Appoint us
Company outside the Union assessing whether NIS2 applies to its services

REP27 · NIS2 · Non-EU companies

Article 26(1)(b) · jurisdiction · registration

NIS2 for companies outside the Union.

NIS2 does not reach every foreign company with European customers, and that is the first thing worth knowing. It reaches a defined list of digital service providers, and for those it goes further than the GDPR: the designation of a representative establishes jurisdiction, and a registration duty follows. This page runs the test in the order that matters, compares it with the Article 27 test you may already have run, and sets out the four first steps.

Article 26(1)(b)JurisdictionRegistrationAnnex IAnnex II

Request this service   Ask a question

NIS2 and the GDPR test, side by side

NIS2 Article 26(3) compared with Article 27 GDPR for companies outside the Union
NIS2 Article 26(3) compared with Article 27 GDPR for companies outside the Union

Read the second row carefully. Under the GDPR you designate where your data subjects are; under NIS2 you designate where you offer the services, and that choice assigns your supervisory authority. The two can be the same country, and keeping them together is usually easier at audit time.

The test, in the order it should be run

  1. Is the service on the list?

    DNS, TLD registries, cloud computing, data centres, content delivery networks, managed services, managed security services, online marketplaces, search engines, social platforms. If nothing you sell appears here, Article 26(1)(b) does not reach you.

  2. Do you offer it in the Union?

    Offering means directing the service at customers in the Union, not being technically reachable from there. Euro pricing, EU-specific terms, European sales and support are the indicators.

  3. Is the providing entity established in the Union?

    If the legal entity that provides the service to the customer is established in a Member State, Article 26(3) does not apply to it. Group structures need checking entity by entity.

  4. Which annex applies?

    Annex I means essential entity, proactive supervision, higher ceiling. Annex II means important entity, supervision on evidence. The obligation to designate is the same in both.

  5. Then designate and register

    Mandate first, registration second, because the registration asks for the representative's details.

Four first steps

Four first steps for a company outside the Union facing NIS2
Four first steps for a company outside the Union facing NIS2

Where companies get it wrong

AssumptionWhat is actually true
"We are too small for NIS2"The size cap does not save the Article 26(1)(b) providers: they are in regardless of headcount or turnover
"We host in Frankfurt, so we are established"Infrastructure is not establishment. Effective activity through stable arrangements is
"Our EU reseller covers us"Only if that entity provides the service in its own name. Otherwise the obligation stays with you
"We already have an Article 27 representative"Different law, different mandate. One does not satisfy the other
"We serve only enterprises"NIS2 does not distinguish consumer from business customers
"We will register when someone asks"Registration is a standing duty, and being unregistered is what draws the first question
The most common of all: assuming NIS2 works like the GDPR. It does not. It is a directive, transposed differently in each Member State, sector-based rather than activity-based, and it assigns jurisdiction rather than merely creating a contact point.

What a company outside the Union should assemble

Entity map

Which legal entity provides which service to European customers, and where each is established. Everything else depends on this.

Service inventory

Each product matched against Annex I and II, with a written note on why it is in or out. Dated, kept with your records.

Registration data

Name, address, contact points, sector and subsector, Member States served, public IP ranges. The IP ranges take longest to assemble.

Security file

Your Article 21 measures, documented well enough to be described to an authority without a project.

Incident process

Who declares a significant incident, who writes the 24-hour warning, who signs the 72-hour notification. Decide before you need it.

The mandate

Signed with an entity in the chosen Member State, which is where the correspondence will arrive.

Two regimes, one company

Most companies that need a NIS2 representative also need an Article 27 GDPR representative, because a cloud or platform service that handles customer data is normally a processor reached by Article 3(2). Holding both with the same provider is not a package trick: it removes the two failure modes we see most often.

Failure modeWhat causes itWhat removes it
One mandate lapses quietlyTwo providers renewing in different monthsOne invoice, one expiry date
Different addresses publishedNotice and registration naming different entitiesConsistent identification everywhere
Requests bounce between desksNobody sure which provider handles whatOne desk, both mandates, one log
Audit takes weeksCertificates from two sources, verified differentlyTwo certificates, one verification page

Three company shapes, three answers

Abstract tests are hard to apply to your own structure. These three shapes cover most of what reaches us, and the reasoning transfers.

ShapeNIS2Reasoning
US company, no EU entity, sells cloud to European businessesDesignate and registerAnnex I service, offered in the Union, no establishment there
US company with a real Irish subsidiary that contracts with EU customersNo designation for that entityThe providing entity is established in the Union
Indian managed service provider selling through an EU reseller in the reseller's own nameDepends on who provides the serviceIf the reseller provides it, the obligation is the reseller's

The second row is worth pausing on, because it is where honest analysis saves money. If a European entity in your group genuinely contracts with customers, operates the service and carries the risk, that entity is established in the Union and Article 26(3) does not apply to it. What does not work is a letterbox subsidiary with no staff and no operations: NIS2 borrows the same idea of effective activity through stable arrangements that the GDPR uses, and an empty shell fails it.

The third row is the one that produces arguments with resellers. The test is who provides the service to the customer, in whose name, under whose terms. A reseller invoicing in its own name and carrying the contract is the provider; an agent introducing customers to you is not.

