Since the law of 5 May 2026, the NIS2 directive has been applicable law in Luxembourg. A typical SME scenario: a company with 60 employees, supplying industry — and management asks: "Does this even apply to us, or is it just for banks and energy providers?" Right now, uncertainty is greater than knowledge. Time to untangle it — from practice, not from the legal text.
Step 1: Are you in scope at all?
The honest answer: probably more often than you think. NIS2 does not only hit the obvious sectors. Typical affected SME areas in Luxembourg:
- Healthcare — facilities above a certain size, laboratories, medical technology suppliers
- Manufacturing — makers of devices, machinery or electronics
- Food and chemicals — manufacturers and distributors
- Digital services — cloud providers, hosters, managed service providers
- Logistics and transport
- Suppliers to critical infrastructure — the classic case almost nobody has on their radar
Rule of thumb: from 50 employees or €10 million in annual turnover in one of these sectors, you are very likely in scope — certain critical services regardless of size. Affected entities must also register themselves with the supervisory authority: for most sectors with the ILR via the guichet.ilr.lu portal, for the financial sector with the CSSF. When in doubt: don't speculate — have it checked in 30 minutes.
Step 2: What management is now personally accountable for
This is the part that hurts many SMEs. NIS2 makes cybersecurity a board-level matter with personal accountability: measures must be formally approved by management, and leadership can be held personally liable for gross failures. In practice, that means three things: a written, up-to-date and approved security strategy (not a PDF from 2019); regular training for management itself, not just the IT team; and proof that sufficient budget is allocated. Without these basics, any audit gets uncomfortable fast.
Step 3: The reporting obligation — the underestimated trap
Significant security incidents must be reported — in Luxembourg via the ILR's SERIMA platform (to the CSSF in the financial sector). The deadlines are staged: early warning within 24 hours, a more detailed notification within 72 hours, and a final report within one month. 24 hours sounds like a lot — it isn't: the clock starts on becoming aware, and in a ransomware night, management often only finds out in the morning. That leaves just a few real hours while forensics run, the business stands still and employees ask questions. The practical recommendation: build the reporting duty into your incident response plan — whoever starts looking for the template mid-crisis has already lost.
Step 4: The supply chain — the blind spot
NIS2 requires you to assess the security of your suppliers too: cloud provider, CRM vendor, external IT service provider — all of them need to be on board contractually and in practice. And the reverse applies as well: a typical scenario is the SME that suddenly receives an extensive security questionnaire from a major customer — those who can't answer drop out of the supply chain. NIS2 is thus not just an obligation; it is increasingly a sales requirement.
What penalties really mean
Up to €10 million or 2% of worldwide annual turnover for essential entities. What's rarely mentioned: the authority can make violations public. For an SME that lives on trust, that is often worse than the fine.
The way through NIS2 — without 200-page PDFs
No standard audit, but three consecutive steps: gap workshop (1 day) — walk through the NIS2 requirements against your real systems and prioritise. Roadmap (4–8 weeks) — implement the quick wins (MFA, backup hardening, logging, incident plan) and plan the longer topics. Ongoing operation — monitoring, regular tests and management reports you can also present in an audit.
Clarity in 30 minutes
Instead of speculating whether you're in scope: 30 minutes on the phone is usually enough to set the direction. Or start with the free NIS2 checklist. — 📞 +352 20 60 12 44 · 📧 mail@local-it-partner.lu
Questions about this topic?
We are happy to advise you personally on Compliance and other IT topics.
Matching services from Local-IT-Partner
More articles you may like
Zero Trust: why VPN alone is negligent in 2026
One click in the home office, one open VPN tunnel — and the whole network stops. Why classic VPN security is obsolete and what Zero Trust really looks like in SMEs.
When the backup gets encrypted too: the three design flaws behind almost every data loss
"Everything's gone — including the backup." Why the cause is rarely the ransomware itself but three design flaws — and how the 3-2-1-1-0 rule prevents them.
