NIS2 Luxembourg: is your online shop in scope?
Luxembourg brought NIS2 into national law with the Law of 5 May 2026. An online shop selling its own products is, in most cases, not an entity in scope. But three situations put it in scope, and a fourth catches it through the supply chain. Here are the tests, in order.
The short answer
If your Luxembourg online shop sells your own products, you are most likely not an entity in scope of the Law of 5 May 2026 on measures to ensure a high level of cybersecurity[1], the act that transposes NIS2 in the Grand Duchy and has been in force since 10 May 2026[1][2]. Online retail appears in neither Annex I nor Annex II of the directive. What does appear is the online marketplace: a service that lets third-party sellers offer their goods and conclude sales through you[4][5].
Two caveats change everything. First, many Luxembourg shops have become hybrid: they opened their catalogue to third-party sellers without treating it as a change of regulatory status. Second, even out of scope you feel NIS2 by ricochet: your business customers, your carrier, your host and your payment provider often are in scope, and they will tell you in writing. The question is not whether NIS2 reaches you, but through which door.
One figure to size the market: according to Eurostat, 12.2 % of Luxembourg enterprises reported e-sales in 2023, down from 13.4 % in 2022[8]. The pool affected through door one is narrow. The pool affected through door four is close to universal.
Are you in scope? Four questions, in this order
Do not start with company size. Start with the activity. Size only settles the matter once the activity is recognised.
- Do you host third-party sellers? If independent merchants list their offers on your site and close the sale through you, you carry on an online marketplace activity. The notion sits in Article 6 of the directive and is clarified by the definition of online intermediation services in Regulation 2019/1150[4][5]. Selling your own stock, however large the volume, does not qualify.
- Do you carry on another listed activity? Many e-commerce operators do more than sell: hosting or cloud for third parties, running a data centre, DNS services, managed IT services, in-house postal or parcel delivery, food production. Each of these has its own line in Annex I or II[4].
- What is your size? The threshold is the medium-enterprise one: at least 50 staff, or more than EUR 10 million annual turnover, or more than EUR 10 million balance sheet total[4]. The three criteria are not cumulative: one is enough. A marketplace with 20 people and EUR 4 million therefore stays, in principle, outside the general regime.
- Are you an authorised financial player? If you are yourself a payment institution or an e-money institution, the competent authority is not the ILR but the CSSF, which supervises the banking sector and financial market infrastructures[2][6]. Accepting card payments through a third-party provider does not make you a financial player.
If the answer to questions 1 and 2 is no, stop there: you have no registration duty. Go straight to the supply-chain section, which is your real subject.
What the Luxembourg law requires from entities in scope
In Luxembourg the supervisory authority for most sectors is the Institut Luxembourgeois de Regulation (ILR)[2][6]. An online marketplace falls under Annex II: it is an important entity, subject to ex post supervision, triggered by a complaint or an indication of non-compliance rather than by a scheduled inspection.
| Obligation | Content | Deadline |
|---|---|---|
| Registration | Entity self-registration with the competent authority, through the ILR online desk | Two months after entry into force, that is 10 July 2026; any change of information within two weeks[3] |
| Risk-management measures | Risk analysis, incident handling, continuity and backups, supply-chain security, vulnerability handling, multi-factor authentication, cryptography, access policies, training[4] | Ongoing |
| Early warning | First notice to the authority about a significant incident | 24 hours[1][4] |
| Incident notification | Initial assessment, severity, impact, indicators of compromise | 72 hours[1][4] |
| Final report | Detailed description, root cause, corrective measures | One month after the notification[1][4] |
| Management accountability | Approval of the measures by the management body and training of senior managers | Ongoing |
Maximum administrative fines are EUR 10 million or 2 % of worldwide annual turnover for an essential entity, and EUR 7 million or 1.4 % for an important entity, whichever is higher[1][2]. For an Annex II online marketplace, the second ceiling applies.
The Luxembourg reflex worth knowing. Before signing a compliance quote, look at the Fit 4 Digital programme: the assessment is invoiced at EUR 5,000 and may be covered by a grant of the same amount, subject to eligibility. The application must be filed before you accept a binding quote, and implementing the recommendations is a separate application[7]. Filing after signature forfeits the grant.
The risks that actually target an online shop
Compliance is one thing, incidents another. In e-commerce four scenarios keep coming back, none specific to Luxembourg, but all handled there by the same contacts: CIRCL for private-sector incident response and CASES for prevention and awareness[10][11].
- The CMS extension. A shop on a CMS typically carries dozens of third-party modules. Each one is a code-execution path you do not maintain. It is the leading cause of merchant-site compromise, and it is exactly what NIS2 calls supply-chain security.
