
Annex I · cloud computing · data centre services
Cloud computing services and data centre services are named in Annex I of NIS2, which puts them among the essential entities: the tier with proactive supervision, the higher fine ceiling and no waiting for something to go wrong. If the entity providing the service is not established in the Union, Article 26(3) requires a representative, and that designation decides which national authority supervises you. This page is written for the person who has to work out whether their product is in, and what to do first.
IaaSPaaSSaaSData centreManaged servicesAnnex I

The right-hand column is not a list of exemptions from security law. It is a list of cases where this particular obligation does not bite, usually because there is no service offered in the Union or because the provider is already established there.

| What you sell | In Annex I? | Why |
|---|---|---|
| Infrastructure as a service | Yes | Cloud computing service in the directive's own terms |
| Platform as a service | Yes | Same category, scalable and elastic resources on demand |
| Software as a service | Yes | Included where it is provided as a cloud computing service |
| Colocation and data centre space | Yes | Data centre services are listed separately in Annex I |
| Managed services and managed security | Yes | Both appear in Annex I, added precisely because of supply chain risk |
| On-premise software licence | No | No service provided by you; the customer runs it |
| Professional services and consultancy | No | Unless bundled with a managed service component |
| Reselling another provider's cloud | Depends | Who provides the service to the customer decides it |
Buying a representative solves the reachability problem and nothing else. These duties remain with the entity, and a provider who tells you otherwise is selling you a story.
Risk analysis, incident handling, business continuity, supply chain security, vulnerability handling and disclosure, cryptography, access control, multi-factor authentication. All of it internal work.
Early warning within 24 hours of becoming aware of a significant incident, notification within 72 hours, final report within a month. Deadlines you cannot delegate.
Security of your own suppliers and service providers, assessed and documented, because Annex I entities are judged on it.
Management bodies approve the measures and can be held personally responsible. Training is expressly required.
Keeping the registered data current, including IP ranges, which change more often than anyone plans for.
Map which of your services fall in Annex I, and which legal entity actually provides each one to European customers.
Choose the Member State. Where you have real customers, whose language your desk can handle, and where your other mandates already sit if you have them.
Sign the mandate. Registration asks for the representative's details, so this comes first.
Assemble the registration data: sector, subsector, Member States served, public IP ranges, contact points for security matters.
Keep the file current and answer what arrives. Most supervisory friction comes from silence, not from imperfect answers.
Check whether Article 27 GDPR also reaches you. A cloud provider with European customers usually processes personal data as a processor, which is a separate designation.
Five that come up in almost every intake call, answered here so the call can be about your architecture instead.
| Question | Short answer |
|---|---|
| Does hosting in an EU region make us established? | No. Infrastructure is not establishment; effective activity through stable arrangements is |
| Does a reseller in Europe cover us? | Only if the reseller provides the service to the customer in its own name |
| We only serve businesses. Are we out? | No. NIS2 does not distinguish consumer from business customers |
| Do we need one representative per Member State? | No. One, in a state where you offer services |
| Can you handle our incident notifications? | No, and nobody honest will. They depend on facts only your team has |
Article 21 lists the measures, and for a cloud provider they are read strictly, because your customers depend on them. This is the shortest honest summary of what your own team has to own.
| Measure | What it means for a cloud provider |
|---|---|
| Risk analysis and information system security policies | Documented, approved by management, reviewed on a stated cadence |
| Incident handling | Detection, triage, escalation and the reporting chain with named people |
| Business continuity and crisis management | Backups, restore testing, failover, and a plan somebody has actually rehearsed |
| Supply chain security | Assessment of your own providers, including the ones customers never see |
| Vulnerability handling and disclosure | A published route for researchers and a defined patch timeline |
| Cryptography and encryption policy | At rest and in transit, with key management written down |
| Access control and asset management | Least privilege, joiners and leavers, inventory that matches reality |
| Multi-factor authentication | For administrative access above all, and for customer accounts where relevant |
A representative does not touch any of that. What it does is make sure that when an authority asks about it, the question reaches a person in the Union who answers within the deadline, in the right language, with the documentation you have provided.
Article 26(3): the entity falls under the jurisdiction of the Member State where its representative is established.
That state's authority supervises you, in its language, under its transposition, with its own registration channel and deadlines.
It has to be a state where you actually offer the services. You cannot choose one for convenience alone.
Align it with your other mandates. One country for NIS2 and Article 27 means one set of correspondence habits and one audit story.
Possible, but it means a new mandate and an updated registration. Deciding once, deliberately, is cheaper.
The Czech Republic, where Europe Services, SE has been established since 2018, with a straightforward registration channel.
Infrastructure, platform, software as a service, colocation, managed and managed security. Write down which is which and why, and date the note.
If a European entity in the group contracts with the customer and operates the service, Article 26(3) does not apply to that entity.
It is the single slowest field in the registration and the only one that depends on someone outside compliance.
It becomes your supervisory jurisdiction. Language, transposition and consistency with your other mandates all count.
In that order, because the registration asks for the representative's details.
Everything after that is ordinary operations: keep the registration current, answer what arrives within the deadline, and keep the security file in a state where it can be described without a project.
NIS2 does not stop at your own compliance. Because supply chain security is one of the Article 21 measures, your European customers are now obliged to ask about you, and the questions arrive in a predictable order.
| What they ask | What they want to see | What to have ready |
|---|---|---|
| Are you in scope of NIS2? | A clear yes or no with the annex named | Your dated service analysis |
| Who is your representative and where? | An entity, an address, a Member State | The mandate and a verifiable certificate |
| Are you registered? | The reference the authority returned | The confirmation, stored with the mandate |
| How do you report incidents to us? | A named contact and a timeline | Your incident procedure, in writing |
| What are your Article 21 measures? | A description, not a certificate | The security file, kept current |
Providers who can answer all five in one email win procurement cycles that others spend a month on. That is the commercial argument for doing this properly, and it is a better one than the fines.
Cloud computing and data centre services are Annex I, which makes you an essential entity with proactive supervision. If the entity contracting with your European customers is not established in the Union, designate a representative in a Member State where you sell, register the entity under Article 27, and keep the public IP ranges current. Everything else — the Article 21 measures, the 24 and 72 hour reporting, the supply chain assessments — is your team's work and cannot be bought from anyone.


