CRA · 2 Oct 2026

The Cyber Resilience Act in Luxembourg

Three key roles, one filled so far. Get ready for future inspections.

Who in Luxembourg will be authorised to inspect your product under the Cyber Resilience Act (CRA)? On 2 October 2026, we could find no authority designated to do so. That is on schedule: the Regulation does not require a market surveillance authority until 11 December 2027.

What the Act already demands of manufacturers is responsiveness. Since 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability in its product must send an early warning without undue delay, and at the latest within 24 hours. If its main establishment in the Union is in Luxembourg, the warning must be sent to the Computer Incident Response Center Luxembourg (CIRCL) and, at the same time, to ENISA, the European Union Agency for Cybersecurity.

For national authorities, the CRA, Regulation (EU) 2024/2847, names roles rather than institutions and leaves each member state to decide which body fills them. Three matter to a manufacturer: the computer security incident response team (CSIRT) designated as coordinator, which receives your vulnerability and incident reports; the notifying authority, which assesses and notifies the bodies that carry out third-party conformity assessments; and the market surveillance authority, which enforces the Regulation, can demand your technical documentation and can order your product off the market. In Luxembourg, one of the three has been designated.

Role Luxembourg, 2 October 2026 CRA provision applies from (Article 71(2))
CSIRT designated as coordinator CIRCL Reporting, Article 14: 11 September 2026
Notifying authority None found Chapter IV, Article 36: 11 June 2026
Market surveillance authority None found Chapter V, Article 52: 11 December 2027

Reporting: CIRCL, live since 11 September

Most of the CRA applies from 11 December 2027. Article 14, the reporting obligation, has applied since 11 September 2026 (Article 71(2)).

A manufacturer that becomes aware of an actively exploited vulnerability in its product, or of a severe incident having an impact on the product’s security, must notify the coordinating CSIRT and ENISA at the same time, through ENISA’s single reporting platform. The deadlines: an early warning within 24 hours, a notification within 72 hours, then a final report. For a vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure is available; for an incident, within one month of the incident notification (Article 14(1) to (4)).

The receiving CSIRT is the coordinator of the member state where the manufacturer has its main establishment in the Union (Article 14(7)). ENISA’s list of coordinators, last updated on 10 September 2026, covers all twenty-seven member states. For Luxembourg, it names CIRCL.

ENISA’s registration guidance, last updated on 12 September 2026, says three things worth knowing before you need them:

  • You sign in through EU Login, with multi-factor authentication enabled. Registration then asks you to choose the coordinating CSIRT and to enter the manufacturer’s details.
  • Validation does not block a report. The CSIRT checks whether you are authorised to report for that manufacturer after registration; that check is not a prerequisite for submitting a notification. Procedures vary between CSIRTs.
  • ENISA advises against registering early. Manufacturers should register and start validation only when they need to submit a specific notification, not pre-emptively.

Two similar names mean different things. The platform refers to its account holders as Assigned Representatives. That is a platform role, not the authorised representative a manufacturer may appoint by written mandate under Article 18.

Funding: help with the cost

The National Cybersecurity Competence Centre (NC3), hosted by the Luxembourg House of Cybersecurity, is Luxembourg’s National Coordination Centre under Regulation (EU) 2021/887. Its missions include coordinating investment from the Digital Europe and Horizon Europe programmes. Two schemes are relevant to a manufacturer on a budget.

SME Packages (Cybersecurity). The Ministry of the Economy pays 70 per cent of the eligible costs of a cybersecurity project worth between 3,000 and 25,000 euro excluding VAT, once the project is in place. The Luxembourg House of Cybersecurity carries out a mandatory pre-analysis that sets the priority actions, you choose the provider, and an evaluation meeting with the House of Cybersecurity closes the file. The House of Entrepreneurship helps with the application. The scheme’s page refers to the NIS 2 Directive (Directive (EU) 2022/2555), not the CRA, so ask whether your CRA work qualifies before you count on it.

SECURE (Strengthening EU SMEs Cyber Resilience). An EU-funded programme for micro, small and medium-sized enterprises that must comply with the CRA. Its second open call runs from 1 October to 11 December 2026 and offers up to 30,000 euro per project at 50 per cent co-financing; the first call closed on 29 March 2026. Firms whose core activity is CRA consultancy or security services cannot be direct beneficiaries unless they themselves place products with digital elements on the market; however, they can take part as subcontractors.

Enforcement: no designation found

Article 52(2) is the whole instruction:

Each Member State shall designate one or more market surveillance authorities for the purpose of ensuring the effective implementation of this Regulation. Member States may designate an existing or new authority to act as market surveillance authority for this Regulation.

Article 64 sets the fines: up to 15 million euro or 2.5 per cent of total worldwide annual turnover for the essential requirements and Articles 13 and 14; up to 10 million euro or 2 per cent for the obligations listed in Article 64(3); up to 5 million euro or 1 per cent for supplying incorrect, incomplete or misleading information; whichever is higher in each case. Depending on the member state, fines may be imposed by courts or other bodies (Article 64(8)).

