Digital compliance timeline 2026-2028 in Luxembourg
Five regimes already apply: DORA since January 2025, the Data Act since September 2025, NIS 2 since May 2026, AI Act transparency since August 2026 and Cyber Resilience Act vulnerability reporting since September 2026. Six deadlines remain, between December 2026 and August 2028. Many Luxembourg companies still have work to do on the first three.
| Deadline | Regime | Who is affected | Status |
|---|---|---|---|
| 17 January 2025 | DORA Regulation (EU) 2022/2554 |
Banks, PSFs, ManCos, AIFMs, insurance and reinsurance undertakings, payment institutions. | Applicable |
| 10 July 2026 | NIS 2 Luxembourg Law of 5 May 2026 |
Medium-sized and large entities in Annexes I and II. Thresholds assessed at group level. | Deadline passed |
| 2 August 2026 | AI Act Transparency and governance |
Providers and deployers of AI systems, depending on their role. | Applicable |
| 11 September 2026 | Cyber Resilience Act Vulnerability reporting |
Manufacturers, software vendors, importers and distributors of products with digital elements. | Applicable |
| 2 December 2026 | AI Act Labelling and new prohibition |
Systems generating artificial content, already on the market on 2 August 2026. | Next deadline |
| 9 December 2026 | Product liability | Software vendors, manufacturers of digital products, integrators. | To anticipate |
| 12 January 2027 | Data Act Switching fees |
Cloud, SaaS, PaaS and IaaS providers and their customers. | To prepare |
| 2 December 2027 | AI Act High risk, Annex III |
AI used in recruitment, credit, education, biometrics, critical infrastructure. | Postponed |
| 11 December 2027 | Cyber Resilience Act Full application |
Products with digital elements, CE marking. | To anticipate |
| 2 August 2028 | AI Act Embedded AI, Annex I |
Machinery, medical devices, products subject to safety regulation. | Postponed |
NIS 2 in Luxembourg: the Law of 5 May 2026
Directive (EU) 2022/2555 was transposed by the Law of 5 May 2026 on measures to ensure a high level of cybersecurity, published in Mémorial A No. 225 and in force since 10 May 2026. It repeals the NIS 1 Law of 28 May 2019 and opened a two-month self-registration window, which closed on 10 July 2026.
Who is covered by NIS 2 in Luxembourg?
NIS 2 targets medium-sized and large entities operating in the sectors listed in Annexes I and II of the Law, together with a small number of digital activities that are in scope regardless of size. Holding companies, wealth-holding structures and most professional services activities are not listed.
NIS 2 thresholds are assessed at group level
Headcount, turnover and balance sheet total thresholds are not read from the entity's standalone accounts. They include all linked enterprises, those controlled at more than 50%, and the proportionate share of partner enterprises held between 25% and 50%, under the European SME definition.
A Luxembourg subsidiary with twenty employees can therefore exceed the thresholds once the data of its linked enterprises enters the calculation and its activity falls within a listed sector. The conclusion depends on the sector, the group structure and the applicable aggregation rules, never on local headcount alone.
Activities in scope regardless of size
Three categories remain in scope whatever their size: providers of public electronic communications networks or services, trust service providers within the meaning of the eIDAS Regulation, and top-level domain name registries and DNS service providers.
Financial entities are excluded from the scope of NIS 2
Article 1(5) of the NIS 2 Law excludes entities covered by the DORA Regulation, in line with Article 2(4) of that Regulation. Where DORA applies, it applies instead of NIS 2 for the same facts, and supervision passes to the competent prudential authority. Pillar 02 sets out this interaction in detail.
Essential entity, important entity, out of scope. The distinction cannot be read from the corporate purpose or the NACE code. It results from cross-checking the actual activity, the consolidation perimeter and whether a special regime applies.
Start with the five-question scope check, then our regulatory compliance team can work through this cross-check with you and record the outcome in a dated note for the corporate file.