Cloud computing services and data centre services are named in Annex I, which makes providers essential entities, subject to proactive supervision.
No. Establishment means effective and real activity through stable arrangements. Servers are infrastructure, not an establishment.
It is covered where it is provided as a cloud computing service, which is the normal case for a multi-tenant hosted product.
Yes. Managed services and managed security services were added to Annex I precisely because of supply chain risk.
One where you actually offer services. That state becomes your supervisory jurisdiction under Article 26(3).
No. The 24-hour early warning and the 72-hour notification remain the entity's duty and depend on facts only your team holds.
Yes. Article 27 requires the entity's details, sector, Member States served and public IP ranges to be submitted to the competent authority.
Everything in the registration, including IP ranges. Most transpositions require notification of changes within three months.
The general size cap does not rescue the providers listed in Article 26(1)(b): they are caught regardless of size.
Usually yes. A cloud provider handling customer data is normally a processor reached by Article 3(2) GDPR, which is a separate designation.
Only if that entity is established in the Union and signs the mandate accepting the tasks. A commercial relationship is not an appointment.
It is recorded as a failure to cooperate, which is heavier than the question that started it and easier to prove.
No. It requires risk management measures appropriate to the risk. Certification can help demonstrate them but is not the obligation.
For essential entities, at least €10 million or 2% of worldwide annual turnover, whichever is higher.
Yes. NIS2 makes management bodies accountable for approving and overseeing the measures, with training expressly required.
The mandate is signed within 24 hours of the intake call. Registration then follows the national channel's own timing.
€490 a year for the NIS2 designation, €690 for the plan that also covers the Article 27 GDPR representative.
Incident reporting, Article 21 implementation, penetration testing, certification and legal advice on national transpositions.
Related: the designation explained · what registration asks for
Europe Services, SE in Prague under Article 26(3), with the registration pack, a verifiable certificate and correspondence answered in eight languages.
Request this service