Home / Cybersecurity / NIS2 in Luxembourg / Healthcare
NIS2 for healthcare providers in Luxembourg
Healthcare is listed in Annex I of the NIS2 directive. Large companies are essential entities; medium companies are important entities. In Luxembourg, the rules come from the Law of 5 May 2026 transposing NIS2, applicable since 10 May 2026; the authority is the Institut Luxembourgeois de Régulation (ILR).
→ Talk to a cybersecurity advisor
Who is covered in this sector
- Hospitals, clinics and other healthcare providers
- EU reference laboratories
- Research and development of medicinal products
- Manufacturers of basic pharmaceutical products and preparations
- Manufacturers of devices considered critical during a public-health emergency
Very small practices below the medium-size threshold are usually out of scope, unless the national authority designates them.
The threats we see most in healthcare
- Ransomware on patient records and scheduling
- Data theft and extortion on medical data
- Insecure connected medical devices
- Compromised accounts at software and lab suppliers
Five priority measures
- 01 MFA on email, remote access and the patient-record system
- 02 Offline, tested backups of clinical systems
- 03 Network segmentation for medical devices
- 04 A register of suppliers with access to patient data
- 05 Downtime procedures rehearsed with care teams
What Luxembourg requires
- The law of 5 May 2026 was published in the Mémorial A (No. 225) and has applied since 10 May 2026.
- The competent authority is the ILR. Self-registration was due within two months, i.e. by 10 July 2026.
- Entities must adopt a cyber-risk management policy covering the ten minimum measures of the directive (risk analysis, incident handling, business continuity, supply-chain security, cryptography…).
- Incident reporting: early warning within 24 hours, notification within 72 hours, final report within one month.
Registration. Self-register with the ILR. The window closed on 10 July 2026 — late registrants should register now.
Significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month. Fines set by the directive: up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities (whichever is higher).
Tools and guides
Healthcare in other countries
Other sectors in Luxembourg
Frequently asked questions
Is my healthcare provider company in scope of NIS2 in Luxembourg?
Healthcare is an Annex I sector. Large companies are essential entities; medium companies are important entities. Small companies are generally out of scope unless designated. Our NIS2 check gives you the answer in two minutes.
What should we do first?
Register if you are in scope, name an owner, run a short risk assessment, and fix the basics: MFA, tested backups, patching, incident routine.
We are a supplier to this sector. Does it affect us?
Yes, indirectly: your customers must secure their supply chain and will ask you for evidence. See our supplier questionnaire guide.
Sources
- Guichet.lu / ILR — NIS2
- PwC Luxembourg — NIS2 in Luxembourg
- Paperjam — Up to 2,000 entities face NIS2 deadline
Last checked: 28 September 2026. This page is general information, not legal advice.
Healthcare in Luxembourg: a first view, free
Tell us where you stand. An English-speaking advisor replies within one business day with a first view and, if useful, a written quote. No commitment.
- Reply within one business day
- Written scope and price before any work
- Netherlands · Belgium · Luxembourg