Regulation

NIS2 Luxembourg: the complete guide

Who is in scope, what the law of 5 May 2026 requires, what a company risks by doing nothing, and where to start. Written for directors, not for lawyers.

Last updated: 4 September 2026. The official sources are listed at the foot of the page.

Microsoft Partner

In brief

NIS2 in two minutes

NIS2 is the European directive that raises the cybersecurity bar for companies in the sectors considered essential or important. In Luxembourg it entered the law through the law of 5 May 2026, in force since 15 May 2026, and the competent authority is the Luxembourg Institute of Regulation (ILR).

This guide answers the questions in the order they arise: am I in scope, what is expected of me, what do I risk, where do I start. One thing is repeated here because it is true: compliance belongs to the entity subject to the law, not to its IT provider.

Who is in scope?

The law does not talk about SMEs or large groups: it talks about sectors and sizes, and it draws two categories. Essential entities are the large companies in highly critical sectors. Important entities are medium-sized companies, from 50 employees upwards, in the sectors covered.

The sectors concerned include energy, transport, health, water, digital infrastructure, ICT services, public administration and the manufacture of critical products.

The figures that separate the two categories are set out in our article on the registration deadline, which remains the piece to read if you are after a number rather than a method.

Your sector iscovered by the law50 employeesor moreNIS2entityORYou subcontract to a regulated entity,whatever your size
The third route bypasses the size threshold. It is the one by which NIS2 reaches the most Luxembourg companies.

An SME with fewer than 50 employees: in scope or not?

This is the question that comes up most often, and the honest answer fits on one line: not automatically, but not never. The important entity threshold starts, in principle, at 50 employees. Below it, a smaller organisation can still be in scope if it supplies a critical service, or if it works as a subcontractor to a regulated entity.

And even out of scope, an SME subcontractor inherits its client’s requirements: that client has to secure its supply chain, so it will pass them on by contract. That is the route, rather than the thresholds, by which NIS2 reaches the most Luxembourg companies.

The obligations, in concrete terms

Beyond registration, the entities concerned have to put proportionate measures in place.

  • security risk analysis and management
  • technical measures: backups, encryption, access control, detection
  • notification of incidents with a significant impact, within the deadlines set
  • supply chain security, suppliers and subcontractors included
  • accountability of management, which approves and supervises the measures

“Proportionate” is the word that matters: what is expected of a hospital is not what is expected of a twenty-person workshop. That is good news and a trap. Nobody will hand you the exact list of what you must do: it has to be built, and it has to be defensible.

The penalties

  • up to 10 million euros or 2% of annual worldwide turnover for essential entities
  • up to 7 million euros or 1.4% of annual worldwide turnover for important entities

On top of that come the reputational risk and, if an incident gets out of hand, business interruption. In practice it is often that last point that costs the most, and the fastest.

The ILR, your point of contact

The Luxembourg Institute of Regulation is the competent authority. Self-registration is done with the ILR, and the ILR supervises. Registration is not automatic: taking the step is up to the company. The 10 July 2026 deadline has passed, and being late suspends none of the substantive obligations, which have been running since 15 May 2026.

One thing to settle before any incident: knowing who, on your side, is authorised to notify, and through which channel. A notification is prepared cold, not on the day the servers start being encrypted.

Your subcontractors are in scope

Supply chain security is an obligation in its own right, not a recommendation. It says two things. You have to know which providers touch your systems and your data, and what they commit to. And your regulated clients will ask you exactly the same question.

In practice: an up-to-date list of providers, what each of them can reach, the security clauses in their contracts, and what happens if one of them suffers an incident. Most companies discover that list by drawing it up.

The NIS2 audit: knowing where you stand

A NIS2 audit is not a legal opinion and issues no certificate. It is a picture of the current state: what is in place, what is missing against the measures the law expects, and in which order to deal with it.

Ours starts from what exists: equipment and network, the security rules actually applied, backups, access rights, logging, providers. And it stops where the decision begins. Compliance is assessed at the entity subject to the law, by its supervisory authority, never at its IT provider. A supplier selling you “NIS2 compliance” is selling something it does not hold.

