Regulatory pillar

Digital compliance in Luxembourg: what changes between 2026 and 2028

Digital compliance in Luxembourg now rests on six distinct regimes: NIS 2, DORA, the AI Act, the Cyber Resilience Act, the Data Act and the GDPR-eIDAS foundation. Each has its own scope. Working out which one applies determines every euro spent afterwards.

Direct answer

As of 3 October 2026, NIS 2, DORA, AI Act transparency (since 2 August 2026) and Cyber Resilience Act reporting (since 11 September 2026) already apply in Luxembourg. The next deadlines are the marking of AI-generated content on 2 December 2026, transposition of the product liability directive on 9 December 2026, then the Data Act's removal of cloud exit fees on 12 January 2027.

The first step is one of qualification, not a technical one. It means determining which regime applies to the entity, assessing thresholds at group level and settling how NIS 2 and DORA interact. A financial entity subject to DORA is excluded from the scope of the NIS 2 Law. A company that looks out of scope on its standalone accounts alone may come into scope once its linked enterprises are consolidated.

Overview

Digital compliance timeline 2026-2028 in Luxembourg

Five regimes already apply: DORA since January 2025, the Data Act since September 2025, NIS 2 since May 2026, AI Act transparency since August 2026 and Cyber Resilience Act vulnerability reporting since September 2026. Six deadlines remain, between December 2026 and August 2028. Many Luxembourg companies still have work to do on the first three.

Status as of 3 October 2026. Official sources cited section by section.
DeadlineRegimeWho is affectedStatus
17 January 2025 DORA
Regulation (EU) 2022/2554
Banks, PSFs, ManCos, AIFMs, insurance and reinsurance undertakings, payment institutions. Applicable
10 July 2026 NIS 2 Luxembourg
Law of 5 May 2026
Medium-sized and large entities in Annexes I and II. Thresholds assessed at group level. Deadline passed
2 August 2026 AI Act
Transparency and governance
Providers and deployers of AI systems, depending on their role. Applicable
11 September 2026 Cyber Resilience Act
Vulnerability reporting
Manufacturers, software vendors, importers and distributors of products with digital elements. Applicable
2 December 2026 AI Act
Labelling and new prohibition
Systems generating artificial content, already on the market on 2 August 2026. Next deadline
9 December 2026 Product liability Software vendors, manufacturers of digital products, integrators. To anticipate
12 January 2027 Data Act
Switching fees
Cloud, SaaS, PaaS and IaaS providers and their customers. To prepare
2 December 2027 AI Act
High risk, Annex III
AI used in recruitment, credit, education, biometrics, critical infrastructure. Postponed
11 December 2027 Cyber Resilience Act
Full application
Products with digital elements, CE marking. To anticipate
2 August 2028 AI Act
Embedded AI, Annex I
Machinery, medical devices, products subject to safety regulation. Postponed
Check whether your entity is in scope: NIS 2 and DORA scope check
Pillar 01 · Cybersecurity

NIS 2 in Luxembourg: the Law of 5 May 2026

Directive (EU) 2022/2555 was transposed by the Law of 5 May 2026 on measures to ensure a high level of cybersecurity, published in Mémorial A No. 225 and in force since 10 May 2026. It repeals the NIS 1 Law of 28 May 2019 and opened a two-month self-registration window, which closed on 10 July 2026.

Who is covered by NIS 2 in Luxembourg?

NIS 2 targets medium-sized and large entities operating in the sectors listed in Annexes I and II of the Law, together with a small number of digital activities that are in scope regardless of size. Holding companies, wealth-holding structures and most professional services activities are not listed.

NIS 2 thresholds are assessed at group level

Headcount, turnover and balance sheet total thresholds are not read from the entity's standalone accounts. They include all linked enterprises, those controlled at more than 50%, and the proportionate share of partner enterprises held between 25% and 50%, under the European SME definition.

A Luxembourg subsidiary with twenty employees can therefore exceed the thresholds once the data of its linked enterprises enters the calculation and its activity falls within a listed sector. The conclusion depends on the sector, the group structure and the applicable aggregation rules, never on local headcount alone.

Activities in scope regardless of size

Three categories remain in scope whatever their size: providers of public electronic communications networks or services, trust service providers within the meaning of the eIDAS Regulation, and top-level domain name registries and DNS service providers.