- Payment page skimming. A script injected into the checkout copies card data as it is typed, breaking nothing. The symptom is not an outage: it is a call from your payment provider.
- Credential stuffing. Customer accounts are tested at scale with passwords leaked elsewhere. Multi-factor authentication on admin accounts is the minimum; rate limiting on customer logins is the complement.
- Bank-details fraud. It travels through your mailbox, not your site. A domain without properly published SPF, DKIM and DMARC makes it easier to impersonate your own address to your customers.
On personal data, the Luxembourg authority is the CNPD[9]. An online shop processes customer accounts, delivery addresses, purchase history and trackers: those duties exist independently of NIS2 and do not vanish if you conclude you are out of scope.
Out of scope, not off the hook: the supply chain
This is the door through which NIS2 reaches almost every Luxembourg shop. Entities in scope must manage the security of their suppliers[4]. In practice three things happen to you without asking.
First, your business customers in scope send you a security questionnaire, sometimes long, often badly calibrated for an SME. Answering fast and accurately becomes a commercial argument. We set out the method in our guide on the sectors that believe they are out of scope and still receive security questionnaires.
Second, your host, cloud provider and carrier often are in scope: cloud computing, data centres and postal and courier services each have their own line in the annexes[4]. Their new contractual requirements flow down to you.
Third, if you supply goods or services to an industrial entity in scope, you enter its supplier-control perimeter. The reasoning is the same as in our guide NIS2 Luxembourg for manufacturing and production, which explains how an entity in scope passes its obligations down. For the sector-by-sector picture in the Grand Duchy, the NIS2 in Luxembourg page sums up authorities and deadlines.
The first five actions
- Settle question 1 in writing. A one-page note: do we host third-party sellers, yes or no, and since when. Dated and signed by management. That is the document you will produce if the ILR asks.
- If the answer is yes and you exceed a size threshold, register. Self-registration goes through the ILR online desk, and any change must be reported within two weeks[3].
- Put multi-factor authentication on admin access to the site, the CMS, the payment back office and your domain registrar. It is the measure that cuts the most scenarios for the least effort.
- Inventory your modules and technical suppliers on one sheet: name, version, who updates it, where the backups are, how long a restore takes. Test one real restore.
- Check SPF, DKIM and DMARC on your domain and write a one-page incident procedure carrying the 24-hour, 72-hour and one-month deadlines, even if you believe you are out of scope. On the day of the incident, nobody reads the directive.
At CyberNovaLabs.io
We work in the Netherlands, Belgium, France and Luxembourg, and the question we hear most in e-commerce is not how do we comply but am I in scope. Start with the free NIS2 check: it places you in minutes by activity and by size. If customers are sending you questionnaires, the supplier security questionnaire gives you the expected answer structure, and the email security check tests SPF, DKIM and DMARC on your domain.
When the shop itself has to change, we build and take over bespoke selling platforms: see custom software development. Our work is quoted per project, with no minimum term.
Describe your online shop and we will tell you in writing whether NIS2 applies to you.
Sources
- Loi du 5 mai 2026 concernant des mesures destinees a assurer un niveau eleve de cybersecurite (Legilux)
- ILR - The NIS 2 Act
- ILR - Frequently asked questions about NIS2 (FAQ)
- Directive (UE) 2022/2555 (NIS2)
- Reglement (UE) 2019/1150 (services d'intermediation en ligne, P2B)
- Gouvernement luxembourgeois - Cybersecurite : l'ILR presente la nouvelle loi NIS 2
- Guichet.lu - Programme Fit 4 Digital
- Eurostat - E-commerce statistics
- CNPD - Commission nationale pour la protection des donnees
- CASES Luxembourg
- CIRCL - Computer Incident Response Center Luxembourg
Qualified meetings, no lock-in.
Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.
Read next
Data breach at FWB: three weeks before it was confirmed (05/10)
Flagged from outside in mid-September, confirmed on 5 October 2026: the EAD-online.be data breach shows where the GDPR's 72 hours are really lost, and why the weak link is so often a supplier.
Read the article →October 7, 2026 · 7 min readNIS2 France: are hotels and tourism in scope?
Tourist accommodation is absent from the NIS2 annexes, and France's transposition was still in parliament on 7 October 2026. Yet in May 2026 three French tourism operators lost their reservation databases within 72 hours. Here is what actually applies to you.
Read the article →October 6, 2026 · 7 min readDGFiP breach: stolen logins, no MFA, no detection (29/09/2026)
On 29 September 2026 France's cyber agency ANSSI published its incident report on the cyberattacks against the tax administration. No rare technique: passwords stolen from personal computers, a second factor sent by email, sensitive applications reachable without segmentation, and a portal nobody was watching. All four links exist in most SMEs.
Read the article →