
REP27 · NIS2 · Non-EU companies
Article 26(1)(b) · jurisdiction · registration
NIS2 does not reach every foreign company with European customers, and that is the first thing worth knowing. It reaches a defined list of digital service providers, and for those it goes further than the GDPR: the designation of a representative establishes jurisdiction, and a registration duty follows. This page runs the test in the order that matters, compares it with the Article 27 test you may already have run, and sets out the four first steps.
Article 26(1)(b)JurisdictionRegistrationAnnex IAnnex II

Read the second row carefully. Under the GDPR you designate where your data subjects are; under NIS2 you designate where you offer the services, and that choice assigns your supervisory authority. The two can be the same country, and keeping them together is usually easier at audit time.
DNS, TLD registries, cloud computing, data centres, content delivery networks, managed services, managed security services, online marketplaces, search engines, social platforms. If nothing you sell appears here, Article 26(1)(b) does not reach you.
Offering means directing the service at customers in the Union, not being technically reachable from there. Euro pricing, EU-specific terms, European sales and support are the indicators.
If the legal entity that provides the service to the customer is established in a Member State, Article 26(3) does not apply to it. Group structures need checking entity by entity.
Annex I means essential entity, proactive supervision, higher ceiling. Annex II means important entity, supervision on evidence. The obligation to designate is the same in both.
Mandate first, registration second, because the registration asks for the representative's details.

| Assumption | What is actually true |
|---|---|
| "We are too small for NIS2" | The size cap does not save the Article 26(1)(b) providers: they are in regardless of headcount or turnover |
| "We host in Frankfurt, so we are established" | Infrastructure is not establishment. Effective activity through stable arrangements is |
| "Our EU reseller covers us" | Only if that entity provides the service in its own name. Otherwise the obligation stays with you |
| "We already have an Article 27 representative" | Different law, different mandate. One does not satisfy the other |
| "We serve only enterprises" | NIS2 does not distinguish consumer from business customers |
| "We will register when someone asks" | Registration is a standing duty, and being unregistered is what draws the first question |
Which legal entity provides which service to European customers, and where each is established. Everything else depends on this.
Each product matched against Annex I and II, with a written note on why it is in or out. Dated, kept with your records.
Name, address, contact points, sector and subsector, Member States served, public IP ranges. The IP ranges take longest to assemble.
Your Article 21 measures, documented well enough to be described to an authority without a project.
Who declares a significant incident, who writes the 24-hour warning, who signs the 72-hour notification. Decide before you need it.
Signed with an entity in the chosen Member State, which is where the correspondence will arrive.
Most companies that need a NIS2 representative also need an Article 27 GDPR representative, because a cloud or platform service that handles customer data is normally a processor reached by Article 3(2). Holding both with the same provider is not a package trick: it removes the two failure modes we see most often.
| Failure mode | What causes it | What removes it |
|---|---|---|
| One mandate lapses quietly | Two providers renewing in different months | One invoice, one expiry date |
| Different addresses published | Notice and registration naming different entities | Consistent identification everywhere |
| Requests bounce between desks | Nobody sure which provider handles what | One desk, both mandates, one log |
| Audit takes weeks | Certificates from two sources, verified differently | Two certificates, one verification page |
Abstract tests are hard to apply to your own structure. These three shapes cover most of what reaches us, and the reasoning transfers.
| Shape | NIS2 | Reasoning |
|---|---|---|
| US company, no EU entity, sells cloud to European businesses | Designate and register | Annex I service, offered in the Union, no establishment there |
| US company with a real Irish subsidiary that contracts with EU customers | No designation for that entity | The providing entity is established in the Union |
| Indian managed service provider selling through an EU reseller in the reseller's own name | Depends on who provides the service | If the reseller provides it, the obligation is the reseller's |
The second row is worth pausing on, because it is where honest analysis saves money. If a European entity in your group genuinely contracts with customers, operates the service and carries the risk, that entity is established in the Union and Article 26(3) does not apply to it. What does not work is a letterbox subsidiary with no staff and no operations: NIS2 borrows the same idea of effective activity through stable arrangements that the GDPR uses, and an empty shell fails it.
The third row is the one that produces arguments with resellers. The test is who provides the service to the customer, in whose name, under whose terms. A reseller invoicing in its own name and carrying the contract is the provider; an agent introducing customers to you is not.
Annex I sectors. Proactive supervision, higher fine ceiling, inspections without a trigger.
Annex II sectors. Supervision on evidence of non-compliance, lower ceiling, same designation duty.
One causing severe operational disruption or financial loss, or affecting others with considerable damage. It starts the 24-hour clock.
The first notification, within 24 hours of becoming aware, saying whether the incident looks malicious or cross-border.
Within 72 hours, with an assessment, severity, impact and indicators of compromise.
The national body that supervises you, determined by the Member State of your representative.
The analysis itself is a compliance artefact. Half a page, dated, kept with your records, and it settles the question the first time an authority or a customer asks.
Each product, whether it falls in Annex I or II, and the reasoning in one sentence each.
With its place of establishment, because that is what decides whether Article 26(3) applies at all.
The list you will also use in the registration.
Designate or not, and if yes, in which Member State and why.
New services and new markets change the answer. Once a year is enough for most companies.
A dated decision made before anyone asked reads very differently from one written after a letter arrived. It costs an hour now and it is the difference between looking organised and looking caught out.
NIS2 has been transposed at different speeds across the Union, which has produced a dangerous impression that nothing is happening. Two things are happening at once, and only one of them is enforcement.
| Pressure | Where it comes from | How fast it arrives |
|---|---|---|
| Supervision | National authorities, proactive for essential entities | Building, state by state |
| Customer questionnaires | Your European clients meeting their own supply chain duty | Already here, in every enterprise deal |
| Procurement gates | Buyers refusing to onboard unregistered providers | Immediate, and silent: you lose without being told why |
| Insurance and audits | Cyber policies and certification bodies asking the same questions | At renewal |
The second and third rows are the reason to act now rather than when the authority writes. A missing designation rarely produces a fine in year one; it routinely produces a lost contract, and nobody sends an email explaining that was the reason.
NIS2 reaches you only if you provide one of the listed services in the Union and the entity providing it is not established there. If that is you, the designation is not a formality: it selects your supervisory authority and it precedes a registration with defined fields. Run the test on paper, write down the conclusion with a date, and decide the Member State deliberately. If nothing you sell appears in Annexes I and II, NIS2 does not apply to you at all, and the only European representative you need is the Article 27 one.


