← HomeREP27All categories

Security vendors, EDR and threat intelligence

Digital and connected products

In short
NIS2 representative for managed security service providers, plus an Article 27 GDPR representative and a CRA representative for products

Who has to appoint one

Security vendors outside the Union serving EU customers. Managed security service providers are explicitly listed in NIS2, so the representative obligation arises there as well as under the GDPR, and security software placed on the market falls under the CRA.

Thresholds and exemptions

NIS2 generally applies to entities with at least 50 staff or €10 million turnover, but managed security service providers are covered in several implementations regardless of size given their criticality.

What must appear on the label

Not physical. Publication of the NIS2 registration details and the CRA vulnerability contact point, and the GDPR representative in the privacy notice.

Marketplace fields

Enterprise and public buyers ask for NIS2 registration, DORA-compatible contractual terms where the customer is a financial entity, and increasingly for a European cybersecurity certification under the Cybersecurity Act schemes.

Documentation you must hold

NIS2 risk management measures, incident handling procedures, supply chain security policy and registration. Article 30 records covering telemetry, which for security products is extensive and sensitive. The Article 27 designation. CRA technical documentation, SBOM and vulnerability handling for products.

Standards and testing

Penetration testing and, for essential entities, audits imposed by the competent authority. Certification under a European scheme where the customer requires it.

Language requirements

Incident reports in the language accepted by the CSIRT, and customer documentation in the market language.

When it applies

NIS2 reporting within 24 hours, 72 hours and one month. CRA vulnerability reporting from 11 September 2026 and the full regime from 11 December 2027.

How long records are kept

Incident records per NIS2, telemetry only as long as necessary for the security purpose, which is the point most often challenged.

What happens if you do not comply

NIS2 penalties up to €10 million or 2% for essential entities with management accountability, GDPR fines up to 4%, and CRA fines up to €15 million or 2.5%.

Who enforces it

NIS2 competent authorities and CSIRTs, data protection authorities, and market surveillance for the products.

Where the boundary lies

Security telemetry is personal data at scale: endpoint agents collect process names, file paths, URLs and user identifiers, and the legitimate interest analysis has to be documented rather than assumed. A vulnerability in your own agent is reportable under the CRA like any other product.

Questions we are asked

Are we in scope of NIS2 as a security vendor?
Managed security service providers are listed explicitly, and cloud and managed service providers separately. Size thresholds apply but several member states extend them for critical suppliers.
Does our product need CRA compliance?
Security software placed on the EU market is a product with digital elements, so yes, including vulnerability reporting from September 2026.
EU representative · from €290 / year

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category