Luxembourg · Law of 5 May 2026 · Supervised by the ILR

Cybersecurity is now
a legal duty
in Luxembourg.

Since May 2026, many Luxembourg companies must prove they take cyber risk seriously. We take care of it for one fixed price: we tell you whether the law applies to you, check how exposed you really are, and write the documents you are required to have.

From €6,900, fixed · English, French or German · Up to 70% may be paid by the State

5 May 2026
The Luxembourg cybersecurity law, in force since May 2026
The ILR
The authority that registers companies, inspects them and issues fines
24h · 72h · 1 month
How quickly you must report an incident, in three stages
Up to €10m
Maximum fine — and directors can be held personally responsible
Three questions decide it

Does this apply to you?

  • 1You work in one of the sectors the law covers: energy, transport, banking, insurance, health, water, food, manufacturing, waste, post, chemicals, space, IT services, digital platforms, public bodies or research.
  • 2You have 50 staff or more, or more than €10 million in yearly turnover.
  • 3Or, whatever your size, you provide IT services to a company that ticks both boxes above — or to a Luxembourg bank or insurer.
Points 1 and 2 together, or point 3 on its own? Then the law applies to you. Registration with the ILR was due by 10 July 2026, and registering late is itself a breach.
Instant check

Are you concerned? Check in 20 seconds

Three questions and an indicative answer — whether the Law of 5 May 2026 is likely to apply to your company. Indicative only, not a legal opinion.

Indicative screening based on published tests, not a legal opinion. A human signs the final determination.
The law, in plain words

What Luxembourg
now expects of you

The law of 5 May 2026 puts companies into two groups — essential and important — based on what they do and how big they are. The more critical your business, the closer the supervision.

 EssentialImportant
Your size 250 staff or more, or turnover above €50m 50 to 249 staff, or turnover of €10m to €50m
Your sector The eleven most critical: energy, transport, banking, health, water, digital and similar Also manufacturing, food, waste, post, digital platforms and research
How you are checked Every year you send the ILR your security measures, your main risks and your plan for the years ahead Nothing to send in — but the ILR can inspect you after an incident or a complaint
Worst-case fine €10m, or 2% of worldwide turnover €7m, or 1.4% of worldwide turnover
01The ten measures every covered company must have
Required of every company the law covers
  1. A written view of your risks, and security rules to match
  2. A plan for handling incidents when they happen
  3. Backups, and a way to keep trading through a crisis
  4. Checks on the suppliers who touch your systems
  5. Security built into the software and systems you buy or build
  6. A way to test whether your measures actually work
  7. Basic security habits, and training for your staff
  8. Encryption where it matters
  9. Control over who can access what, and what happens when people leave
  10. Two-step login and secure communications

Some companies are covered no matter how small they are — for example if you are the only provider of a service, or you run domain name or trust services. And if you are too small to be covered directly, your clients will very likely pass these requirements on to you in your contract.

This is a plain-language summary for information only, not legal advice. What counts is the law of 5 May 2026 (Mémorial A n° 225), EU Directive 2022/2555, and the guidance published by the Institut Luxembourgeois de Régulation.
What we do

One audit. One file.
One fixed price.

Made for Luxembourg companies of 20 to 250 people. You do not need to understand IT security — that is our job. You need to be in order, and to be able to show it.

Our main service

The NIS2 Compliance Audit

Your legal position established, your defences actually tested, your file complete — for one fixed price.

We work out whether the law applies to you, test how exposed your systems really are, and write every document you are required to hold. You end up with one file your board can sign and the authorities can read.

from €6,900 · fixed price · 4 to 6 weeks · nothing recurring
The price does not change once the scope is agreed.

What we check

  • Whether the law applies to you at all — answered in writing, with our reasoning
  • Your registration with the ILR: we prepare it and file it, even if you are late
  • Where you stand against the ten things the law requires
  • What a stranger can reach from the internet: open systems, old software, passwords already leaked online
  • Your Microsoft 365 and staff accounts: who has admin rights, who is missing two-step login
  • Your people: a realistic fake phishing email, so you know how many would click

What you receive

  • A risk assessment, written the way the authority expects it
  • A security policy your board can approve and sign
  • An action plan: what to fix, in what order, and what it will cost
  • An incident procedure: who does what, and how to report in time
  • Wording to put in your IT suppliers' contracts
  • A meeting with your board, including the training directors must now have
  • A report in plain language — and a free re-check once you have fixed things

We call you back within 24 hours, and the scoping call costs you nothing.