No. It applies to entities providing the services listed in Article 26(1)(b), among them cloud, DNS, CDN, data centres, managed services, marketplaces, search engines and social platforms.
The GDPR designation creates a contact point. The NIS2 designation also determines which Member State has jurisdiction over you, and it comes with a registration duty.
Yes, and it is simpler: two designations, two certificates, one renewal date and one desk.
The one where your representative is established, chosen among the states where you offer the services.
The general size cap does not apply to the Article 26(1)(b) providers. They are caught regardless of size.
No. NIS2 looks at the service you provide, not at the type of customer.
No. Establishment requires effective and real activity through stable arrangements, not servers.
Entity name, address, contact details, sector and subsector, the Member States where you offer services and your public IP ranges.
You do: early warning within 24 hours, notification within 72, final report within a month. The representative receives correspondence, it does not report.
Essential entities face at least €10 million or 2% of worldwide turnover; important entities at least €7 million or 1.4%, whichever is higher.
If that subsidiary is the entity providing the service, Article 26(3) does not apply to it. Check which entity contracts with the customer.
The mandate is signed within 24 hours of the intake call, and registration then follows the national channel.
One designation covers the entity. The registration lists the sectors and the Member States served.
No. You need a representative established in a Member State, which is exactly what this service is.
No. Article 21 requires appropriate measures. Certification may evidence them but is not itself the obligation.
Yes. NIS2 makes management bodies accountable for approving and supervising the measures.
€490 a year for NIS2, €690 for the plan covering NIS2 and Article 27 GDPR together.
Incident reporting, security implementation, audits, certification and legal advice on national transpositions.
Related: the designation explained · the Article 27 test
NIS2 under Article 26(3) and Article 27 GDPR from Europe Services, SE in Prague, each with its own certificate and verification code.
Request this service