Financial entities are excluded from the scope of NIS 2

Article 1(5) of the NIS 2 Law excludes entities covered by the DORA Regulation, in line with Article 2(4) of that Regulation. Where DORA applies, it applies instead of NIS 2 for the same facts, and supervision passes to the competent prudential authority. Pillar 02 sets out this interaction in detail.

Three qualifications, three regimes

Essential entity, important entity, out of scope. The distinction cannot be read from the corporate purpose or the NACE code. It results from cross-checking the actual activity, the consolidation perimeter and whether a special regime applies.

Start with the five-question scope check, then our regulatory compliance team can work through this cross-check with you and record the outcome in a dated note for the corporate file.

NIS 2 Luxembourg: the new obligations since 10 May 2026

The Luxembourg transposition splits roles between four institutions. The ILR is the lead competent authority and single point of contact: it operates the self-registration portal, receives incident notifications, carries out inspections and imposes administrative sanctions. The CSSF retains supervision of the financial sector under DORA. The HCPN provides national strategic coordination and representation towards the European Commission and ENISA. On incident response, CIRCL is the CSIRT for the private sector and municipalities, and GOVCERT.LU for the public sector.

In substance, the new obligation lies less in additional technical controls than in a requirement of continuous proof. The company must be able to demonstrate that its risks, suppliers, incidents and measures are governed and overseen by the management body, with the corresponding minutes.

NIS 2 documents and deadlines in Luxembourg

Registration with the ILR

Self-registration was due by 10 July 2026 at the latest, the portal having been open since April 2026. The process is declarative and the entity bears responsibility for its own qualification. An in-scope entity that has not registered should regularise without delay: the absence of registration is liable to be identified during the authority's inspections and cross-checks.

Incident notification: 24 hours, 72 hours, one month
24 hEarly warning to the ILR via the SERIMA platform, without undue delay after detection.
72 hFormal notification, with an initial assessment of severity, impact and indicators of compromise.
1 monthFinal report after the formal notification. An intermediate report remains possible.

In practice, this timetable requires a procedure for qualifying an incident and alerting management, IT, the DPO, legal and the ILR without waiting for teams to come back the next morning.

Risk management measures
  • Mapping of assets, networks, applications, data and critical services
  • Risk and dependency analysis, security policy approved by the management body
  • Business continuity, backups and documented restoration tests
  • Supply chain security and contractual clauses imposed on ICT providers
  • Vulnerability management, patch management, secure development
  • Multi-factor authentication, access control, privileged accounts, encryption
  • Recurring, traceable cyber training, for employees and executives alike

NIS 2 inspections and penalties in Luxembourg

Essential entities are subject to ex ante and ex post supervision. Important entities are mainly subject to ex post supervision, triggered by an incident, a complaint or a report. The timetable and practical arrangements for inspections should be checked against the ILR's most recent communications.

QualificationMaximum penaltySupervision
Essential entity€10 million or 2% of worldwide annual turnover, whichever is higherEx ante and ex post
Important entity€7 million or 1.4% of worldwide annual turnover, whichever is higherEx post

These come on top of corrective measures with immediate effect, including injunctions and the temporary suspension of a certification or an activity, as well as direct obligations on members of the management body under the conditions set by the Law.

Pillar 02 · Financial sector

DORA in Luxembourg: the special regime that displaces NIS 2

Regulation (EU) 2022/2554 on digital operational resilience for the financial sector has applied since 17 January 2025. It is a lex specialis: for the entities it covers, it replaces NIS 2. In Luxembourg, two authorities share its supervision, the CSSF and the Commissariat aux Assurances.

Who falls under DORA rather than NIS 2?

  • Credit institutions, PSFs, payment institutions and electronic money institutions
  • Investment firms, management companies (ManCos) and AIF managers (AIFMs)
  • Insurance and reinsurance undertakings, insurance intermediaries, certain pension funds
  • Central securities depositories, central counterparties, trading venues
  • MiCA-authorised crypto-asset service providers, credit rating agencies
  • Critical ICT third-party service providers, subject to direct oversight

CSSF or Commissariat aux Assurances: which supervisory authority?

The CSSF and the Commissariat aux Assurances have been designated as the competent authorities in Luxembourg for DORA, each for the entities it supervises. The CSSF covers banks, investment firms, payment and electronic money institutions, fund managers and crypto-asset service providers. The CAA covers insurance and reinsurance undertakings, their intermediaries and certain pension funds.

Filing channels also differ. CSSF entities file through the eDesk portal. Entities supervised by the CAA use the SOFiE or E-File channels, with dedicated reporting types for the register of information and incident notification.

