NIS2 in Luxembourg — the HCPN, CIRCL, and financial-sector overlap with DORA.
Luxembourg transposed NIS2 through national legislation, with the High Commission for National Protection (HCPN) serving as the competent authority and CIRCL operating as the national CSIRT. What makes Luxembourg distinctive is not the transposition mechanism but the sector structure: the country hosts an outsized financial-services sector relative to its size, and NIS2 scope for financial entities must always be checked against DORA overlap. The same entity is frequently subject to both regimes, creating a compliance question that does not arise with the same frequency elsewhere.
The transposition follows the standard EU structure, but the financial-sector concentration creates a distinctive compliance landscape. For organizations operating in Luxembourg's financial sector, this means navigating overlapping obligations from NIS2 and DORA rather than treating them as separate programs. The question is not "which regime applies?" but "how do both apply together?" — and the answer requires mapping both regimes onto one control model so overlapping obligations do not mean duplicated evidence.
Who it applies to
Essential and important entities across NIS2 sectors, with particular emphasis on financial services given Luxembourg's economic structure. Entities that meet the size thresholds must register with HCPN and submit risk-management documentation. Financial entities should always check for DORA overlap.
The clock
Competent authority: HCPN + CIRCL. Transposition: National Cybersecurity Law (NIS2 transposition).
| When | What happens |
|---|---|
| National transposition | NIS2 law enters into force · HCPN authority confirmed |
| On registration | Registration with HCPN · risk-management filing |
| Ongoing | Incident reporting to CIRCL · annual compliance updates |
Financial-sector DORA overlap
Luxembourg's outsized financial-services sector means NIS2 and DORA frequently overlap for the same entity, creating a distinctive compliance challenge. Most member states have less financial-sector concentration, so the overlap question arises less often. In Luxembourg, it is the default: financial entities must navigate both regimes simultaneously. The question is not "which applies?" but "how do both apply together?" — and the answer requires mapping NIS2 and DORA onto one control model so overlapping obligations do not mean duplicated evidence. TruSecure holds both mappings in one place, so a single control produces both exports.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Luxembourg transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Check NIS2 and DORA overlap | Applicability engine · both regimes assessed for financial entities |
| Register with HCPN | Entity profile · NIS2 registration, with DORA obligations tracked alongside |
| File risk-management documentation | Risk register · aligned with both NIS2 and DORA requirements |
| Report incidents to CIRCL | Incident workflow · clocked reporting, with both regimes considered |
| Map overlapping obligations | Compliance workspace · NIS2 and DORA onto one control model, no duplication |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Applicability
- confirmed · financial entity, NIS2 essential + DORA in scope
- HCPN registration
- complete · filed with DORA obligations tracked
- Regime overlap
- mapped · single control library serves both NIS2 and DORA
- Controls evidenced
- 64/72 · 8 open, with dual-regime ownership
- Export
- sealed · sha256:7c3a...5e9f
Where teams usually start
With a demo walked through by TruSecure — your NIS2 and DORA overlap assessed, both regimes mapped onto one control model, and overlapping obligations unified so compliance does not mean duplicated evidence.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Luxembourg by HCPN + CIRCL. TruSecure determines applicability against Luxembourg's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.