Is your company concerned by NIS2 in Luxembourg?
Two tests decide it — your sector and your size. A third route catches companies below both thresholds, and it is the one most often missed.
Since the Law of 5 May 2026 came into force, a great many Luxembourg companies have been trying to answer a deceptively simple question: does this apply to us? The answer is not a judgement call. It is a sequence of tests, and you can work through them in about ten minutes.
Test one: your sector
The law lists sectors in two annexes. Annex I covers the eleven sectors of high criticality — energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II adds postal and courier services, waste management, chemicals, food production and distribution, manufacturing, digital providers and research.
That second list is where Luxembourg companies are most often surprised. Manufacturing and food are in scope. A company producing machine parts in the south of the country, with no idea it had a cybersecurity obligation, may well be an important entity.
Test two: your size
Sector alone is not enough. You also have to meet a size threshold, and the threshold determines which of two categories you land in.
| Essential entity | Important entity | |
|---|---|---|
| Staff | 250 or more | 50 to 249 |
| Turnover | Above €50m | €10m to €50m |
| Supervision | Proactive — annual filing to the ILR | Reactive — inspected after an incident or complaint |
| Maximum fine | €10m or 2% of worldwide turnover | €7m or 1.4% of worldwide turnover |
The security obligations themselves are identical for both categories. What differs is how closely you are watched, and how much you have to send in unprompted.
The exceptions that ignore size entirely
A short list of activities brings you into scope whatever your headcount. If you are the sole provider of a service in Luxembourg, a trust service provider, a DNS service provider, a top-level domain registry, a provider of public electronic communications networks, or already designated as a critical entity, size does not save you. A four-person trust service provider is in scope; a four-person bakery is not.
The route most companies miss
Here is where the analysis usually goes wrong. Companies check the two tests, find themselves below the thresholds, and conclude they have nothing to do. Then a client sends them a security questionnaire.
Article 21 of the directive requires in-scope entities to manage the security risks in their supply chain, including their relationships with direct suppliers. An entity that must comply cannot simply hope its IT provider is secure — it has to impose requirements contractually. So the obligation propagates downward through contracts, reaching companies the law never names.
If you provide IT services to a Luxembourg bank, insurer, hospital, energy company or manufacturer above the thresholds, you will be asked to evidence the same controls. Not by the ILR — by your customer, at renewal, with your contract as leverage.
The same happens through DORA in the financial sector, which imposes its own contractual requirements on ICT third-party providers serving financial entities. In a country with Luxembourg's concentration of financial institutions, that catches a considerable number of small technology companies.
What to do with the answer
If both tests point at you, the immediate obligations are registration with the ILR, the ten risk-management measures of Article 21, management-body approval and training, and incident reporting on a 24-hour, 72-hour and one-month schedule.
If only the supply-chain route applies, you have no direct legal obligation — but you have a commercial one that behaves almost identically, and arriving at a client's renewal conversation without evidence is an expensive way to discover that.
If none of the three applies, you are genuinely outside the scope of the law, and anyone selling you a mandatory compliance audit is selling you something you do not need.
A note on accuracy. This is a plain-language summary for information only, not legal advice. The authoritative texts are the Law of 5 May 2026 (Mémorial A n° 225), Directive (EU) 2022/2555, and the guidance published by the Institut Luxembourgeois de Régulation. The ILR also publishes an applicability simulator.