Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Risk-Management Measures for Essential and Important Entities
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 4 months, effective 10 May 2026.
A sector security regimes rule binding public and private bodies.
As of 14 September 2026.
What it requires
- This binds an entité essentielle (essential entity) or entité importante (important entity) under Article 11, which reaches you where you qualify as at least a medium-sized enterprise under the EU size-cap rule (Commission Recommendation 2003/361/EC) and you are named in Annexe II point 6 as an online-marketplace provider, an online-search-engine provider or a social-networking-services-platform provider, or where you are a public-administration entity under Annexe I point 10; the wider sector classes Annexe I and Annexe II also reach (energy, transport, health, digital infrastructure, ICT-service management, banking and financial-market infrastructure among them) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
- Take technical, operational and organisational measures appropriate and proportionate to the risks facing the network and information systems you use for your activities or to provide your services, and act to eliminate or reduce the impact of an incident on the recipients of your services and on other services.
- Cover at least: risk analysis and information-system-security policy; incident handling; business continuity, including backup management and crisis management; supply-chain security, including the security of your relationships with direct suppliers and service providers; security in the acquisition, development and maintenance of your systems, including vulnerability handling and disclosure; evaluating the effectiveness of your own risk-management measures; basic cyber-hygiene practices and cybersecurity training; policies on cryptography and, where appropriate, encryption; personnel security, access-control policy and asset management; and multi-factor or continuous authentication, secure voice, video and text communications, and secure emergency communication systems as needed.
- Notify the measures you take under this duty to the competent authority in the form, format and timeframe it sets by règlement or circulaire.
- Have your management body approve these risk-management measures, oversee their implementation, and complete regular training on assessing risk and risk-management practice; expect the body to be held liable for the entity's violation of this duty.
- Where you find you are not complying with these measures, take, without undue delay, all necessary, appropriate and proportionate corrective measures.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 26's penalty regime for an Article 12 violation is an administrative fine (amende administrative), enforced through an administrative appeal (recours en réformation) to the tribunal administratif; no provision reviewed here makes the violation itself a criminal offence.
Penalty structure
Article 26(4) sets the maximum administrative fine for an essential entity's violation of Article 12 (or Article 14, paragraphs 1 to 4) at EUR 10,000,000 or 2 percent of the total worldwide annual turnover of the preceding financial year of the undertaking the essential entity belongs to, whichever is higher. Article 26(5) sets the important-entity tier at the same violations at EUR 7,000,000 or 1.4 percent of turnover, whichever is higher. Article 26(7) separately lets the competent authority attach a daily astreinte (penalty payment) to compel an end to a violation, capped at EUR 1,250 per day of the breach and EUR 25,000 in total.
- Rule
- Higher of
- As of
- 14 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Institut luxembourgeois de régulation (ILR), the general competent authority for cybersecurity under this law; the Commission de surveillance du secteur financier (CSSF) is the competent authority instead for the banking sector and the financial-market-infrastructure sector, and for the digital-infrastructure and ICT-service-management sectors as far as CSSF's own supervision reaches.
Settledness
- As of
- 14 September 2026
- Guidance link
- https://www.ilr.lu/cadre-legal/loi-nis2/
- Guidance body
- Institut luxembourgeois de régulation (ILR)
- Open questions
- Does the Institut luxembourgeois de régulation's règlement or circulaire under Article 12(1) (the risk-analysis framework) or Article 12(3) (the notification of measures taken) narrow or specify how the duty applies to an online-marketplace, online-search-engine or social-networking-services-platform provider specifically?
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 12 requires an entité essentielle (essential entity) or entité importante (important entity) to take technical, operational and organisational measures appropriate and proportionate to the risks threatening the security of the network and information systems it uses for its activities or services, and to eliminate or reduce the impact of incidents on the recipients of its services and on other services.
The measures must follow an all-hazards approach and cover at least ten categories: risk-analysis and information-system-security policy, incident handling, business continuity including backup and crisis management, supply-chain security, security in the acquisition, development and maintenance of systems including vulnerability handling and disclosure, evaluating the measures' own effectiveness, basic cyber-hygiene and training, cryptography and encryption policy, human-resources security, access control and asset management, and multi-factor or continuous authentication and secure communications, transposing NIS2 Article 21.
Annexe II point 6 names an online-marketplace provider, an online-search-engine provider and a social-networking-services-platform provider among the digital providers this duty reaches expressly. Annexe I point 10 separately reaches public-administration entities, as defined by Article 2. Article 13 requires the entity's management body to approve these measures and oversee their implementation, and states that the body may be held liable for the entity's violation of Article 12.
When LexLint raises it
operates_social_platform
Read the law
Loi du 5 mai 2026, Journal officiel du Grand-Duché de Luxembourg (Legilux), Art. 12