Cascade effect on service providers

A SaaS vendor, an integrator or a managed services firm serving Luxembourg financial entities is not subject to DORA as such. It has the requirements passed down by contract: audit and access clauses, incident notification, subcontracting controls, exit plans. The same mechanism applies to NIS 2 across the supply chain.

DORA Luxembourg: the register of information and its filing timetable

CSSF-supervised entities were required to submit their 2026 register of information between 11 February and 31 March 2026, based on contracts in force at 31 December 2025. The register covers all contractual arrangements for ICT services, including chains of subcontractors. Entities under the CAA follow their own timetable and channels, to be checked with that authority.

DORA documents to produce in Luxembourg

  • Comprehensive inventory of ICT contracts and identification of critical or important functions
  • Register of information submitted to the competent authority on its own timetable
  • Mandatory contractual clauses: audit, access, notification, subcontracting, termination
  • Testable exit plans for each critical provider, and cloud concentration analysis
  • ICT risk management framework approved by the management body
  • Resilience testing, outage scenarios, incident notification procedures
Preliminary step

NIS 2 or DORA? The answer determines everything else.

Group-level thresholds, linked and partner enterprises included, DORA test first. The outcome is a dated, reasoned note to place in the corporate file.

Regulatory compliance services
Pillar 03 · Artificial intelligence

AI Act: what the omnibus regulation of 27 July 2026 changes

Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the deadline it amended. It postpones the obligations for high-risk systems without altering the architecture of the AI Act.

Who is covered by the AI Act?

Any company that provides, deploys, imports or distributes an AI system, depending on its role and the risk level of the system. Qualifying as a deployer is enough to trigger obligations.

Using an AI system to assess, shortlist or rank candidates can make the employer a deployer and, depending on the system's intended use, trigger the obligations applicable to high-risk systems. Incidental use of a generative assistant does not automatically lead to the same qualification.

AI Act 2026: obligations applicable on 2 August 2026

  • Article 50 transparency obligations for systems interacting with natural persons
  • Effective supervisory powers of the Commission over providers of general-purpose AI models
  • Penalty regime and governance provisions

Two obligations were already applicable and remain so: the ban on prohibited AI practices since February 2025, and the obligation to ensure a sufficient level of AI literacy within the organisation.

Labelling of generated content is deferred to 2 December 2026

The labelling provided for in Article 50(2) applies from 2 December 2026 for systems already on the market on 2 August 2026. Systems placed on the market from that date must comply immediately. The same date brings into force a prohibited practice added to Article 5, aimed at systems that generate or manipulate non-consensual intimate content and child sexual abuse material.

AI Act 2027-2028: high-risk system deadlines

02.12.2027Stand-alone high-risk systems under Annex III: recruitment, workforce management, credit assessment, education, essential services, biometrics, critical infrastructure. Postponed by sixteen months.
02.08.2028AI embedded in regulated products under Annex I: machinery, medical devices, toys and other products subject to European safety legislation. Postponed by twelve months.

This postponement does not relieve any obligation that already applies. It buys time on the heavy documentation for high-risk systems, not on the inventory, transparency or AI literacy.

AI Act documents to prepare in 2026

  • Register of all AI tools in use, including free ones introduced without approval
  • Qualification of the company's role: provider, deployer, importer, distributor
  • Policy prohibiting the entry of confidential data into unapproved AI
  • Identification of decisions affecting employees or customers
  • Information for people interacting with an AI system, controls on generated content
  • Traceability of prompts, sources, models, human oversight and validations
  • AI clauses imposed on suppliers, and employee training
Pillar 04 · Digital products

Cyber Resilience Act: software and connected products

The Cyber Resilience Act imposes cybersecurity requirements on hardware and software products with digital elements placed on the Union market. Reporting obligations apply from 11 September 2026, the main compliance obligations from 11 December 2027.

Cyber Resilience Act: companies and software in scope

The Regulation covers manufacturers, software vendors, importers and distributors of products with digital elements, as well as remote data processing solutions integrated into those products.

A Luxembourg software vendor can fall under the CRA when it places on the market software that qualifies as a product with digital elements, for example an application or a solution with integrated remote data processing. A service delivered exclusively online, with no associated product, calls for a specific analysis and does not automatically fall within scope. Qualification is done case by case, on the basis of the text and the Commission's guidance.

