Cybersecurity is now
a legal duty
in Luxembourg.
Since May 2026, many Luxembourg companies must prove they take cyber risk seriously. We take care of it for one fixed price: we tell you whether the law applies to you, check how exposed you really are, and write the documents you are required to have.
From €6,900, fixed · English, French or German · Up to 70% may be paid by the State
Does this apply to you?
- 1You work in one of the sectors the law covers: energy, transport, banking, insurance, health, water, food, manufacturing, waste, post, chemicals, space, IT services, digital platforms, public bodies or research.
- 2You have 50 staff or more, or more than €10 million in yearly turnover.
- 3Or, whatever your size, you provide IT services to a company that ticks both boxes above — or to a Luxembourg bank or insurer.
Are you concerned? Check in 20 seconds
Three questions and an indicative answer — whether the Law of 5 May 2026 is likely to apply to your company. Indicative only, not a legal opinion.
What Luxembourg
now expects of you
The law of 5 May 2026 puts companies into two groups — essential and important — based on what they do and how big they are. The more critical your business, the closer the supervision.
| Essential | Important | |
|---|---|---|
| Your size | 250 staff or more, or turnover above €50m | 50 to 249 staff, or turnover of €10m to €50m |
| Your sector | The eleven most critical: energy, transport, banking, health, water, digital and similar | Also manufacturing, food, waste, post, digital platforms and research |
| How you are checked | Every year you send the ILR your security measures, your main risks and your plan for the years ahead | Nothing to send in — but the ILR can inspect you after an incident or a complaint |
| Worst-case fine | €10m, or 2% of worldwide turnover | €7m, or 1.4% of worldwide turnover |
01The ten measures every covered company must have
- A written view of your risks, and security rules to match
- A plan for handling incidents when they happen
- Backups, and a way to keep trading through a crisis
- Checks on the suppliers who touch your systems
- Security built into the software and systems you buy or build
- A way to test whether your measures actually work
- Basic security habits, and training for your staff
- Encryption where it matters
- Control over who can access what, and what happens when people leave
- Two-step login and secure communications
Some companies are covered no matter how small they are — for example if you are the only provider of a service, or you run domain name or trust services. And if you are too small to be covered directly, your clients will very likely pass these requirements on to you in your contract.
One audit. One file.
One fixed price.
Made for Luxembourg companies of 20 to 250 people. You do not need to understand IT security — that is our job. You need to be in order, and to be able to show it.
The NIS2 Compliance Audit
Your legal position established, your defences actually tested, your file complete — for one fixed price.
We work out whether the law applies to you, test how exposed your systems really are, and write every document you are required to hold. You end up with one file your board can sign and the authorities can read.
What we check
- Whether the law applies to you at all — answered in writing, with our reasoning
- Your registration with the ILR: we prepare it and file it, even if you are late
- Where you stand against the ten things the law requires
- What a stranger can reach from the internet: open systems, old software, passwords already leaked online
- Your Microsoft 365 and staff accounts: who has admin rights, who is missing two-step login
- Your people: a realistic fake phishing email, so you know how many would click
What you receive
- A risk assessment, written the way the authority expects it
- A security policy your board can approve and sign
- An action plan: what to fix, in what order, and what it will cost
- An incident procedure: who does what, and how to report in time
- Wording to put in your IT suppliers' contracts
- A meeting with your board, including the training directors must now have
- A report in plain language — and a free re-check once you have fixed things
We call you back within 24 hours, and the scoping call costs you nothing.
Ask for a quoteThe State may pay up to 70% of this
Through the Ministry of the Economy's SME Packages — Cybersecurity scheme, Luxembourg SMEs can be reimbursed 70% of the cost, for projects between €3,000 and €25,000 excluding VAT. On a €6,900 audit, that can bring what you actually pay down to around €2,070.
To qualify you first need a short review by the Luxembourg House of Cybersecurity, arranged through the House of Entrepreneurship or the Chambre des Métiers. We will tell you who to call and prepare our quote in the format the application needs. The final decision rests with the Ministry.
+Two things beyond the audit
Penetration testing and red teaming
If you already have an IT or security team and want your defences genuinely attacked, that is a different kind of engagement — scoped around your environment, quoted individually, and run by people who do this full time.
See our offensive security work →Ongoing support
Compliance is not a one-off. We can keep your file up to date, handle your yearly submission, re-check your systems every quarter, and pick up the phone if something goes wrong.
Three commitments
we put in writing
Plenty of firms will sell you a NIS2 project. These three go into the engagement letter, and they are the reasons clients choose us over a consultancy or over their own IT provider.
We don't run your IT, so we can audit it
Your IT provider can install your security and tell you it is sound. What nobody can do is independently verify their own work. We sell no software, resell no licences and manage no infrastructure — so nothing we find costs us anything to report.
Every control carries two scores
How developed it is, and how we know it: you told us, we read the document, or we tested it and saw the result. You can see at a glance which parts of your file are claims and which are proven. Most reports give you only the first number.
The number does not move
One figure, agreed before we start, unchanged by what we find. No day rates, no scope creep, no revision because the assessment turned up more than expected. If we misjudge the work, that is our problem and not your invoice.
02See a specimen page from the file we hand over
Every control is scored twice: how far along it is, and how we established that. You can see at a glance which parts of your compliance rest on evidence and which rest on somebody's word.
- Verified
- We tested it and saw the result
- Documented
- We read the artefact ourselves
- Claimed
- Someone told us, nothing more
| Control | Stage | Basis |
|---|---|---|
| Multi-factor authentication | 3 Implemented | Verified |
| Backups and restore testing | 2 Defined | Documented |
| Supplier security clauses | 1 Ad hoc | Claimed |
| Internet-facing systems | 3 Implemented | Verified |
| Staff security training | 2 Defined | Verified |
| Privileged account review | 0 Absent | Verified |
An illustration, not a real client. Your scores will be your own — including the ones you would rather not see.
Four steps, four to six weeks
You will know from day one what we need from you and when. We ask for a few hours of your time in total — the rest is our work.
Where you stand
We confirm in writing whether the law applies to you, then prepare or correct your registration with the ILR.
What we find
A conversation with you and your IT provider, a look at your documents, and a real test of what is exposed.
What we write
Your risk assessment, security policy, action plan and incident procedure — written for your company, not copied from a template.
What you sign
We present it to your board, run the training directors are required to have, and hand over the finished file.
03Everything we can test, beyond the audit itself
Plenty of firms will sell you a folder of documents. Ours are backed by people who break into systems for a living — which is why our findings hold up in front of an inspector, an insurer, or a client checking their suppliers.
Getting you compliant
Working out if the law applies to you, finding the gaps, and preparing everything you have to send to the ILR.
What outsiders can see
Everything reachable from the internet: forgotten servers, out-of-date software, expired certificates, staff passwords already circulating.
Email and cloud accounts
Microsoft 365, Google Workspace, AWS and Azure: who holds the keys, who can still log in without two-step, and what is shared too widely.
Penetration testing
A proper attempt to break into your applications, your internal network or your cloud — included in the audit, or booked on its own for larger organisations.
Your staff
A measured phishing test, short practical training, and the separate session the law now requires of company directors.
Answering your clients
If a large client sends you a security questionnaire before renewing your contract, we prepare the answers and the evidence behind them.
The questions we
are asked most
Does the Luxembourg cybersecurity law apply to my company?
I never registered with the ILR by 10 July 2026. What now?
What does becoming compliant actually cost?
We have fewer than 50 employees. Are we exempt?
How long does it take?
What are the penalties for getting this wrong?
What is the difference between an essential and an important entity?
Our IT provider says they can handle this. Why would we use you?
How are you different from a large consultancy?
Do you also do penetration testing?
Not sure whether
this concerns you?
That is the most common question we get, and the easiest to answer. One short call and you will know where you stand — at no cost, whether or not you become a client.
Book a free callTell us about
your company
Your sector, how many people you employ, and who looks after your IT. That is enough for us to tell you whether the law applies to you. We reply within one working day.
L-4367 Belvaux, Luxembourg
We call you back within 24h
Leave your number — we do the rest.