Law / Luxembourg

Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification

Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité, Art. 14

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 4 months, effective 10 May 2026.

A vulnerability and incident reporting rule binding public and private bodies.

As of 14 September 2026.

What it requires

  • This binds an entité essentielle or entité importante under Article 11, which reaches you where you qualify as at least a medium-sized enterprise under the EU size-cap rule (Commission Recommendation 2003/361/EC) and you are named in Annexe II point 6 as an online-marketplace provider, an online-search-engine provider or a social-networking-services-platform provider, or where you are a public-administration entity under Annexe I point 10; the wider sector classes this article also reaches are not separately flagged here, for the reason given on this jurisdiction's companion risk-management row.
  • Notify the competent authority, without undue delay, of any incident with a significant impact on the provision of your services: treat an incident as significant where it has caused or is capable of causing severe operational disruption or financial loss to you, or considerable material, physical or moral damage to another person.
  • Submit an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious acts or could have cross-border effect.
  • Follow with a fuller incident notification within 72 hours of becoming aware, updating the early warning and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
  • Submit an intermediate report if a CSIRT or the competent authority requests one, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.
  • Where appropriate, notify the recipients of your services, without undue delay, of a significant incident likely to affect the services they receive from you, and of any measures or corrections they can apply in response to a significant cyber threat.
  • If you are a qualified trust-service provider, notify significant incidents affecting your trust services within 24 hours of becoming aware, without the 72-hour and later stages that apply to other entities.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 26's penalty regime for an Article 14 violation is an administrative fine (amende administrative), enforced through an administrative appeal (recours en réformation) to the tribunal administratif; no provision reviewed here makes a failure to report itself a criminal offence.

Penalty structure

The same Article 26(4) and 26(5) tiers that govern an Article 12 violation govern a violation of Article 14, paragraphs 1 to 4: EUR 10,000,000 or 2 percent of worldwide turnover for an essential entity, and EUR 7,000,000 or 1.4 percent of turnover for an important entity, whichever amount is higher in each case. Article 26(7) separately lets the competent authority attach a daily astreinte (penalty payment) to compel an end to a violation, capped at EUR 1,250 per day of the breach and EUR 25,000 in total.

Rule
Higher of
As of
14 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Institut luxembourgeois de régulation (ILR), the general competent authority for cybersecurity under this law; the Commission de surveillance du secteur financier (CSSF) is the competent authority instead for the banking sector and the financial-market-infrastructure sector, and for the digital-infrastructure and ICT-service-management sectors as far as CSSF's own supervision reaches.

Settledness

As of
14 September 2026
Guidance link
https://www.ilr.lu/cadre-legal/loi-nis2/
Guidance body
Institut luxembourgeois de régulation (ILR)

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 14 requires an entité essentielle or entité importante to notify the competent authority, without undue delay, of any incident with a significant impact on the provision of its services (an incident important), and, where appropriate, to notify the recipients of its services of a significant incident likely to affect the supply of those services.

An incident is significant if it has caused or is capable of causing severe operational disruption or financial loss to the entity, or has affected or is capable of affecting other natural or legal persons through considerable material, physical or moral damage.

The notification runs on a graduated clock: an early warning within 24 hours of becoming aware of the incident, a fuller notification within 72 hours giving an initial assessment of its severity and impact and any indicators of compromise, an intermediate report on request, and a final report within one month of the 72-hour notification (or a progress report followed by a final report if the incident is still ongoing at that point), transposing NIS2 Article 23.

A qualified trust-service provider notifies on the shorter 24-hour clock alone, by derogation. The mere act of notifying an incident does not itself increase the notifying entity's liability, and the competent authority forwards the notification to the relevant CSIRT and the single point of contact upon receiving it.

When LexLint raises it

  • operates_social_platform

Read the law

Loi du 5 mai 2026, Journal officiel du Grand-Duché de Luxembourg (Legilux), Art. 14

Back to the example  ·  Lint your app