Cyber Resilience Act: mandatory reporting from 11 September 2026

From that date, manufacturers report actively exploited vulnerabilities and severe incidents affecting the security of their products. The initial alert is due within 24 hours, the full notification within 72 hours. This timetable mirrors that of NIS 2, which makes it possible to pool the qualification and escalation procedure.

CRA documents and compliance deadlines

11.09.2026Vulnerability response function (PSIRT), coordinated disclosure policy, regulatory reporting procedure.
OngoingInventory of software components and dependencies (SBOM), traceability of versions and patches, post-market vulnerability monitoring.
11.12.2027Full application: security by design, defined support period, technical compliance documentation, CE marking.
Pillar 05 · Data and cloud

Data Act: cloud, SaaS and the end of exit fees

Regulation (EU) 2023/2854 on data has applied since 12 September 2025. It governs access to data generated by connected products, portability, data-sharing contracts, interoperability and switching between data processing service providers.

Data Act: cloud and SaaS providers in scope

The Regulation covers cloud, SaaS, PaaS and IaaS providers and their customers. Manufacturers and users of connected devices fall under the data access chapter.

Data Act: the end of exit fees on 12 January 2027

From that date, switching fees and data egress fees disappear. The deadline requires prior contractual and technical review, not a simple pricing adjustment: it affects export formats, data return timeframes and service commitments.

Data Act documents and clauses to prepare

  • Operational export formats, APIs and portability interfaces
  • Data return and deletion timeframes, reversibility clauses
  • Removal of exit fees and switching fees
  • Data usage rights and protection of trade secrets
  • Procedure for handling data requests from customers
Official Data Act sources
Pillar 06 · Permanent foundation

Digital compliance in Luxembourg: GDPR, accessibility, resilience and eIDAS 2

NIS 2, DORA, the AI Act, the CRA and the Data Act do not replace the permanent foundation. The GDPR, digital accessibility, the resilience of critical entities and the European digital identity each produce their own obligations, independently of the five regimes above.

GDPR: the foundation that never goes away

Record of processing activities, minimisation, retention periods, processor contracts, international transfers, impact assessments and data security. A breach likely to result in a risk must be notified to the CNPD within 72 hours of its discovery.

One practical point deserves attention: on a single incident, the GDPR, NIS 2 and CRA deadlines run simultaneously towards different authorities. A single notification matrix avoids discovering this collision in the middle of a crisis.

Digital accessibility: applicable since 28 June 2025

Certain products and services must meet European accessibility requirements: e-commerce, consumer banking services, electronic communications, computers and operating systems. Checks cover websites, applications, purchase journeys, forms, documents, authentication methods and support services.

Resilience of critical entities

The Luxembourg Law of 5 May 2026 on the resilience of critical entities complements NIS 2 with an all-hazards approach, covering physical, organisational and environmental risks as well as external dependencies. An entity formally notified as critical carries out a risk assessment within nine months of its notification.

European digital identity, eIDAS 2

Member States must offer European Digital Identity Wallets by the end of 2026. Companies engaged in digital onboarding, KYC, electronic signature or the issuance of credentials should plan for their integration, without collecting more data than necessary.

Official sources for the permanent foundation
Evidence

Digital compliance in Luxembourg: 14 documents you should be able to produce

A well-prepared Luxembourg company can quickly present fourteen categories of documents demonstrating its governance, risk management, incident procedures and control of its digital suppliers.

  • Security policy approved by the management body
  • Mapping of assets, networks, data and critical services
  • Risk and dependency analysis
  • Register of suppliers and ICT contractual arrangements
  • GDPR record of processing activities
  • Register of artificial intelligence systems
  • Incident management and notification procedure
  • Business continuity plan and recovery plan
  • Backup policy and restoration test results
  • Access and privileged account management policy
  • Vulnerability and patch management policy
  • Training reports and crisis exercise records
  • Contracts and exit plans for critical providers
  • Minutes demonstrating effective oversight by management

The fourteenth item is the one most often missing from the files we take over, and the one that exposes executives most directly.

Execution

Digital compliance programme in Luxembourg: start with the scope

The first step is to determine which texts apply to the company. This analysis cross-checks the actual business sector, the size of the group, the role played in the digital chain and whether a special regime such as DORA applies.

Launching a technical project before this step means spending without knowing which obligation it answers. A company that deploys a SOC without knowing its qualification ends up with an expensive tool and a documentation file that is still missing on the day of the inspection.