Like most of the Regulation, Article 64 applies from 11 December 2027 (Article 71(2)). For micro and small manufacturers there is an exemption: they cannot be fined under Article 64 for missing the 24-hour early warning, whether for an actively exploited vulnerability or for a severe incident. Missing the 72-hour notification or a final report can still be fined (Article 64(2) and (10)(a); the opening words of Article 64(10) were corrected in the Official Journal on 2 July 2025). The Regulation takes its definitions of micro and small enterprises from the Annex to Recommendation 2003/361/EC (Article 3(19)): in short, fewer than 50 staff and no more than 10 million euro of annual turnover or balance sheet total, counted together with any linked or partner enterprises, so a small subsidiary of a larger group does not qualify.

On 2 October 2026, we found no Luxembourg designation of a CRA market surveillance authority.

  • A full-text search of Legilux, the official journal, returns no act citing Regulation 2024/2847.
  • The Chambre des Députés has no CRA bill. The Regulation appears in a few bill files, but only in passing: in EU texts reproduced there, or in the title of another EU act. The closest in subject, bill 8740, implements Regulation (EU) 2019/881 on managed security services.
  • The Commission’s register of market surveillance authorities lists no Luxembourg authority for the CRA. It lists the Institut luxembourgeois de la normalisation, de l’accréditation, de la sécurité et qualité des produits et services (ILNAS) for 142 other pieces of Union legislation, including the Artificial Intelligence Act and the Batteries Regulation.

For the Cybersecurity Act, Regulation (EU) 2019/881, the designation came by law: the Loi du 20 décembre 2024 designates ILNAS as the national cybersecurity certification authority, a role ILNAS has held since 2020. For the Artificial Intelligence Act, bill 8476, deposited on 23 December 2024 and still in committee, would make the Commission nationale pour la protection des données (CNPD), Luxembourg’s data protection authority, the default market surveillance authority.

In the meantime, ILNAS’s own article on the CRA, published on 17 December 2024, provides contact details under the heading “Surveillance du marché” (market surveillance): surveillance@ilnas.etat.lu. The article does not say that ILNAS will be designated.

How Luxembourg compares

What the registers showed on 2 October 2026:

Role Required from Member states listed
Coordinating CSIRT 2024, under the NIS 2 Directive (Article 12(1)) 27 of 27 (ENISA list)
Notifying authority for the CRA 11 June 2026 13 of 27 (Commission register)
Market surveillance authority for the CRA 11 December 2027 7 of 27 (Commission register)

Luxembourg appears only on ENISA’s list of coordinators.

Article 52 sits in Chapter V, which applies from 11 December 2027 (Article 71(2)), so no member state is late in designating a market surveillance authority. This does not apply to the notifying authority: Chapter IV, which includes Article 36, has applied since 11 June 2026.

The seven market surveillance entries come from Belgium, Cyprus, Finland, France, Germany, Latvia and Slovakia, and not every body named is a cybersecurity agency: France is recorded with the Agence nationale des fréquences (ANFR), its spectrum agency, and Belgium with the Belgian Institute for Postal Services and Telecommunications (BIPT), its telecoms regulator.

National laws are at different stages. Finland’s Act 439/2026, in force since 1 June 2026, names Traficom, the Finnish Transport and Communications Agency. Germany’s bill, which had its first reading in the Bundestag on 11 June 2026, names the Federal Office for Information Security (BSI). A French bill, not yet adopted, names the ANFR. The Dutch bill passed the Tweede Kamer on 10 September 2026 and is before the Eerste Kamer; the Netherlands is not yet among the seven.

What it means for you

Until Luxembourg designates one, there is no CRA market surveillance authority to ask how it will read a requirement. Once designated, such authorities may give guidance and advice to economic operators (Article 52(10)).

The requirements do not depend on who enforces them. The CRA is a regulation, so the same Annex I requirements, Annex VII technical documentation and Article 14 reporting apply in every member state. Build the file for the Regulation, not for the regulator, and do three things now.

  1. Find your conformity route. Products outside the important and critical categories may be self-assessed. Important products of class I (Annex III) may be self-assessed only if the manufacturer fully applies harmonised standards, common specifications or a European cybersecurity certification scheme at an assurance level of at least “substantial” (Article 32(2)); no CRA harmonised standard has been cited in the Official Journal yet. Class II and critical products (Annex IV) need a third party (Article 32(3) and (4)). Either way, by drawing up the EU declaration of conformity the manufacturer takes responsibility for compliance (Article 28(4)).
  2. Name the person who reports. Decide who, by name, would file a notification at night or at a weekend, and make sure that person already has a working EU Login account with multi-factor authentication. That person should not be registered on the platform yet, since ENISA advises against registering early, but should be able to sign in without a password reset while the 24-hour clock runs.
  3. Set your support period. Article 13(19) requires its end date, at least the month and the year, to be clearly specified at the time of purchase.

None of the three waits for an authority to be designated. Which route applies depends on your product, and every route rests on the technical documentation. The evidence in that file, your reporting and your support period are where we can help, and the place to start is your product.

Tell us about your product →


General information on the Regulation, checked against its text and the sources below between 25 September and 2 October 2026. Not legal advice.

Sources

← Back to Insights