NIS 2 Luxembourg: the new obligations since 10 May 2026
The Luxembourg transposition splits roles between four institutions. The ILR is the lead competent authority and single point of contact: it operates the self-registration portal, receives incident notifications, carries out inspections and imposes administrative sanctions. The CSSF retains supervision of the financial sector under DORA. The HCPN provides national strategic coordination and representation towards the European Commission and ENISA. On incident response, CIRCL is the CSIRT for the private sector and municipalities, and GOVCERT.LU for the public sector.
In substance, the new obligation lies less in additional technical controls than in a requirement of continuous proof. The company must be able to demonstrate that its risks, suppliers, incidents and measures are governed and overseen by the management body, with the corresponding minutes.
NIS 2 documents and deadlines in Luxembourg
Registration with the ILR
Self-registration was due by 10 July 2026 at the latest, the portal having been open since April 2026. The process is declarative and the entity bears responsibility for its own qualification. An in-scope entity that has not registered should regularise without delay: the absence of registration is liable to be identified during the authority's inspections and cross-checks.
Incident notification: 24 hours, 72 hours, one month
In practice, this timetable requires a procedure for qualifying an incident and alerting management, IT, the DPO, legal and the ILR without waiting for teams to come back the next morning.
Risk management measures
- Mapping of assets, networks, applications, data and critical services
- Risk and dependency analysis, security policy approved by the management body
- Business continuity, backups and documented restoration tests
- Supply chain security and contractual clauses imposed on ICT providers
- Vulnerability management, patch management, secure development
- Multi-factor authentication, access control, privileged accounts, encryption
- Recurring, traceable cyber training, for employees and executives alike
NIS 2 inspections and penalties in Luxembourg
Essential entities are subject to ex ante and ex post supervision. Important entities are mainly subject to ex post supervision, triggered by an incident, a complaint or a report. The timetable and practical arrangements for inspections should be checked against the ILR's most recent communications.
| Qualification | Maximum penalty | Supervision |
|---|---|---|
| Essential entity | €10 million or 2% of worldwide annual turnover, whichever is higher | Ex ante and ex post |
| Important entity | €7 million or 1.4% of worldwide annual turnover, whichever is higher | Ex post |
These come on top of corrective measures with immediate effect, including injunctions and the temporary suspension of a certification or an activity, as well as direct obligations on members of the management body under the conditions set by the Law.
- NIS 2 section of the Luxembourg Institute of RegulationILR · competent authority
- Frequently asked questions on the scope of applicationILR
- Incident notification under NIS 2ILR
- Law of 5 May 2026, Mémorial A No. 225Legilux · Official Journal
- Directive (EU) 2022/2555, Articles 2, 20, 21 and 23EUR-Lex
DORA in Luxembourg: the special regime that displaces NIS 2
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector has applied since 17 January 2025. It is a lex specialis: for the entities it covers, it replaces NIS 2. In Luxembourg, two authorities share its supervision, the CSSF and the Commissariat aux Assurances.
Who falls under DORA rather than NIS 2?
- Credit institutions, PSFs, payment institutions and electronic money institutions
- Investment firms, management companies (ManCos) and AIF managers (AIFMs)
- Insurance and reinsurance undertakings, insurance intermediaries, certain pension funds
- Central securities depositories, central counterparties, trading venues
- MiCA-authorised crypto-asset service providers, credit rating agencies
- Critical ICT third-party service providers, subject to direct oversight
CSSF or Commissariat aux Assurances: which supervisory authority?
The CSSF and the Commissariat aux Assurances have been designated as the competent authorities in Luxembourg for DORA, each for the entities it supervises. The CSSF covers banks, investment firms, payment and electronic money institutions, fund managers and crypto-asset service providers. The CAA covers insurance and reinsurance undertakings, their intermediaries and certain pension funds.
Filing channels also differ. CSSF entities file through the eDesk portal. Entities supervised by the CAA use the SOFiE or E-File channels, with dedicated reporting types for the register of information and incident notification.
A SaaS vendor, an integrator or a managed services firm serving Luxembourg financial entities is not subject to DORA as such. It has the requirements passed down by contract: audit and access clauses, incident notification, subcontracting controls, exit plans. The same mechanism applies to NIS 2 across the supply chain.
