You missed the ILR registration deadline. What happens now?
Registration was due by 10 July 2026. Not registering is a breach in its own right — but coming forward late is a very different position from being found out.
When the Law of 5 May 2026 entered into force, in-scope entities were given a two-month window to identify themselves to the Institut Luxembourgeois de Régulation. That window closed on 10 July 2026. A significant number of Luxembourg companies did not register, and most of them did not register for the same reason: they did not know the law reached them.
If that describes your company, the position is recoverable. It gets less recoverable with time.
Why late registration is not a small thing
Registration is not administrative housekeeping attached to the real obligations. It is an obligation in itself. Failing to register is a standalone breach, sanctionable on its own terms, independently of whether your security measures are any good.
That has an awkward consequence. A company can have genuinely solid security — patched systems, multi-factor authentication, tested backups — and still be in breach purely because nobody filed a form. The regulator has no way of knowing you exist, which is precisely what the registration requirement is designed to fix.
The distinction that actually matters
There is a considerable difference between two situations that look similar on paper.
| Coming forward | Being found |
|---|---|
| You register late, unprompted | The ILR identifies you during sector mapping, or after an incident |
| You arrive with a documented action plan | You arrive with an explanation |
| The conversation is about your timeline | The conversation is about your breach |
Regulators, generally speaking, distinguish between an entity that identified its own failure and corrected it, and one that was discovered. Nothing in the law guarantees leniency for voluntary disclosure, and we would not promise it. But arriving with a registration, a risk analysis and a dated remediation plan is a materially stronger position than arriving with none of those after a supervisory letter.
The worst version of this. An unregistered entity suffers a significant incident, has to notify within 24 hours, and in doing so reveals to the regulator both the incident and the fact that it should have registered eleven months earlier. Two breaches surface at once, at the least convenient possible moment.
What to do, in order
- Confirm you are actually in scope. Do not register defensively. Registering an entity that is out of scope creates obligations you do not have. Work through the sector and size tests properly first.
- Gather what the registration asks for. Typically: RCS number, NACE code, headcount and turnover, the services you provide, your sites in Luxembourg, and a security contact reachable around the clock. That last one is not a formality — it is the number the authorities will call.
- File it. Through the ILR's self-registration form.
- Have something to show behind it. Registration puts you on the register; it does not make you compliant. If you register and then do nothing, you have told the regulator where to find you and given them nothing to find. Have at least a risk analysis and a dated action plan in progress.
If you are not sure whether you were ever in scope
Many of the companies that missed the deadline missed it honestly. The sectors in Annex II — manufacturing, food, waste, postal services, digital providers, research — do not describe themselves as critical infrastructure, and their managing directors had no particular reason to read a cybersecurity law.
Establishing scope is a short exercise: your sector against the annexes, your headcount and turnover against the thresholds, and a check of the size-independent categories. It takes about half an hour and produces a written answer you can keep on file, which is useful whichever way it comes out.
A note on accuracy. This is a plain-language summary for information only, not legal advice, and it does not predict how the ILR will treat any individual case. The authoritative texts are the Law of 5 May 2026 (Mémorial A n° 225), Directive (EU) 2022/2555, and the guidance published by the Institut Luxembourgeois de Régulation.