Ask for a quote

The State may pay up to 70% of this

Through the Ministry of the Economy's SME Packages — Cybersecurity scheme, Luxembourg SMEs can be reimbursed 70% of the cost, for projects between €3,000 and €25,000 excluding VAT. On a €6,900 audit, that can bring what you actually pay down to around €2,070.

To qualify you first need a short review by the Luxembourg House of Cybersecurity, arranged through the House of Entrepreneurship or the Chambre des Métiers. We will tell you who to call and prepare our quote in the format the application needs. The final decision rests with the Ministry.

Two things beyond the audit
For larger organisations

Penetration testing and red teaming

If you already have an IT or security team and want your defences genuinely attacked, that is a different kind of engagement — scoped around your environment, quoted individually, and run by people who do this full time.

See our offensive security work
After the audit

Ongoing support

Compliance is not a one-off. We can keep your file up to date, handle your yearly submission, re-check your systems every quarter, and pick up the phone if something goes wrong.

From €650 per month · cancel any time
What's different

Three commitments
we put in writing

Plenty of firms will sell you a NIS2 project. These three go into the engagement letter, and they are the reasons clients choose us over a consultancy or over their own IT provider.

Independence

We don't run your IT, so we can audit it

Your IT provider can install your security and tell you it is sound. What nobody can do is independently verify their own work. We sell no software, resell no licences and manage no infrastructure — so nothing we find costs us anything to report.

Evidence

Every control carries two scores

How developed it is, and how we know it: you told us, we read the document, or we tested it and saw the result. You can see at a glance which parts of your file are claims and which are proven. Most reports give you only the first number.

Fixed price

The number does not move

One figure, agreed before we start, unchanged by what we find. No day rates, no scope creep, no revision because the assessment turned up more than expected. If we misjudge the work, that is our problem and not your invoice.

02See a specimen page from the file we hand over

Every control is scored twice: how far along it is, and how we established that. You can see at a glance which parts of your compliance rest on evidence and which rest on somebody's word.

Verified
We tested it and saw the result
Documented
We read the artefact ourselves
Claimed
Someone told us, nothing more
Specimen · control assessment extract
ControlStageBasis
Multi-factor authentication3 ImplementedVerified
Backups and restore testing2 DefinedDocumented
Supplier security clauses1 Ad hocClaimed
Internet-facing systems3 ImplementedVerified
Staff security training2 DefinedVerified
Privileged account review0 AbsentVerified

An illustration, not a real client. Your scores will be your own — including the ones you would rather not see.

How it works

Four steps, four to six weeks

You will know from day one what we need from you and when. We ask for a few hours of your time in total — the rest is our work.

Step 1

Where you stand

We confirm in writing whether the law applies to you, then prepare or correct your registration with the ILR.

Week 1
Step 2

What we find

A conversation with you and your IT provider, a look at your documents, and a real test of what is exposed.

Weeks 2–3
Step 3

What we write

Your risk assessment, security policy, action plan and incident procedure — written for your company, not copied from a template.

Weeks 3–5
Step 4

What you sign

We present it to your board, run the training directors are required to have, and hand over the finished file.

Week 6
03Everything we can test, beyond the audit itself

Plenty of firms will sell you a folder of documents. Ours are backed by people who break into systems for a living — which is why our findings hold up in front of an inspector, an insurer, or a client checking their suppliers.

Getting you compliant

Working out if the law applies to you, finding the gaps, and preparing everything you have to send to the ILR.

What outsiders can see

Everything reachable from the internet: forgotten servers, out-of-date software, expired certificates, staff passwords already circulating.

Email and cloud accounts

Microsoft 365, Google Workspace, AWS and Azure: who holds the keys, who can still log in without two-step, and what is shared too widely.

Penetration testing

A proper attempt to break into your applications, your internal network or your cloud — included in the audit, or booked on its own for larger organisations.

Your staff

A measured phishing test, short practical training, and the separate session the law now requires of company directors.

Answering your clients

If a large client sends you a security questionnaire before renewing your contract, we prepare the answers and the evidence behind them.

Common questions

The questions we
are asked most

Does the Luxembourg cybersecurity law apply to my company?
It applies if you work in one of the sectors listed in the law and you have 50 staff or more, or more than €10 million in turnover. A handful of activities are covered at any size, such as being the sole provider of a service, or running domain name or trust services. And even if you are below the thresholds, your larger clients are obliged to pass equivalent requirements on to you through your contract. If you are unsure, a thirty-minute call settles it. Read the full guide: who is concerned by NIS2 in Luxembourg →
I never registered with the ILR by 10 July 2026. What now?
Register now. Failing to register is a breach in its own right, and it does not become less of one by waiting. In practice a late registration filed voluntarily, together with a documented plan to close your gaps, is a very different conversation with the regulator than being found unregistered after an incident. We prepare and file late registrations as part of the audit. Read the full guide: you missed the ILR registration deadline →
What does becoming compliant actually cost?
Our Compliance Audit starts at €6,900 as a fixed price, covering the assessment, the technical testing and every document you are required to hold. Luxembourg SMEs can apply for the Ministry of the Economy's SME Packages — Cybersecurity scheme, which reimburses 70% of eligible costs, so the real cost can come down to roughly €2,070. Remediating what we find is separate and depends entirely on what is already in place. Read the full guide: what NIS2 compliance costs in Luxembourg →
We have fewer than 50 employees. Are we exempt?
Usually you are outside the direct scope of the law, yes — but that is rarely the end of it. If you supply IT services to a company that is in scope, or to a Luxembourg bank or insurer, their own supply chain obligations mean the requirements reach you contractually. Small suppliers are increasingly asked to evidence exactly the same controls, just by their clients rather than by the regulator.
How long does it take?
Four to six weeks from the first call to a signed file, and we ask for only a few hours of your time across the whole engagement. Most of that is one interview with whoever manages your IT, access for the technical checks, and a final session with your board.
What are the penalties for getting this wrong?
Up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities. More significant for most owner-managed businesses: the law makes the management body personally responsible for approving the security measures and for being trained on them, so this is not a liability you can fully delegate to your IT provider.
What is the difference between an essential and an important entity?
Size and sector. Essential entities are the larger organisations in the most critical sectors, and they are supervised proactively: every year they file their security measures, their main risks and their multi-year plan with the ILR. Important entities have nothing to file, but can be inspected after an incident or a complaint. The ten underlying security requirements are the same for both.
Our IT provider says they can handle this. Why would we use you?
They may well be able to implement the measures, and if they are good you should keep them. What they cannot do is independently verify their own work. An audit concluding that your IT provider's setup is sound, written by your IT provider, carries very little weight with a regulator, an insurer or a client checking their suppliers. We work alongside your provider rather than replacing them: we find what needs fixing, they fix it, and we check it again afterwards.
How are you different from a large consultancy?
Price and evidence, mostly. A large firm cannot profitably staff a €6,900 engagement, so the same work reaches you at several times the cost — and it is usually built on interviews and document review rather than testing. We test what can be tested and label the rest honestly. What we do not offer is a globally recognised logo on the cover. If that is what your board needs, you should hire them instead.
Do you also do penetration testing?
Yes. Technical testing is built into the audit, and for larger organisations with their own security team we run standalone penetration tests and full red team operations, scoped and quoted individually. Those are described on our offensive security page.

Not sure whether
this concerns you?

That is the most common question we get, and the easiest to answer. One short call and you will know where you stand — at no cost, whether or not you become a client.

Book a free call
Get in touch

Tell us about
your company

Your sector, how many people you employ, and who looks after your IT. That is enough for us to tell you whether the law applies to you. We reply within one working day.

Something confidential
[email protected] — encryption key on request
We reply in
One working day, Monday to Friday
Office
7 avenue du Swing
L-4367 Belvaux, Luxembourg
Where we work
Luxembourg and the Greater Region · on site or remotely

We use your details only to answer you. We never pass them on.