DORA Luxembourg: the register of information and its filing timetable
CSSF-supervised entities were required to submit their 2026 register of information between 11 February and 31 March 2026, based on contracts in force at 31 December 2025. The register covers all contractual arrangements for ICT services, including chains of subcontractors. Entities under the CAA follow their own timetable and channels, to be checked with that authority.
DORA documents to produce in Luxembourg
- Comprehensive inventory of ICT contracts and identification of critical or important functions
- Register of information submitted to the competent authority on its own timetable
- Mandatory contractual clauses: audit, access, notification, subcontracting, termination
- Testable exit plans for each critical provider, and cloud concentration analysis
- ICT risk management framework approved by the management body
- Resilience testing, outage scenarios, incident notification procedures
- ICT and cyber risk for DORA entitiesCSSF · competent authority
- Commissariat aux Assurances, scope of supervisionCAA · competent insurance authority
- Regulation (EU) 2022/2554, Articles 2, 28 and 46EUR-Lex
- DORA section of the European Securities and Markets AuthorityESMA
NIS 2 or DORA? The answer determines everything else.
Group-level thresholds, linked and partner enterprises included, DORA test first. The outcome is a dated, reasoned note to place in the corporate file.
AI Act: what the omnibus regulation of 27 July 2026 changes
Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the deadline it amended. It postpones the obligations for high-risk systems without altering the architecture of the AI Act.
Who is covered by the AI Act?
Any company that provides, deploys, imports or distributes an AI system, depending on its role and the risk level of the system. Qualifying as a deployer is enough to trigger obligations.
Using an AI system to assess, shortlist or rank candidates can make the employer a deployer and, depending on the system's intended use, trigger the obligations applicable to high-risk systems. Incidental use of a generative assistant does not automatically lead to the same qualification.
AI Act 2026: obligations applicable on 2 August 2026
- Article 50 transparency obligations for systems interacting with natural persons
- Effective supervisory powers of the Commission over providers of general-purpose AI models
- Penalty regime and governance provisions
Two obligations were already applicable and remain so: the ban on prohibited AI practices since February 2025, and the obligation to ensure a sufficient level of AI literacy within the organisation.
Labelling of generated content is deferred to 2 December 2026
The labelling provided for in Article 50(2) applies from 2 December 2026 for systems already on the market on 2 August 2026. Systems placed on the market from that date must comply immediately. The same date brings into force a prohibited practice added to Article 5, aimed at systems that generate or manipulate non-consensual intimate content and child sexual abuse material.
AI Act 2027-2028: high-risk system deadlines
This postponement does not relieve any obligation that already applies. It buys time on the heavy documentation for high-risk systems, not on the inventory, transparency or AI literacy.
AI Act documents to prepare in 2026
- Register of all AI tools in use, including free ones introduced without approval
- Qualification of the company's role: provider, deployer, importer, distributor
- Policy prohibiting the entry of confidential data into unapproved AI
- Identification of decisions affecting employees or customers
- Information for people interacting with an AI system, controls on generated content
- Traceability of prompts, sources, models, human oversight and validations
- AI clauses imposed on suppliers, and employee training
- Regulatory framework for artificial intelligenceEuropean Commission
- AI omnibus regulation enters into forceEuropean Commission
- Final adoption of the simplification packageCouncil of the European Union
- Regulation (EU) 2024/1689, Articles 5, 6 and 50EUR-Lex
Cyber Resilience Act: software and connected products
The Cyber Resilience Act imposes cybersecurity requirements on hardware and software products with digital elements placed on the Union market. Reporting obligations apply from 11 September 2026, the main compliance obligations from 11 December 2027.
Cyber Resilience Act: companies and software in scope
The Regulation covers manufacturers, software vendors, importers and distributors of products with digital elements, as well as remote data processing solutions integrated into those products.
A Luxembourg software vendor can fall under the CRA when it places on the market software that qualifies as a product with digital elements, for example an application or a solution with integrated remote data processing. A service delivered exclusively online, with no associated product, calls for a specific analysis and does not automatically fall within scope. Qualification is done case by case, on the basis of the text and the Commission's guidance.
Cyber Resilience Act: mandatory reporting from 11 September 2026
From that date, manufacturers report actively exploited vulnerabilities and severe incidents affecting the security of their products. The initial alert is due within 24 hours, the full notification within 72 hours. This timetable mirrors that of NIS 2, which makes it possible to pool the qualification and escalation procedure.
