Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 4 months, effective 10 May 2026.
A vulnerability and incident reporting rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds an entité essentielle or entité importante under Article 11, which reaches you where you qualify as at least a medium-sized enterprise under the EU size-cap rule (Commission Recommendation 2003/361/EC) and you are named in Annexe II point 6 as an online-marketplace provider, an online-search-engine provider or a social-networking-services-platform provider, or where you are a public-administration entity under Annexe I point 10; the wider sector classes this article also reaches are not separately flagged here, for the reason given on this jurisdiction's companion risk-management row.
- Notify the competent authority, without undue delay, of any incident with a significant impact on the provision of your services: treat an incident as significant where it has caused or is capable of causing severe operational disruption or financial loss to you, or considerable material, physical or moral damage to another person.
- Submit an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious acts or could have cross-border effect.
- Follow with a fuller incident notification within 72 hours of becoming aware, updating the early warning and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
- Submit an intermediate report if a CSIRT or the competent authority requests one, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.
- Where appropriate, notify the recipients of your services, without undue delay, of a significant incident likely to affect the services they receive from you, and of any measures or corrections they can apply in response to a significant cyber threat.
- If you are a qualified trust-service provider, notify significant incidents affecting your trust services within 24 hours of becoming aware, without the 72-hour and later stages that apply to other entities.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 26's penalty regime for an Article 14 violation is an administrative fine (amende administrative), enforced through an administrative appeal (recours en réformation) to the tribunal administratif; no provision reviewed here makes a failure to report itself a criminal offence.
Penalty structure
The same Article 26(4) and 26(5) tiers that govern an Article 12 violation govern a violation of Article 14, paragraphs 1 to 4: EUR 10,000,000 or 2 percent of worldwide turnover for an essential entity, and EUR 7,000,000 or 1.4 percent of turnover for an important entity, whichever amount is higher in each case. Article 26(7) separately lets the competent authority attach a daily astreinte (penalty payment) to compel an end to a violation, capped at EUR 1,250 per day of the breach and EUR 25,000 in total.
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Institut luxembourgeois de régulation (ILR), the general competent authority for cybersecurity under this law; the Commission de surveillance du secteur financier (CSSF) is the competent authority instead for the banking sector and the financial-market-infrastructure sector, and for the digital-infrastructure and ICT-service-management sectors as far as CSSF's own supervision reaches.
Settledness
- As of
- 14 September 2026
- Guidance link
- https://www.ilr.lu/cadre-legal/loi-nis2/
- Guidance body
- Institut luxembourgeois de régulation (ILR)
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 14 requires an entité essentielle or entité importante to notify the competent authority, without undue delay, of any incident with a significant impact on the provision of its services (an incident important), and, where appropriate, to notify the recipients of its services of a significant incident likely to affect the supply of those services.
An incident is significant if it has caused or is capable of causing severe operational disruption or financial loss to the entity, or has affected or is capable of affecting other natural or legal persons through considerable material, physical or moral damage.
The notification runs on a graduated clock: an early warning within 24 hours of becoming aware of the incident, a fuller notification within 72 hours giving an initial assessment of its severity and impact and any indicators of compromise, an intermediate report on request, and a final report within one month of the 72-hour notification (or a progress report followed by a final report if the incident is still ongoing at that point), transposing NIS2 Article 23.
A qualified trust-service provider notifies on the shorter 24-hour clock alone, by derogation. The mere act of notifying an incident does not itself increase the notifying entity's liability, and the competent authority forwards the notification to the relevant CSIRT and the single point of contact upon receiving it.
When LexLint raises it
operates_social_platform
Read the law
Loi du 5 mai 2026, Journal officiel du Grand-Duché de Luxembourg (Legilux), Art. 14