Skip to content
Cyvalent
Back to resources

The EU's Cybersecurity and Resilience Rulebook, in Plain English

Published

The answer depends on sector, size, designation, activity, product and operator role. The Luxembourg NIS 2 Act uses sector, size and entity-type triggers; CER requires formal designation as a critical entity. DORA follows financial-entity status and, for suppliers, contractual or critical-provider status. The CRA follows products with digital elements and economic-operator roles. The AI Act follows system type, risk category and operator role. The EU Space Programme Regulation matters primarily to organisations participating in, operating or supplying security-relevant programme infrastructure or services.

This article gives you a first map. It is not a legal opinion. It is a plain-language guide to what each instrument is for, why it exists, and which question to ask next.

How the main EU cyber rules compare

How the main EU cyber instruments compare
RegulationTriggerRegulatesFirst questionKey date
NIS2Sector + size + roleOrganisation / serviceAre we in a sector listed in the Luxembourg NIS 2 Act, and do the size, entity-type or special-case rules bring us into scope?Luxembourg Act in force since 10 May 2026; initial self-registration was due by 10 July 2026
DORADORA financial entity; or designation as a critical ICT third-party providerFinancial operational resilienceAre we a DORA financial entity, or do we supply ICT services to one?Applies since 17 Jan 2025
CRAProduct with digital elementsProduct / economic operatorDo we make available a product with digital elements on the EU market?Rules on notifying and assessing conformity-assessment bodies apply from 11 June 2026; Article 14 reporting duties from 11 September 2026; most provisions from 11 December 2027
AI ActAI-system risk and roleAI systemsDo we provide, deploy, import or distribute an AI system—or provide a GPAI model—and which risk category and operator role apply?Phased application since 2025. A provisional EU political agreement would move the main high-risk dates to 2 December 2027 and 2 August 2028; verify the final amending regulation
CERCritical-entity designationPhysical / operational resilienceCould we be designated critical?Luxembourg Law of 5 May 2026; entity-level duties follow formal designation and notification

Why There Are Suddenly So Many Rules

The EU's approach has moved from largely voluntary cyber guidance toward mandatory, supervised obligations for organisations, products, and critical services. The shift follows years of serious incidents and recurring threat patterns documented by ENISA. Events such as WannaCry, NotPetya, SolarWinds, Colonial Pipeline and Kaseya helped move cyber resilience from voluntary guidance towards supervised, board-level duties 15 16.

The result is not one single cyber law. It is a stack of instruments that answer different questions: is the organisation in a critical sector, is it a financial entity, does it place a connected software or hardware product on the EU market, does it develop or deploy high-risk AI, or is it identified as critical to societal resilience?

NIS2: Sector-Based Cybersecurity Governance

In Luxembourg, NIS2 is implemented through the Law of 5 May 2026 concerning measures intended to ensure a high level of cybersecurity—the Luxembourg NIS 2 Act 2. It establishes the essential- and important-entity categories, management-body responsibilities, cybersecurity risk-management measures and significant-incident reporting duties. The main operational provisions appear in Articles 12 to 14 of the Luxembourg Act. The underlying EU instrument is Directive (EU) 2022/2555 1.

Scope starts with the sectors in Annexes I and II of the Luxembourg Act, but sector alone is not enough. Most entities are caught only if they are at least medium-sized—generally 50 or more employees, or turnover or balance-sheet figures above the small-enterprise thresholds—and the calculation can include linked and partner enterprises. Certain entity types and criticality cases are covered regardless of size 3.

The Luxembourg NIS 2 Act has applied since 10 May 2026. ILR is the competent cybersecurity authority for most sectors. CSSF is competent for banking and financial-market infrastructure, and for digital-infrastructure and B2B ICT-service-management activities that fall under CSSF supervision. HCPN is the national single point of contact and the authority responsible for major cyber incidents and cyber-crisis management 2 3.

The initial self-registration deadline was 10 July 2026. An in-scope entity that missed it should register without delay through the ILR form and contact its competent authority if it needs instructions; missing the deadline does not remove the entity's other obligations 3.

For entities supervised by ILR, a significant incident is reported through SERIMA: an early warning within 24 hours of becoming aware of it, a fuller notification within 72 hours, and a final report within one month of the 72-hour notification. CSSF-supervised entities should follow the CSSF reporting route applicable to them, including DORA where relevant 3 6.