CRA documents and compliance deadlines
- Cyber Resilience ActEuropean Commission
- Summary of the legislative text and product scopeEuropean Commission
- CRA resources from the European Union Agency for CybersecurityENISA
Data Act: cloud, SaaS and the end of exit fees
Regulation (EU) 2023/2854 on data has applied since 12 September 2025. It governs access to data generated by connected products, portability, data-sharing contracts, interoperability and switching between data processing service providers.
Data Act: cloud and SaaS providers in scope
The Regulation covers cloud, SaaS, PaaS and IaaS providers and their customers. Manufacturers and users of connected devices fall under the data access chapter.
Data Act: the end of exit fees on 12 January 2027
From that date, switching fees and data egress fees disappear. The deadline requires prior contractual and technical review, not a simple pricing adjustment: it affects export formats, data return timeframes and service commitments.
Data Act documents and clauses to prepare
- Operational export formats, APIs and portability interfaces
- Data return and deletion timeframes, reversibility clauses
- Removal of exit fees and switching fees
- Data usage rights and protection of trade secrets
- Procedure for handling data requests from customers
- Data ActEuropean Commission
- Data Act explained: timetable and switching feesEuropean Commission
- Regulation (EU) 2023/2854, Chapter VIEUR-Lex
Digital compliance in Luxembourg: GDPR, accessibility, resilience and eIDAS 2
NIS 2, DORA, the AI Act, the CRA and the Data Act do not replace the permanent foundation. The GDPR, digital accessibility, the resilience of critical entities and the European digital identity each produce their own obligations, independently of the five regimes above.
GDPR: the foundation that never goes away
Record of processing activities, minimisation, retention periods, processor contracts, international transfers, impact assessments and data security. A breach likely to result in a risk must be notified to the CNPD within 72 hours of its discovery.
One practical point deserves attention: on a single incident, the GDPR, NIS 2 and CRA deadlines run simultaneously towards different authorities. A single notification matrix avoids discovering this collision in the middle of a crisis.
Digital accessibility: applicable since 28 June 2025
Certain products and services must meet European accessibility requirements: e-commerce, consumer banking services, electronic communications, computers and operating systems. Checks cover websites, applications, purchase journeys, forms, documents, authentication methods and support services.
Resilience of critical entities
The Luxembourg Law of 5 May 2026 on the resilience of critical entities complements NIS 2 with an all-hazards approach, covering physical, organisational and environmental risks as well as external dependencies. An entity formally notified as critical carries out a risk assessment within nine months of its notification.
European digital identity, eIDAS 2
Member States must offer European Digital Identity Wallets by the end of 2026. Companies engaged in digital onboarding, KYC, electronic signature or the issuance of credentials should plan for their integration, without collecting more data than necessary.
- Data breach notificationCNPD · Luxembourg
- Directive (EU) 2019/882 on accessibilityEUR-Lex
- European Digital Identity RegulationEuropean Commission
- Official Journal of the Grand Duchy of LuxembourgLegilux
Digital compliance in Luxembourg: 14 documents you should be able to produce
A well-prepared Luxembourg company can quickly present fourteen categories of documents demonstrating its governance, risk management, incident procedures and control of its digital suppliers.
- Security policy approved by the management body
- Mapping of assets, networks, data and critical services
- Risk and dependency analysis
- Register of suppliers and ICT contractual arrangements
- GDPR record of processing activities
- Register of artificial intelligence systems
- Incident management and notification procedure
- Business continuity plan and recovery plan
- Backup policy and restoration test results
- Access and privileged account management policy
- Vulnerability and patch management policy
- Training reports and crisis exercise records
- Contracts and exit plans for critical providers
- Minutes demonstrating effective oversight by management
The fourteenth item is the one most often missing from the files we take over, and the one that exposes executives most directly.
Digital compliance programme in Luxembourg: start with the scope
The first step is to determine which texts apply to the company. This analysis cross-checks the actual business sector, the size of the group, the role played in the digital chain and whether a special regime such as DORA applies.
