ilr.lu/publications/6-mesures-de-securite-fondamentales/) is a starting point.

## Questions & answers
**When did NIS2 become law in Luxembourg?**
The Chamber of Deputies adopted bill 8364 on 28 April 2026, the Council of State waived the second vote on 5 May 2026, and the law of 5 May 2026 entered into force on 10 May 2026.

**Which authority supervises NIS2 in Luxembourg?**
The Institut Luxembourgeois de Régulation (ILR) for most sectors. The CSSF is competent for the banking sector and financial market infrastructures. The HCPN handles national cyber-crisis management.

**What was the NIS2 registration deadline in Luxembourg?**
Entities in scope had to self-register with the ILR by 10 July 2026, two months after the law entered into force. Registration is a legal obligation, so entities that missed the date should register without further delay.

**Does NIS2 apply to banks that already comply with DORA?**
For financial entities, DORA acts as lex specialis and generally prevails for ICT risk management and incident reporting. NIS2 still applies to areas DORA does not cover.

**What are the NIS2 fines in Luxembourg?**
Up to €10 million or 2% of annual worldwide turnover, whichever is higher, for essential entities, and up to €7 million or 1.4% for important entities.

## Sources
1. [Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité (Mémorial A n° 225)](https://legilux.public.lu/eli/etat/leg/loi/2026/05/05/a225/jo) · Legilux
2. [Bill 8364 – Dispense du second vote constitutionnel par le Conseil d'État (5 May 2026)](https://wdocs-pub.chd.lu/docs/Dossiers_parlementaires/8364/20260720_AccordDispenseSecondVote.pdf) · Chambre des Députés
3. [Communiqué de presse : l'ILR présente la nouvelle loi NIS 2 (6 July 2026)](https://www.ilr.lu/wp-content/uploads/publication/ILR_communique-de-presse_NIS2_06072026-1.pdf) · ILR
4. [NIS 2](https://www.ilr.lu/secteurs-activites/niss/nis-2/) · ILR
5. [Cybersécurité : présentation de la loi NIS 2](https://gouvernement.lu/fr/actualites/toutes_actualites/communiques/2026/07-juillet/06-cybersecurite-nis-2.html) · gouvernement.lu
6. [Entry into application of DORA regulation on 17 January 2025](https://www.cssf.lu/en/2025/01/entry-in-application-of-dora-regulation-on-17-january-2025/) · CSSF
7. [NIS2 now in force in Luxembourg](https://elvingerhoss.lu/insights/publications/nis2-now-force-luxembourg) · Elvinger Hoss Prussen
8. [Luxembourg transposes NIS2, strengthening cybersecurity rules](https://www.simmons-simmons.com/en/publications/cmqhtf6pm00dov6occ2svi2uz/luxembourg-transposes-nis2-strengthening-cybersecurity-rules-) · Simmons & Simmons
9. [Up to 2,000 entities face NIS2 cyber deadline](https://en.paperjam.lu/article/up-to-2-000-entities-face-nis2-cyber-deadline) · Paperjam
