← All resources

NIS2 Luxembourg: manufacturing, who is actually in scope?

Published October 1, 2026 · 7 min read · CyberNovaLabs.io

Luxembourg's NIS 2 Act has applied since 10 May 2026, and self-registration with the ILR was due by 10 July 2026. For a manufacturer, everything hinges on one line of Annex II: five NACE divisions, and nothing else. This guide settles the scope, the reporting clock, the fines and the public funding available.

The short answer

Part of manufacturing is in scope of NIS2 in Luxembourg, but not all of it. The Act of 5 May 2026 on measures to ensure a high level of cybersecurity entered into force on 10 May 2026 and repealed the NIS1 Act[1][2]. Its Annex II line headed Fabrication covers only two things: manufacturers of medical devices and in vitro diagnostic medical devices, and undertakings carrying out an economic activity in divisions 26 to 30 of NACE Rev. 2[1]. Computer, electronic and optical products, electrical equipment, machinery and equipment, motor vehicles and trailers, other transport equipment: you are in. Steel, fabricated metal products, plastics, rubber, glass, paper, food processing: that line does not name you, and the difference changes everything that follows.

Where it does apply, an Annex II entity is an important entity[3]. The obligations are not upcoming: they have been running since May 2026.

NIS2 Luxembourg manufacturing: four questions to settle

The ILR publishes an applicability simulator. The result is explicitly indicative and does not constitute self-registration within the meaning of the Act[5]. Date and archive the answer anyway: it is the first document in your file.

Who supervises you, and who helps during an incident

Luxembourg has split the roles precisely. A manufacturer does not deal with the same bodies as a bank.

RoleBody
Competent authority for Annex I and II sectorsInstitut luxembourgeois de régulation (ILR)[1]
Carve-out: banking and financial market infrastructuresCommission de surveillance du secteur financier[1]
CSIRT for the State, public bodies and critical entitiesHaut-Commissariat à la Protection nationale, acting as GOVCERT.LU[1]
CSIRT for all other cases, so for your plantCIRCL[1]
Single point of contact and major cyber crisis managementHaut-Commissariat à la Protection nationale[1]

Remember the CIRCL line. That is the team which may, at the request of the entity, run a proactive scan of its network and information systems to detect vulnerabilities with a potentially significant impact[1]. The right exists and costs one letter.

Registration was due on 10 July 2026

Self-registration with the competent authority is a legal obligation to be completed within two months of the Act entering into force, that is by 10 July 2026 at the latest[4]. Registrations made before entry into force remain valid, provided the data stays accurate and is kept continuously up to date[4]. One ILR sentence belongs on the boardroom wall: failing to self-register does not release an entity from its obligations under the NIS 2 Act[4]. Not registering has never taken anyone out of scope; it adds a breach.

Reporting an incident: 24 hours, 72 hours, one month

An incident is significant if it has caused or is capable of causing severe operational disruption of services or financial loss for the entity, or if it has affected or is capable of affecting other natural or legal persons by causing considerable material, bodily or non-material damage[1]. The notion is deliberately broad: it covers cyberattacks, but also human error, technical failure and physical events[3]. A production line halted by ransomware meets the definition.

DeadlineWhat you send the ILR
24 hours after becoming awareEarly warning, stating where applicable whether the incident is suspected of being caused by unlawful or malicious acts and whether cross-border impact is possible[1]
72 hoursIncident notification: update, initial assessment of severity and impact, indicators of compromise where available[1]
On request of the CSIRT or the authorityIntermediate report on relevant status updates[1]
One month after the incident notificationFinal report: detailed description, threat type or likely root cause, mitigation measures applied, cross-border impact[1]

The clock starts when you become aware of the incident, not when you fix it. If the incident is still ongoing at the time of the final report, you provide a progress report and then a final report within one month of handling the incident[1]. In return, the authority must respond where possible within 24 hours of the early warning, with initial feedback and, at your request, operational guidance or advice[1].

The ten measures, and one nuance in your favour

The Act requires an all-hazards approach comprising at least ten families of measures[1]: risk analysis and information system security policies; incident handling; business continuity, backups, disaster recovery and crisis management; supply chain security, including aspects of relationships with direct suppliers and service providers; security in acquisition, development and maintenance, including vulnerability handling and disclosure; policies to assess the effectiveness of the measures; basic cyber hygiene practices and security training; cryptography and, where appropriate, encryption; human resources security, access control policies and asset management; multi-factor or continuous authentication and secured communications.

