IT emergency?+352 20 60 12 44
    Back to the blog
    Compliance
    12 May 2026
    5 min read

    NIS2 in Luxembourg: what the new law actually means for SMEs

    Since May 2026, NIS2 has been law in Luxembourg. Who is affected, what management is personally accountable for, and the 4 steps that matter now.

    Frank Schenkewitz
    CEO & IT-Security Experte

    Since the law of 5 May 2026, the NIS2 directive has been applicable law in Luxembourg. A typical SME scenario: a company with 60 employees, supplying industry — and management asks: "Does this even apply to us, or is it just for banks and energy providers?" Right now, uncertainty is greater than knowledge. Time to untangle it — from practice, not from the legal text.

    Step 1: Are you in scope at all?

    The honest answer: probably more often than you think. NIS2 does not only hit the obvious sectors. Typical affected SME areas in Luxembourg:

    • Healthcare — facilities above a certain size, laboratories, medical technology suppliers
    • Manufacturing — makers of devices, machinery or electronics
    • Food and chemicals — manufacturers and distributors
    • Digital services — cloud providers, hosters, managed service providers
    • Logistics and transport
    • Suppliers to critical infrastructure — the classic case almost nobody has on their radar

    Rule of thumb: from 50 employees or €10 million in annual turnover in one of these sectors, you are very likely in scope — certain critical services regardless of size. Affected entities must also register themselves with the supervisory authority: for most sectors with the ILR via the guichet.ilr.lu portal, for the financial sector with the CSSF. When in doubt: don't speculate — have it checked in 30 minutes.

    Step 2: What management is now personally accountable for

    This is the part that hurts many SMEs. NIS2 makes cybersecurity a board-level matter with personal accountability: measures must be formally approved by management, and leadership can be held personally liable for gross failures. In practice, that means three things: a written, up-to-date and approved security strategy (not a PDF from 2019); regular training for management itself, not just the IT team; and proof that sufficient budget is allocated. Without these basics, any audit gets uncomfortable fast.

    Step 3: The reporting obligation — the underestimated trap

    Significant security incidents must be reported — in Luxembourg via the ILR's SERIMA platform (to the CSSF in the financial sector). The deadlines are staged: early warning within 24 hours, a more detailed notification within 72 hours, and a final report within one month. 24 hours sounds like a lot — it isn't: the clock starts on becoming aware, and in a ransomware night, management often only finds out in the morning. That leaves just a few real hours while forensics run, the business stands still and employees ask questions. The practical recommendation: build the reporting duty into your incident response plan — whoever starts looking for the template mid-crisis has already lost.

    Step 4: The supply chain — the blind spot

    NIS2 requires you to assess the security of your suppliers too: cloud provider, CRM vendor, external IT service provider — all of them need to be on board contractually and in practice. And the reverse applies as well: a typical scenario is the SME that suddenly receives an extensive security questionnaire from a major customer — those who can't answer drop out of the supply chain. NIS2 is thus not just an obligation; it is increasingly a sales requirement.

    What penalties really mean

    Up to €10 million or 2% of worldwide annual turnover for essential entities. What's rarely mentioned: the authority can make violations public. For an SME that lives on trust, that is often worse than the fine.

    The way through NIS2 — without 200-page PDFs

    No standard audit, but three consecutive steps: gap workshop (1 day) — walk through the NIS2 requirements against your real systems and prioritise. Roadmap (4–8 weeks) — implement the quick wins (MFA, backup hardening, logging, incident plan) and plan the longer topics. Ongoing operation — monitoring, regular tests and management reports you can also present in an audit.

    Clarity in 30 minutes

    Instead of speculating whether you're in scope: 30 minutes on the phone is usually enough to set the direction. Or start with the free NIS2 checklist. — 📞 +352 20 60 12 44 · 📧 mail@local-it-partner.lu

    Tags:
    NIS2
    Compliance
    Cybersecurity
    Luxembourg
    SME

    Questions about this topic?

    We are happy to advise you personally on Compliance and other IT topics.

    Matching services from Local-IT-Partner