Home / Cybersecurity / NIS2 in Luxembourg / Cloud and data centres

Luxembourg · Cloud and data centres · Annex I

NIS2 for cloud and data-centre providers in Luxembourg

Cloud and data centres is listed in Annex I of the NIS2 directive. Large companies are essential entities; medium companies are important entities. In Luxembourg, the rules come from the Law of 5 May 2026 transposing NIS2, applicable since 10 May 2026; the authority is the Institut Luxembourgeois de Régulation (ILR).

→ Talk to a cybersecurity advisor

Who is covered in this sector

Companies that only use cloud services are not in scope as cloud providers.

The threats we see most in cloud and data centres

Five priority measures

  1. 01 Customer-facing incident communication within the legal deadlines
  2. 02 Privileged-access management and hardware keys for administrators
  3. 03 Configuration baselines and continuous misconfiguration checks
  4. 04 Redundancy and recovery tests with documented results
  5. 05 Register in the country of your head office (NIS2 rule for cloud and data-centre providers)

What Luxembourg requires

Registration. Self-register with the ILR. The window closed on 10 July 2026 — late registrants should register now.

Significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month. Fines set by the directive: up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities (whichever is higher).

Tools and guides

Cloud and data centres in other countries

Other sectors in Luxembourg

Frequently asked questions

Is my cloud and data-centre provider company in scope of NIS2 in Luxembourg?

Cloud and data centres is an Annex I sector. Large companies are essential entities; medium companies are important entities. Small companies are generally out of scope unless designated. Our NIS2 check gives you the answer in two minutes.

What should we do first?

Register if you are in scope, name an owner, run a short risk assessment, and fix the basics: MFA, tested backups, patching, incident routine.

We are a supplier to this sector. Does it affect us?

Yes, indirectly: your customers must secure their supply chain and will ask you for evidence. See our supplier questionnaire guide.

Sources

Last checked: 28 September 2026. This page is general information, not legal advice.

Free first call · English

Cloud and data centres in Luxembourg: a first view, free

Tell us where you stand. An English-speaking advisor replies within one business day with a first view and, if useful, a written quote. No commitment.

  • Reply within one business day
  • Written scope and price before any work
  • Netherlands · Belgium · Luxembourg

Prefer email? Write to contact@cybernovalabs.io

→ Free cybersecurity call