A short glossary, because the words are new

Essential entity

Annex I sectors. Proactive supervision, higher fine ceiling, inspections without a trigger.

Important entity

Annex II sectors. Supervision on evidence of non-compliance, lower ceiling, same designation duty.

Significant incident

One causing severe operational disruption or financial loss, or affecting others with considerable damage. It starts the 24-hour clock.

Early warning

The first notification, within 24 hours of becoming aware, saying whether the incident looks malicious or cross-border.

Incident notification

Within 72 hours, with an assessment, severity, impact and indicators of compromise.

Competent authority

The national body that supervises you, determined by the Member State of your representative.

What to write down, whatever the answer

The analysis itself is a compliance artefact. Half a page, dated, kept with your records, and it settles the question the first time an authority or a customer asks.

  1. The services and the annex

    Each product, whether it falls in Annex I or II, and the reasoning in one sentence each.

  2. The entity that provides each one

    With its place of establishment, because that is what decides whether Article 26(3) applies at all.

  3. The Member States served

    The list you will also use in the registration.

  4. The conclusion

    Designate or not, and if yes, in which Member State and why.

  5. A review date

    New services and new markets change the answer. Once a year is enough for most companies.

A dated decision made before anyone asked reads very differently from one written after a letter arrived. It costs an hour now and it is the difference between looking organised and looking caught out.

Timing, and why waiting is expensive

NIS2 has been transposed at different speeds across the Union, which has produced a dangerous impression that nothing is happening. Two things are happening at once, and only one of them is enforcement.

PressureWhere it comes fromHow fast it arrives
SupervisionNational authorities, proactive for essential entitiesBuilding, state by state
Customer questionnairesYour European clients meeting their own supply chain dutyAlready here, in every enterprise deal
Procurement gatesBuyers refusing to onboard unregistered providersImmediate, and silent: you lose without being told why
Insurance and auditsCyber policies and certification bodies asking the same questionsAt renewal

The second and third rows are the reason to act now rather than when the authority writes. A missing designation rarely produces a fine in year one; it routinely produces a lost contract, and nobody sends an email explaining that was the reason.

The short version

NIS2 reaches you only if you provide one of the listed services in the Union and the entity providing it is not established there. If that is you, the designation is not a formality: it selects your supervisory authority and it precedes a registration with defined fields. Run the test on paper, write down the conclusion with a date, and decide the Member State deliberately. If nothing you sell appears in Annexes I and II, NIS2 does not apply to you at all, and the only European representative you need is the Article 27 one.

Signing a NIS2 mandate for a provider established outside the Union
Signing a NIS2 mandate for a provider established outside the Union
Infrastructure operated from outside the Union for European customers

Questions we are actually asked

Does NIS2 apply to every foreign company selling in the EU?

No. It applies to entities providing the services listed in Article 26(1)(b), among them cloud, DNS, CDN, data centres, managed services, marketplaces, search engines and social platforms.

How is it different from the GDPR representative?

The GDPR designation creates a contact point. The NIS2 designation also determines which Member State has jurisdiction over you, and it comes with a registration duty.

Can one company hold both mandates for us?

Yes, and it is simpler: two designations, two certificates, one renewal date and one desk.

Which Member State assigns jurisdiction?

The one where your representative is established, chosen among the states where you offer the services.

Are small companies exempt?

The general size cap does not apply to the Article 26(1)(b) providers. They are caught regardless of size.

We sell only to businesses. Does that help?

No. NIS2 looks at the service you provide, not at the type of customer.

Is hosting in the EU enough to avoid the obligation?

No. Establishment requires effective and real activity through stable arrangements, not servers.

What is registered under Article 27?

Entity name, address, contact details, sector and subsector, the Member States where you offer services and your public IP ranges.

Who reports incidents?

You do: early warning within 24 hours, notification within 72, final report within a month. The representative receives correspondence, it does not report.

What are the penalties?

Essential entities face at least €10 million or 2% of worldwide turnover; important entities at least €7 million or 1.4%, whichever is higher.

Does an EU subsidiary solve it?

If that subsidiary is the entity providing the service, Article 26(3) does not apply to it. Check which entity contracts with the customer.

How long does designation take?

The mandate is signed within 24 hours of the intake call, and registration then follows the national channel.

What if we provide several listed services?

One designation covers the entity. The registration lists the sectors and the Member States served.

Do we need a local office?

No. You need a representative established in a Member State, which is exactly what this service is.

Is certification required?

No. Article 21 requires appropriate measures. Certification may evidence them but is not itself the obligation.

Can management be held liable?

Yes. NIS2 makes management bodies accountable for approving and supervising the measures.

What does it cost?

€490 a year for NIS2, €690 for the plan covering NIS2 and Article 27 GDPR together.

What is not included?

Incident reporting, security implementation, audits, certification and legal advice on national transpositions.

Related: the designation explained · the Article 27 test

Two mandates, one provider, one renewal

NIS2 under Article 26(3) and Article 27 GDPR from Europe Services, SE in Prague, each with its own certificate and verification code.

Request this service