Launching a technical project before this step means spending without knowing which obligation it answers. A company that deploys a SOC without knowing its qualification ends up with an expensive tool and a documentation file that is still missing on the day of the inspection.
Establish your scope before you spend
Group-level thresholds, linked and partner enterprises included. DORA test first. The outcome is a dated, reasoned note to place in the corporate file.
Related digital compliance resources
Frequently asked questions on digital compliance in Luxembourg
Are all Luxembourg companies covered by NIS 2?
No. NIS 2 targets medium-sized and large entities in the sectors listed in Annexes I and II of the Law of 5 May 2026, together with a small number of digital activities that are in scope regardless of size. A holding company, an SPF (family wealth management company) or a professional services activity is not listed. Thresholds are, however, assessed at group level, which can bring an entity into scope that believed it was outside it.
Does a ManCo or a PSF have to register with the ILR?
No, subject to confirmation of its qualification. Article 1(5) of the NIS 2 Law excludes entities covered by DORA. A management company, an AIF manager or a PSF falls under DORA, supervised by the CSSF, and not under NIS 2, supervised by the ILR. For insurance and reinsurance undertakings, the competent authority is the Commissariat aux Assurances. The exclusion should be documented in writing rather than assumed.
What does an in-scope entity risk if it did not register before 10 July 2026?
Maximum penalties reach EUR 10 million or 2% of worldwide annual turnover for an essential entity, and EUR 7 million or 1.4% for an important entity. These come on top of corrective measures with immediate effect and direct obligations on members of the management body. Because the register is declarative, the absence of registration is liable to be identified during the authority's inspections and cross-checks. Immediate regularisation remains the most favourable course.
How are NIS 2 thresholds calculated within a group?
By consolidating all headcount, turnover and balance sheet total of linked enterprises, those controlled directly or indirectly at more than 50%, then adding the proportionate share of partner enterprises held between 25% and 50%. This is the most frequent gap between a self-assessment made on standalone accounts and the actual qualification.
Has the AI Act been postponed?
Partially. The omnibus regulation of 27 July 2026 postpones the obligations for Annex III high-risk systems to 2 December 2027, and those for AI embedded in regulated products to 2 August 2028. The prohibited practices, the AI literacy obligation, the rules for general-purpose models and the transparency obligations of 2 August 2026 are not postponed.
Does a Luxembourg SaaS vendor fall under the Cyber Resilience Act?
It depends on what is placed on the market. The CRA covers products with digital elements, including remote data processing solutions integrated into a product. A service delivered exclusively online, with no associated product, does not automatically fall within scope and calls for a case-by-case analysis.
Is an IT provider that is not itself in scope really unaffected?
No. A software vendor, an integrator or a managed services firm serving in-scope entities has these requirements passed down to it by contract: security clauses, audit and access rights, notification obligations, subcontracting controls, exit plans. Not having to register in its own right does not exempt it from the contractual compliance imposed through the supply chain.
Where should we start in practice?
With determining the scope of application, before any technical investment. Cross-check the actual business sector, the group's consolidation perimeter and whether a special regime applies. This work produces either a registration to regularise or a reasoned non-applicability note to place in the corporate file. In both cases, it conditions all later spending.
- Author
- Mickaël LOC, licensed accountant (comptable autorisé), seventeen years of Luxembourg accounting-firm practice, consolidation of multi-jurisdictional groups.
- Scope
- Informational content for executives and compliance officers of companies established in Luxembourg.
- Method
- Every date, threshold and penalty ceiling is taken from a primary source cited at the end of the section: Luxembourg authorities, the Official Journal, EUR-Lex, the European Commission.
- Verification
- 3 October 2026 (calendar and statuses). The page is reviewed whenever a regulatory development affects any of the six regimes.
This page is neither legal advice nor an assurance engagement. Financial Services Luxembourg practises as a licensed accountant (comptable autorisé) within the meaning of the Law of 2 September 2011. Interpreting cybersecurity and product security legislation also calls for legal and technical expertise: client files touching on these matters are handled together with legal counsel and a specialist provider.
Amounts, conditions and deadlines that may change should be checked against the official sources cited.