Who should investigate further: organisations that carry out an activity listed in Annex I or II of the Luxembourg NIS 2 Act—including Annex I activities such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space; and Annex II activities such as postal services, waste management, manufacture of critical products, food production, digital providers, and research organisations. Sector is only the first screen; apply the Luxembourg size, group and special-case rules before reaching a conclusion 2 3.

DORA: Digital Operational Resilience for Financial Entities

DORA is an EU regulation, not a directive, so it applies directly across the EU. It governs digital operational resilience for financial entities and their ICT third-party risk management, including governance obligations, incident management, testing, and third-party ICT risk rules in Regulation (EU) 2022/2554 Articles 5, 17-30, and 64 4.

DORA has applied directly since 17 January 2025. Luxembourg's Law of 1 July 2024 transposed Directive (EU) 2022/2556, designated CSSF and CAA as competent authorities for their respective supervised entities, and established their national supervisory and enforcement powers. For CSSF-supervised entities, Circular 25/882 addresses the use of ICT third-party services, while Circular 25/883 amended the existing outsourcing framework in Circular 22/806 5 6.

A financial entity may still fall within the wider Luxembourg NIS 2 framework, but DORA is treated as the sector-specific EU act for its ICT risk-management and incident-reporting obligations. Where DORA supplies equivalent rules, the corresponding NIS2 provisions—and their related supervision and enforcement—do not apply. The remaining national preparedness and crisis-cooperation framework can still be relevant 4 7.

Who should investigate further: banks, insurers, investment firms, payment institutions, fund managers, and crypto-asset service providers. ICT providers to financial entities should expect DORA requirements to flow into contracts, including security, incident support, audit, subcontracting and exit provisions. That does not automatically make every supplier a directly supervised DORA entity; direct EU oversight applies to ICT providers formally designated as critical. DORA has applied since 17 January 2025 under Article 64 4.

Cyber Resilience Act: Product Cybersecurity

The Cyber Resilience Act sets cybersecurity requirements for products with digital elements placed on the EU market. It applies to the product and economic-operator role, not to a sector alone: Article 2 sets the scope and connectivity criterion, Article 3 defines products with digital elements and economic operators, Annex I sets essential cybersecurity and vulnerability-handling requirements, and Annexes III and IV identify important and critical product classes 8.

Because the CRA is an EU regulation, Luxembourg does not transpose its core product obligations. It must, however, designate a notifying authority for conformity-assessment bodies and one or more market-surveillance authorities. As of 15 July 2026, no official Luxembourg designation had been identified in the sources reviewed. Check Legilux and official ILNAS or Ministry of the Economy updates before naming an authority 8.

Who should investigate further: manufacturers, importers and distributors that make software, connected hardware, embedded firmware or another product with digital elements available on the EU market. Scope and exclusions—including the rules for free and open-source software—must be checked against the product's distribution and commercial context. Rules on notifying and assessing conformity-assessment bodies apply from 11 June 2026, reporting duties under Article 14 apply from 11 September 2026, and the regulation applies generally from 11 December 2027 8.

EU AI Act: Risk-Tiered AI Governance

The EU AI Act regulates AI systems by risk tier and entered into force on 1 August 2024. Article 6 creates two main high-risk routes: AI used as a safety component of, or itself constituting, a product governed by legislation listed in Annex I; and stand-alone uses listed in Annex III, such as certain systems used in employment, education, essential services or critical infrastructure 9.

Under the AI Act as currently published, many provisions apply from 2 August 2026, after prohibitions and AI-literacy duties from 2 February 2025 and governance and GPAI obligations from 2 August 2025. A provisional political agreement reached on 7 May 2026 would move the main Annex III high-risk rules to 2 December 2027 and the product-related high-risk rules to 2 August 2028. Those later dates should be treated as provisional until the amending regulation is formally adopted and published 9 10.

For Luxembourg, Bill 8476 remains in committee following the Council of State opinion published on 10 July 2026. As drafted, it would make CNPD the default market-surveillance authority and national single point of contact, supported by sectoral authorities including CSSF, CAA, ILNAS, ILR, ALMPS, ALIA and the judicial supervisory authority. These roles remain proposed until the bill is enacted 11.

Who should investigate further: organisations acting as provider, deployer, importer, distributor, product manufacturer or GPAI-model provider—especially where AI is used in HR, creditworthiness, biometrics, critical infrastructure, education, law enforcement, migration or access to essential services. Start with your operator role—provider, deployer, importer, distributor, product manufacturer or GPAI-model provider—and then assess the system under Article 6, Annex I and Annex III. High-risk classification is only one part of the Act: prohibited practices, AI literacy, transparency and GPAI rules can apply independently 9.

CER: Critical Entities Resilience

CER is the resilience counterpart to NIS2. NIS2 focuses on cybersecurity; CER focuses on broader physical, operational, and supply-chain resilience for entities identified as critical under national rules. The directive's sectors are listed in its Annex 12.

Luxembourg transposed CER through the Law of 5 May 2026 on the resilience of critical entities. HCPN is the competent authority for most sectors and the national single point of contact. CSSF is competent for banking, financial-market infrastructure and supervised digital-infrastructure activities. An organisation does not become a critical entity merely because it operates in a listed sector: the competent authority must formally identify and designate it 13.

Once notified of its designation, a critical entity generally has nine months to complete its critical-entity risk assessment, while the main resilience duties apply after ten months. The designation notice and instructions from HCPN or CSSF are therefore the starting point for the entity-level timetable 13.

Who should investigate further: organisations providing essential services in a listed Luxembourg sector should assess their potential exposure and prepare the information needed for engagement with HCPN or CSSF. Formal CER duties are triggered by designation, not by sector membership alone 12 13.

EU Space Programme: specialised security context

The EU Space Programme Regulation is not a general cybersecurity law for Luxembourg space companies. It becomes relevant where an organisation participates in the EU programme, operates programme infrastructure, or supplies security-relevant components or services under the applicable programme and contractual arrangements. Ordinary downstream use of Galileo or Copernicus data does not, by itself, establish the same kind of compliance trigger as NIS2, DORA or the CRA 14.

Who should investigate further: Luxembourg space-sector companies that participate in, operate or supply EU programme infrastructure or security-relevant services connected to Galileo, Copernicus or GOVSATCOM 14.

In short

  • These regimes can overlap, but they do not always apply cumulatively. For DORA financial entities, DORA displaces the equivalent NIS2 ICT risk-management and incident-reporting provisions.
  • The trigger matters: sector, financial status, product role, AI-system role, or critical-entity designation.
  • Start with scoping before building a compliance roadmap.

The four questions that decide whether you should act now

Not sure where to start? Ask four questions:

  1. Are we within a sector and entity category covered by the Luxembourg NIS 2 Act, or have we been designated—or could we be designated—as a critical entity under the Luxembourg CER law?
  2. Are we a regulated financial entity, or an ICT provider to one?
  3. Do we make available software, connected hardware, embedded firmware, or another product with digital elements on the EU market?
  4. Do we provide, deploy, import, distribute or integrate AI systems or GPAI models, and what risk category applies?

If the answer to any question is yes, start with a scoping assessment before building a roadmap: map each legal entity against five triggers — sector, financial status, product role, AI-system role, and critical-entity designation — then, for each trigger, record the legal entity, the applicable Luxembourg or EU instrument, the competent Luxembourg authority, the reporting route and the next deadline.

What Cyvalent Does

Cyvalent helps Luxembourg and EU organisations turn this map into an evidence-backed obligations register, management-ready decisions, and a practical control roadmap. Cyvalent 360 Cyber Services / CISOaaS provides expert operating capacity; Cyvalent RGX maps obligations to controls and tracks posture across overlapping regimes.

Both offerings can be used independently or together. The correct starting point depends on whether the immediate gap is human operating capacity, structured compliance tracking, or both.

Not sure which rules apply to you?

Cyvalent helps Luxembourg and EU organisations map which obligations apply before over-investing in the wrong compliance work — through founder-led Cyvalent 360 Cyber Services / CISOaaS and the Cyvalent RGX platform.

Frequently asked questions

Which EU cybersecurity regulation applies to my business?

It depends on the sector, size, designation, activity, product and operator role of each legal entity. The Luxembourg NIS 2 Act uses sector, size and entity-type triggers, and CER requires formal designation as a critical entity; DORA follows financial-entity status and, for suppliers, contractual or critical-provider status; the Cyber Resilience Act follows products with digital elements and economic-operator roles; and the AI Act follows system type, risk category and operator role. Working through the four questions — sector, financial-entity status, products with digital elements, and AI systems — gives you a first map of which instruments to investigate.

What is the difference between NIS2 and DORA?

NIS2 is an EU directive setting a high common level of cybersecurity for essential and important entities across listed sectors, with governance duties, cybersecurity risk-management measures, and incident-reporting duties. DORA is an EU regulation that applies directly across the Union and governs digital operational resilience for financial entities and their ICT third-party risk. A financial entity can fall within both frameworks, but DORA is treated as the sector-specific EU act for its ICT risk-management and incident-reporting obligations: where DORA supplies equivalent rules, the corresponding NIS2 provisions do not apply.

When did DORA come into effect?

DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025 under its Article 64. Because it is a regulation rather than a directive, it applies directly across the EU without national transposition of the core obligations.

Does the EU Cyber Resilience Act apply to my product?

The Cyber Resilience Act sets cybersecurity requirements for products with digital elements placed on the EU market. Scope turns on the product and connectivity criterion and on your economic-operator role — manufacturer, importer, or distributor — rather than on your sector alone. Reporting duties apply from 11 September 2026 and the regulation applies fully from 11 December 2027.

What are the NIS2 deadlines for organisations in Luxembourg?

Luxembourg transposed NIS2 through the Act of 5 May 2026, in force from 10 May 2026, and the initial self-registration deadline was 10 July 2026. ILR is the competent authority for most sectors; CSSF is competent for banking, financial-market infrastructure and certain supervised digital and ICT activities; and HCPN is the national single point of contact for major cyber incidents. Entities that missed the initial registration deadline should use the ILR registration form without delay and confirm the appropriate route with ILR or CSSF, depending on the activity concerned.

Can one organisation be subject to more than one EU cyber rule?

Yes. The instruments regulate different objects — organisations, services, products, and AI systems — so they stack. A financial entity can be under DORA, in a NIS2 sector, and dependent on CRA-regulated products at the same time; a manufacturer can be under NIS2 for its sector and the CRA for its connected product line. For financial entities specifically, DORA is treated as the sector-specific act for ICT risk-management and incident reporting, so where it provides equivalent rules the corresponding NIS2 provisions do not apply.

Sources & References

Last checked:

EU legislation

  1. [1] European Parliament & Council. Directive (EU) 2022/2555 (NIS2) — Art. 2 & Annexes I-II (scope/sectors), Art. 3 (essential vs important), Arts. 20-21 (governance & risk measures), Art. 23 (incident reporting), Art. 41 (transposition deadline 17 Oct 2024). Status/date: in force; adopted 14 Dec 2022. Source: EUR-Lex. https://eur-lex.europa.eu/eli/dir/2022/2555/oj

  2. [4] European Parliament & Council. Regulation (EU) 2022/2554 (DORA) — Art. 5 (governance/management body), Arts. 17-23 (incident management), Arts. 24-27 (testing/TLPT), Arts. 28-30 (third-party risk; Art. 28(3) Register of Information), Art. 64 (applies 17 Jan 2025). Status/date: applicable from 17 Jan 2025. Source: EUR-Lex. https://eur-lex.europa.eu/eli/reg/2022/2554/oj

  3. [8] European Parliament & Council. Regulation (EU) 2024/2847 (Cyber Resilience Act) — Art. 2 (scope/connectivity), Art. 3 (definitions/roles), Art. 14 (reporting from 11 Sep 2026), Annex I (essential requirements and vulnerability handling), Annexes III-IV (product classes); conformity-assessment-body provisions from 11 Jun 2026; full application 11 Dec 2027. Status/date: in force 10 Dec 2024; phased application. Source: EUR-Lex. https://eur-lex.europa.eu/eli/reg/2024/2847/oj

  4. [9] European Parliament & Council. Regulation (EU) 2024/1689 (AI Act) — Art. 6 and Annexes I & III (high-risk routes); phased application. Status/date: in force since 1 August 2024; prohibitions and AI literacy from 2 February 2025; GPAI/governance from 2 August 2025; many rules from 2 August 2026. Source: EUR-Lex. https://eur-lex.europa.eu/eli/reg/2024/1689/oj

  5. [12] European Parliament & Council. Directive (EU) 2022/2557 (CER) — Annex (sectors); transposition deadline 17 Oct 2024. Status/date: in force; adopted 14 Dec 2022. Source: EUR-Lex. https://eur-lex.europa.eu/eli/dir/2022/2557/oj

  6. [14] European Parliament & Council. Regulation (EU) 2021/696 (EU Space Programme) — Galileo, Copernicus, GOVSATCOM security context. Status/date: in force. Source: EUR-Lex. https://eur-lex.europa.eu/eli/reg/2021/696/oj

Luxembourg authorities

  1. [2] Grand-Duché de Luxembourg. Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité (Mémorial A No 225, published 6 May 2026) — Luxembourg NIS2 transposition; in force 10 May 2026; ILR competent for most sectors, CSSF for banking, financial-market infrastructure, and supervised digital-infrastructure and B2B ICT-service-management activities (Art. 3); HCPN national single point of contact. Status/date: in force 10 May 2026; initial self-registration deadline passed on 10 July 2026. Source: Legilux. https://legilux.public.lu/eli/etat/leg/loi/2026/05/05/a225/jo

  2. [3] ILR. NIS2 — scope, self-registration, security measures, incident notification (SERIMA) — Luxembourg NIS2 portal: sector guidance, self-registration form, security measures, and incident notification. Status/date: accessed July 2026. Source: ILR. https://www.ilr.lu/en/sectors/niss/nis-2/, https://www.ilr.lu/en/sectors/niss/self-registration/ and https://www.ilr.lu/en/sectors/niss/incident-notification/

  3. [5] Luxembourg / CSSF. Loi du 1er juillet 2024 implementing DORA / transposing Directive (EU) 2022/2556; Circular CSSF 25/882; Circular CSSF 25/883 amending Circular CSSF 22/806 — CSSF and CAA competent authorities; ICT third-party service requirements for DORA entities. Status/date: law of 1 July 2024; CSSF circulars published 2025. Source: CSSF. https://www.cssf.lu/en/regulatory-framework/, https://www.cssf.lu/en/Document/circular-cssf-25-882/ and https://www.cssf.lu/en/Document/circular-cssf-25-883/

  4. [6] CSSF. ICT and cyber risk — for DORA entities — Luxembourg DORA implementation, competent authorities and supervisory guidance. Status/date: accessed July 2026. Source: CSSF. https://www.cssf.lu/en/ict-and-cyber-risk-for-dora-entities/

  5. [11] Luxembourg / Chambre des Députés. Projet de loi no. 8476 implementing Regulation (EU) 2024/1689 (AI Act) — proposed national competent authorities; CNPD as default market-surveillance authority and single point of contact, supported by sectoral authorities (CSSF, CAA, ILNAS, ILR, ALMPS, ALIA and the judicial supervisory authority). Status/date: in committee; Council of State opinion 10 July 2026. Sources: Chambre des Députés and CNPD. https://www.chd.lu/fr/dossier/8476 and https://cnpd.public.lu/fr/actualites/national/2024/11/cnpd-ai-act.html

  6. [13] Grand-Duché de Luxembourg / HCPN. Loi du 5 mai 2026 sur la résilience des entités critiques (Mémorial A No 226, published 11 May 2026; parliamentary dossier 8307) — Luxembourg CER transposition; HCPN competent authority and national single point of contact; CSSF for banking, financial-market infrastructure and supervised digital infrastructure. Status/date: in force 2026. Sources: Legilux, Chambre des Députés and HCPN. https://legilux.public.lu/eli/etat/leg/loi/2026/05/05/a226/jo, https://www.chd.lu/fr/dossier/8307 and https://hcpn.gouvernement.lu/fr/service/attributions/missions-nationales/protection-infrastructures-critiques.html

Threat & policy context

  1. [7] European Commission. Guidance on the relationship between NIS2 and sector-specific Union acts (NIS2 Article 4) — where a sector-specific act such as DORA imposes at least equivalent requirements, the corresponding NIS2 provisions do not apply (Commission Guidelines on the application of Article 4(1) and (2) of Directive (EU) 2022/2555, OJ C 328, 18.9.2023). Status/date: accessed July 2026. Source: European Commission. https://digital-strategy.ec.europa.eu/en/library/commission-guidelines-application-article-4-1-and-2-directive-eu-20222555-nis-2-directive

  2. [15] ENISA. Threat Landscape — annual threat landscape series and threat-pattern context. Status/date: current annual series. Source: ENISA. https://www.enisa.europa.eu/topics/cyber-threats/threats-and-trends

  3. [16] European Commission. EU Cybersecurity Strategy for the Digital Decade — Dec 2020 policy context. Status/date: published Dec 2020. Source: European Commission. https://digital-strategy.ec.europa.eu/en/library/eus-cybersecurity-strategy-digital-decade

Other sources

  1. [10] Council of the European Union. AI omnibus — provisional political agreement on amending the AI Act application dates — would move the main Annex III high-risk rules to 2 December 2027 and product-related high-risk rules to 2 August 2028; provisional until the amending regulation is adopted and published. Status/date: provisional political agreement, 7 May 2026. Source: Council of the EU. https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/

Related reading