Step 1Applicability matrix. Cross-check actual sector, consolidation perimeter and special regime. Settle NIS 2 versus DORA.
Step 2Regularisation. ILR registration if in scope, or a reasoned and approved non-applicability note if out of scope.
Step 3Registers. Assets, ICT suppliers, processing activities, AI systems. A single incident notification matrix.
Step 4Governance. Risk analysis, policy approved by the board, executive training, documented crisis exercise.
Starting point

Establish your scope before you spend

Group-level thresholds, linked and partner enterprises included. DORA test first. The outcome is a dated, reasoned note to place in the corporate file.

Regulatory compliance services

Related digital compliance resources

Questions

Frequently asked questions on digital compliance in Luxembourg

Are all Luxembourg companies covered by NIS 2?

No. NIS 2 targets medium-sized and large entities in the sectors listed in Annexes I and II of the Law of 5 May 2026, together with a small number of digital activities that are in scope regardless of size. A holding company, an SPF (family wealth management company) or a professional services activity is not listed. Thresholds are, however, assessed at group level, which can bring an entity into scope that believed it was outside it.

Does a ManCo or a PSF have to register with the ILR?

No, subject to confirmation of its qualification. Article 1(5) of the NIS 2 Law excludes entities covered by DORA. A management company, an AIF manager or a PSF falls under DORA, supervised by the CSSF, and not under NIS 2, supervised by the ILR. For insurance and reinsurance undertakings, the competent authority is the Commissariat aux Assurances. The exclusion should be documented in writing rather than assumed.

What does an in-scope entity risk if it did not register before 10 July 2026?

Maximum penalties reach EUR 10 million or 2% of worldwide annual turnover for an essential entity, and EUR 7 million or 1.4% for an important entity. These come on top of corrective measures with immediate effect and direct obligations on members of the management body. Because the register is declarative, the absence of registration is liable to be identified during the authority's inspections and cross-checks. Immediate regularisation remains the most favourable course.

How are NIS 2 thresholds calculated within a group?

By consolidating all headcount, turnover and balance sheet total of linked enterprises, those controlled directly or indirectly at more than 50%, then adding the proportionate share of partner enterprises held between 25% and 50%. This is the most frequent gap between a self-assessment made on standalone accounts and the actual qualification.

Has the AI Act been postponed?

Partially. The omnibus regulation of 27 July 2026 postpones the obligations for Annex III high-risk systems to 2 December 2027, and those for AI embedded in regulated products to 2 August 2028. The prohibited practices, the AI literacy obligation, the rules for general-purpose models and the transparency obligations of 2 August 2026 are not postponed.

Does a Luxembourg SaaS vendor fall under the Cyber Resilience Act?

It depends on what is placed on the market. The CRA covers products with digital elements, including remote data processing solutions integrated into a product. A service delivered exclusively online, with no associated product, does not automatically fall within scope and calls for a case-by-case analysis.

Is an IT provider that is not itself in scope really unaffected?

No. A software vendor, an integrator or a managed services firm serving in-scope entities has these requirements passed down to it by contract: security clauses, audit and access rights, notification obligations, subcontracting controls, exit plans. Not having to register in its own right does not exempt it from the contractual compliance imposed through the supply chain.

Where should we start in practice?

With determining the scope of application, before any technical investment. Cross-check the actual business sector, the group's consolidation perimeter and whether a special regime applies. This work produces either a registration to regularise or a reasoned non-applicability note to place in the corporate file. In both cases, it conditions all later spending.

About this page
Author
Mickaël LOC, licensed accountant (comptable autorisé), seventeen years of Luxembourg accounting-firm practice, consolidation of multi-jurisdictional groups.
Scope
Informational content for executives and compliance officers of companies established in Luxembourg.
Method
Every date, threshold and penalty ceiling is taken from a primary source cited at the end of the section: Luxembourg authorities, the Official Journal, EUR-Lex, the European Commission.
Verification
3 October 2026 (calendar and statuses). The page is reviewed whenever a regulatory development affects any of the six regimes.

This page is neither legal advice nor an assurance engagement. Financial Services Luxembourg practises as a licensed accountant (comptable autorisé) within the meaning of the Law of 2 September 2011. Interpreting cybersecurity and product security legislation also calls for legal and technical expertise: client files touching on these matters are handled together with legal counsel and a specialist provider.

Amounts, conditions and deadlines that may change should be checked against the official sources cited.

CallRequest a quoteFirm quote within 48 h