2024-01-05

CSSF Regulation No 24-01 of 5 January 2024 on the notification of incidents under the NIS Directive

The CSSF issued Regulation No 24-01 on 5 January 2024 to establish the framework for the notification of incidents under the Law of 28 May 2019. This regulation implements Directive (EU) 2016/1148 concerning measures for a high common level of security of network and information systems across the European Union. It defines the specific requirements and procedures for reporting ICT-related incidents to ensure compliance with national and EU cybersecurity standards.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Click to view thumbnail

Published on 5 January 2024

Email this

Share this on LinkedIn

Share this on Facebook

CSSF regulation

relating to the notification of incidents according to the Law of 28 May 2019 transposing Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the European Union.

Communiqué of 5 January 2024

Lien

PDF (49.76Kb)

Related documents

5 January 2024

CSSF FAQ related to Circular CSSF 24/847 on ICT-related incident reporting framework

PDF (341.29Kb)

PDF (331.47Kb)

5 January 2024

Circular CSSF 24/847

on ICT-related incident reporting framework

PDF (300.89Kb)

PDF (213.33Kb)

31 May 2019

Law of 28 May 2019

transposing Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the European Union and amending 1° the Law of…

Lien

PDF (198.07Kb)