The nuance: measures taken by essential entities must be notified to the competent authority, in a format and within a deadline it determines[1]. As manufacturing sits in Annex II, that notification of measures is not on you — which changes nothing about having to implement the measures and evidence them in a supervisory exercise. For drafting, the ILR publishes its own guidance, including six fundamental security measures and guidelines addressed to management bodies[7].

Fines, daily penalties and director liability

For a breach of Article 12 or Article 14(1) to (4), the maximum administrative fine is 7,000,000 euro or 1.4 % of the total worldwide annual turnover of the preceding financial year of the undertaking to which the important entity belongs, whichever is higher. For an essential entity the ceiling is 10,000,000 euro or 2 %[1]. The authority may also attach a daily penalty payment of up to 1,250 euro per day, capped at 25,000 euro in total for the breach established[1].

The most structural change is not financial. Management bodies approve the cybersecurity risk-management measures, supervise their implementation and may be held liable for the entity's breach of Article 12. Their members must follow regular training, and the entity must offer similar training to its staff[1]. A management committee that has never put cybersecurity on its agenda cannot prove it approved anything.

The Luxembourg funding few manufacturers claim

The Ministry of the Economy's SME Packages – Cybersecurity scheme funds 70 % of eligible costs for implementing a cybersecurity tool, for a project worth between 3,000 and 25,000 euro excluding VAT[6]. Conditions: holding a business permit from the Ministry of the Economy, meeting the SME criteria, and having your registered office in Luxembourg[6]. The route is mapped out: a mandatory pre-analysis by the Luxembourg House of Cybersecurity, the application prepared with the House of Entrepreneurship at the Chamber of Commerce — or the Service Cybersecurity eHandwierk at the Chamber of Skilled Trades for craft businesses — choice of provider, validation by the Ministry, then reimbursement after the package is in place[6]. The scheme explicitly mentions support towards NIS2 compliance[6].

Grant = 70 % × eligible costs, for a project of 3,000 to 25,000 euro excluding VAT, so a grant between 2,100 and 17,500 euro[6]. Figures computed from the published bounds: confirm your eligibility with the bodies named before committing anything.

Before spending a euro, the free and anonymous Fit4Cybersecurity self-assessment from SECURITYMADEIN.LU gives you a first picture of where you stand[8].

The first five actions

  1. Settle the scope in writing. The NACE code actually operated, headcount and accounts consolidated at group level, a dated result from the ILR simulator, and a conclusion signed by management. A two-page note beats a conviction.
  2. Register with the ILR if you have not. The 10 July 2026 deadline has passed; the obligation has not. Appoint someone to keep the contact details current, IP ranges included.
  3. Write the 24 h / 72 h / one month procedure. Who classifies an incident as significant, who signs the early warning, where the ILR and CIRCL contact details live, which template you send. Run it once as a drill, at night if your plant runs at night.
  4. Cover the shop floor, not just the offices. PLCs, supervision, maintenance workstations, remote access held by machine suppliers, update USB sticks. Supply chain and direct-supplier security is one of the ten required families of measures[1].
  5. Have the management committee approve and train, with dated evidence, then start the Luxembourg House of Cybersecurity pre-analysis so the SME Package file is open before you buy anything[6].

At CyberNovaLabs.io

CyberNovaLabs.io runs a free NIS2 check that gives a first read on your situation in minutes, plus a page dedicated to NIS2 for manufacturing in Luxembourg.

Two further reads: our analysis of the Cyber Resilience Act and what it imposes on manufacturers, which targets your connected products where NIS2 targets your organisation, and the guide to NIS2 in the Netherlands for transport and logistics, useful if your sites cross the border. If your commercial development also runs through the Grand Duchy, see our page on B2B appointment setting in Luxembourg.

Want a view on your scope, your reporting procedure or your funding file? Write to us and we will look at your specific case. For the mandatory training of directors and teams, tell us about your training needs.

Sources

  1. Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité (Mémorial A n° 225)
  2. ILR — La loi NIS 2
  3. gouvernement.lu — Cybersécurité : l'ILR présente la nouvelle loi NIS 2 (06/07/2026)
  4. ILR — Auto-enregistrement NIS 2
  5. ILR — Simulateur NIS 2
  6. Guichet.lu — SME Packages – Cybersecurity
  7. ILR — 6 mesures de sécurité fondamentales (publications NIS 2)
  8. SECURITYMADEIN.LU — Fit4Cybersecurity
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked