Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity services — Luxembourg

Command of the Luxembourg regulatory framework — ILR, CSSF, CNPD, NIS2, DORA — with dedicated expertise for financial entities regulated by the CSSF.

Last updatedAugust 22, 2026

The local regulatory framework

Luxembourg's cybersecurity framework relies on the Institut Luxembourgeois de Régulation (ILR) for the oversight of essential and important service operators under NIS2, on the Commission de Surveillance du Secteur Financier (CSSF) for financial entities, and on the Commission Nationale pour la Protection des Données (CNPD) for personal data protection. The CSSF issues specific circulars governing IT risk management, information security governance, and the use of third-party providers for the entities it supervises. Given the weight of Luxembourg's financial center, the EU DORA regulation carries particular importance for financial institutions, insurance undertakings and their critical ICT providers.

Concrete obligations

Compliance with CSSF circulars on IT risk management and information security governance for regulated financial entities

Application of the DORA regulation for financial institutions, insurance undertakings and their critical ICT providers

Compliance with NIS2-derived obligations for essential and important service operators supervised by the ILR

GDPR compliance under the oversight of the Commission Nationale pour la Protection des Données (CNPD)

Priority sectors

Financial services & insuranceInvestment fundsPublic sector

Delivery modalities

Engagement model

Direct engagement

Specialization

DORA compliance and CSSF circulars for the financial sector

Languages

French, English, German

Local FAQ

What are the reference cybersecurity authorities in Luxembourg?

The ILR for essential and important service operators, the CSSF for the financial sector, and the CNPD for personal data protection.

Why is DORA particularly important in Luxembourg?

Given the weight of Luxembourg's financial center, a large number of financial institutions, insurance undertakings and investment funds fall directly within the scope of the DORA regulation. This topic has its own dedicated page on this site.

What do CSSF circulars require in terms of cybersecurity?

They govern IT risk management, information security governance, and the use of third-party providers for entities supervised by the CSSF.

Which entities are supervised by the ILR under NIS2?

Essential and important service operators identified according to the sector and size criteria set by the national NIS2 transposition.

Which authority oversees data protection in Luxembourg?

The Commission Nationale pour la Protection des Données (CNPD), which enforces GDPR.

What services are most requested in Luxembourg?

GRC compliance aligned with DORA and CSSF circulars, security audits, and outsourced CISO support for financial center actors.

How does an engagement in Luxembourg typically start?

With an initial scoping phase to identify the entity's regulatory status (CSSF, ILR, DORA) and the requirements applicable to its sector.

Get in touch