Skip to main content
NIS2 · LUXEMBOURG

NIS2 in Luxembourg — the HCPN, CIRCL, and financial-sector overlap with DORA.

Luxembourg transposed NIS2 through national legislation, with the High Commission for National Protection (HCPN) serving as the competent authority and CIRCL operating as the national CSIRT. What makes Luxembourg distinctive is not the transposition mechanism but the sector structure: the country hosts an outsized financial-services sector relative to its size, and NIS2 scope for financial entities must always be checked against DORA overlap. The same entity is frequently subject to both regimes, creating a compliance question that does not arise with the same frequency elsewhere.

The transposition follows the standard EU structure, but the financial-sector concentration creates a distinctive compliance landscape. For organizations operating in Luxembourg's financial sector, this means navigating overlapping obligations from NIS2 and DORA rather than treating them as separate programs. The question is not "which regime applies?" but "how do both apply together?" — and the answer requires mapping both regimes onto one control model so overlapping obligations do not mean duplicated evidence.

Who it applies to

Essential and important entities across NIS2 sectors, with particular emphasis on financial services given Luxembourg's economic structure. Entities that meet the size thresholds must register with HCPN and submit risk-management documentation. Financial entities should always check for DORA overlap.

The clock

Competent authority: HCPN + CIRCL. Transposition: National Cybersecurity Law (NIS2 transposition).

NIS2 in Luxembourg · timeline
WhenWhat happens
National transpositionNIS2 law enters into force · HCPN authority confirmed
On registrationRegistration with HCPN · risk-management filing
OngoingIncident reporting to CIRCL · annual compliance updates

Financial-sector DORA overlap

Luxembourg's outsized financial-services sector means NIS2 and DORA frequently overlap for the same entity, creating a distinctive compliance challenge. Most member states have less financial-sector concentration, so the overlap question arises less often. In Luxembourg, it is the default: financial entities must navigate both regimes simultaneously. The question is not "which applies?" but "how do both apply together?" — and the answer requires mapping NIS2 and DORA onto one control model so overlapping obligations do not mean duplicated evidence. TruSecure holds both mappings in one place, so a single control produces both exports.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Luxembourg transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Luxembourg requirements · how TruSecure answers them
What the law asksWhere it is answered
Check NIS2 and DORA overlapApplicability engine · both regimes assessed for financial entities
Register with HCPNEntity profile · NIS2 registration, with DORA obligations tracked alongside
File risk-management documentationRisk register · aligned with both NIS2 and DORA requirements
Report incidents to CIRCLIncident workflow · clocked reporting, with both regimes considered
Map overlapping obligationsCompliance workspace · NIS2 and DORA onto one control model, no duplication

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Luxembourg NIS2 readiness file · excerptSample data
Applicability
confirmed · financial entity, NIS2 essential + DORA in scope
HCPN registration
complete · filed with DORA obligations tracked
Regime overlap
mapped · single control library serves both NIS2 and DORA
Controls evidenced
64/72 · 8 open, with dual-regime ownership
Export
sealed · sha256:7c3a...5e9f

Where teams usually start

With a demo walked through by TruSecure — your NIS2 and DORA overlap assessed, both regimes mapped onto one control model, and overlapping obligations unified so compliance does not mean duplicated evidence.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Luxembourg by HCPN + CIRCL. TruSecure determines applicability against Luxembourg's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

If we're a Luxembourg financial entity, do NIS2 and DORA both apply?
Often yes — Luxembourg's outsized financial-services sector means NIS2 and DORA frequently overlap for the same entity, and TruSecure maps both onto the same control model so overlapping obligations don't mean duplicated evidence.