The European NIS2 directive has been law in Luxembourg since the Law of 5 May 2026, in force on 15 May. The deadline for self-registration with the ILR was 10 July 2026, and it has passed. Here is what is still to be done, without the jargon.
What is NIS2, in two sentences?
NIS2 (Network and Information Security 2) is the European directive that raises cybersecurity requirements for companies in sectors deemed essential or important. In Luxembourg it was transposed by the Law of 5 May 2026, which mandates security measures, cyber risk governance and the notification of major incidents.
Is your SME concerned?
The directive draws two categories:
- Essential entities: highly critical sectors, at least 250 employees and more than €50m turnover (or more than €43m on the balance sheet).
- Important entities: medium-sized companies (from 50 employees) in the covered sectors.
The sectors covered include energy, transport, health, water, digital infrastructure, ICT services, public administration and the manufacture of critical products. Even below these thresholds, an SME can be concerned if it provides a critical service or works as a subcontractor to a regulated entity.
Worth remembering: many company directors assume this does not apply to them. In practice the subcontracting chain widens the scope considerably. When in doubt, a few minutes of checking beats a penalty.
The 10 July 2026 deadline has passed
Essential and important entities had to self-register with the Institut Luxembourgeois de Régulation (ILR) by 10 July 2026 at the latest, using the Institute’s self-registration form. Registration is not automatic: it is up to the company to take the step.
If you have not done so, registration remains the expected step — and above all, the substantive obligations are not suspended by the delay: they have been running since the law came into force on 15 May 2026.
What are the concrete obligations?
Beyond registration, the entities concerned must put proportionate measures in place:
- security risk analysis and management;
- technical measures: backups, encryption, access control, detection;
- notification of any significant incident within 24 hours, an obligation in force since 15 May 2026;
- supply chain security (suppliers and subcontractors);
- accountability of management, which must approve and oversee the implementation of risk management measures.
What does inaction cost?
- up to 10 million euros or 2 % of annual worldwide turnover for essential entities;
- up to 7 million euros or 1.4 % of annual worldwide turnover for important entities.
On top of that come reputational risk and, if an incident is not contained, business interruption.
Where to start? A four-step plan
- Determine whether you are concerned: sector, size, role in a critical chain.
- Register with the ILR if you have not already.
- Run a gap audit between your current practices and the NIS2 requirements.
- Implement the missing measures: governance, protection, detection and a notification procedure.
How Empirys helps
Empirys is an IT company in Luxembourg that supports SMEs and mid-caps along the NIS2 path: compliance audit, implementation of technical measures and continuous monitoring through CyberOne, our packaged cybersecurity offer, whose Premium level adds an active hybrid SOC.
Part of these measures can be state-funded: see the SME Packages, up to 70 % funding — subject to the eligibility conditions and to the decision of the Ministry of the Economy.
Want to know whether NIS2 applies to you? Talk to an expert — first estimate within 24 working hours, firm quote after audit.
Frequently asked questions
Frequently asked questions
Is NIS2 mandatory in Luxembourg?
Yes. The directive was transposed by the Law of 5 May 2026, which came into force on 15 May 2026. Essential and important entities have legal obligations, including registration with the ILR.
Is my SME with fewer than 50 employees concerned?
The important-entity threshold generally starts at 50 employees, but a smaller organisation can be concerned if it provides a critical service or works as a subcontractor to a regulated entity.
What is the penalty for non-compliance?
Up to 10 million euros or 2 % of annual worldwide turnover for an essential entity, and up to 7 million euros or 1.4 % for an important entity.
Who is the competent authority in Luxembourg?
The Institut Luxembourgeois de Régulation (ILR). Self-registration is done with the ILR, and the ILR carries out supervision.
The 10 July 2026 deadline has passed — what now?
Registration with the ILR remains the expected step, and the substantive obligations have been running since 15 May 2026 — in particular the notification of significant incidents within 24 hours. Being late does not suspend them.