Who holds itWhat that means
The technical measuresUs, if you hand them to usBackups, encryption, access, detection, logging
The record and the toolingUsAudit, prioritised gaps, written procedures, reports
The compliance decisionYouYour company is the entity subject to the law, not its provider
GovernanceYour managementApproving and supervising the measures, article 20 of the directive
The assessmentThe ILRIt is the authority that supervises and that penalises

The gap analysis, or the distance measured

This is what follows the audit: the distance between what you do and what the law expects, line by line, with an order of treatment. The value is not the list, it is the prioritisation. An SME does not close thirty gaps at once; it closes three, the ones that cut the most risk for the least effort, and it knows why it left the others for later.

That record has a second, less obvious use. It documents a decision. In front of a regulator, “we had identified this gap, prioritised it this way, for this reason” is not the same position as “we did not know”.

The SOC, and what we do not advertise

Detecting means collecting, correlating and looking. Empirys’ cyber detection runs on Microsoft Sentinel, which makes automated detection continuous. The human response, by contrast, is provided five days a week.

We do not advertise round-the-clock supervision, and that is deliberate: the only coverage that counts is the one a contract sets, and it is read in the contract, not on a website. At Premium level, CyberOne adds an active hybrid SOC, which combines specialists and automation.

Responding to an incident

The law does not expect you to be beyond reproach. It expects you to know how to react, and to say so within the deadlines. Directive (EU) 2022/2555 organises notification in three stages: an early warning within 24 hours, an incident notification within 72 hours, a final report within one month.

What is prepared beforehand, and never during:

  • who decides that this is an incident, and who notifies
  • the authority’s contact details and the notification channel, written down somewhere other than the affected network
  • what gets isolated first, and what gets restored next
  • where the backups are, and the last time a restore was actually tried

That last point is the least forgiving. A backup that has never been restored is a hypothesis, not a backup.

Detection24 hoursEarly warning72 hoursNotificationOne monthFinal report
The three stages set by Directive (EU) 2022/2555. The clock starts at detection, not at the incident.

Governance: management is named

This is the change directors see coming least. Risk management measures have to be approved and supervised by management, and the directive provides for members of management bodies to follow training. Cybersecurity stops being a subject delegated to the IT department.

In practice: an item on the agenda, a written record of decisions, and somebody who answers for it. An organisation where nobody knows who answers for cybersecurity already has a gap, before any technical examination.

NIS2 and Microsoft 365

Many Luxembourg companies already run most of their IT in Microsoft 365. A properly configured tenant covers part of the technical measures: multi-factor authentication and conditional access, access rights, logging, encryption, document classification with Purview.

What it does not cover, and this has to be said in the same breath: governance, the inventory of providers, the notification procedure, and the evidence that all of it works. A tenant is not compliance. It is a foundation, and a substantial one once it is configured, which by default it almost never is.

NIS2 and CyberOne

CyberOne comes in two tiers, Standard and Premium. Premium includes all of Standard and adds four assessments and an active hybrid SOC.

Against NIS2, what the offer brings is tooling and regularity: the security rules, awareness for the teams, monitoring, and assessments that feed the gap analysis. What it does not bring is the compliance decision, which stays yours.

Part of this spending can be state-funded: see the SME Packages, up to 70% funding, subject to eligibility conditions and to a decision by the Ministry of the Economy.

The official sources

This page does not ask to be taken on trust. The four texts it summarises are public, and they are what counts, not our summary.

Frequently asked questions

Frequently asked questions

Where do I start if I do not know whether I am in scope?

With the sector and the size, then with the subcontractor question: do you work for a regulated entity? The three answers fit into one meeting, and that is where the audit starts.

Can a provider make me NIS2 compliant?

No. A provider puts measures in place, documents and tools them. Compliance itself is assessed at the entity subject to the law, by its supervisory authority. An offer that promises compliance itself is promising something it does not hold.

What is the difference between a NIS2 audit and a gap analysis?

The audit records what exists. The gap analysis sets that record against the expected measures and draws a prioritised list from it. The first describes, the second decides the order.

How long does a NIS2 audit take?

It depends on the size of the estate and the number of providers, and we do not announce it in advance on a website. Scope and timing are fixed before we start, in the quote.

Do I need a SOC to be in order?

The law asks for a detection and response capability, not for a SOC by name. A SOC is one way of getting there, relevant above a certain size or a certain level of risk. Below that, lighter monitoring and a written procedure can be enough.

The simplest thing is to talk it through

A first estimate within 24 working hours, a firm quote after we audit your IT estate. No commitment, over a coffee if you prefer.

Direct contact

Sales e-mail

hello@empirys.com

Address

2 Am Brill, L-3961 Ehlange-sur-Mess