Appoint us
Data centre racks operated by a cloud provider under NIS2 Annex I

REP27 · NIS2 · Cloud

Annex I · cloud computing · data centre services

NIS2 for cloud providers, without the guesswork.

Cloud computing services and data centre services are named in Annex I of NIS2, which puts them among the essential entities: the tier with proactive supervision, the higher fine ceiling and no waiting for something to go wrong. If the entity providing the service is not established in the Union, Article 26(3) requires a representative, and that designation decides which national authority supervises you. This page is written for the person who has to work out whether their product is in, and what to do first.

IaaSPaaSSaaSData centreManaged servicesAnnex I

Request this service   Ask a question

Which cloud services are inside

Cloud services inside the NIS2 representative obligation and cases with a different answer
Cloud services inside the NIS2 representative obligation and cases with a different answer

The right-hand column is not a list of exemptions from security law. It is a list of cases where this particular obligation does not bite, usually because there is no service offered in the Union or because the provider is already established there.

What designation changes

The four consequences of designating a NIS2 representative for a cloud provider
The four consequences of designating a NIS2 representative for a cloud provider
The first one is the important one and it is easy to miss: under Article 26(3) the entity falls under the jurisdiction of the Member State where the representative is established. You are not appointing a mailbox, you are choosing your regulator.

Cloud models and the answer for each

What you sellIn Annex I?Why
Infrastructure as a serviceYesCloud computing service in the directive's own terms
Platform as a serviceYesSame category, scalable and elastic resources on demand
Software as a serviceYesIncluded where it is provided as a cloud computing service
Colocation and data centre spaceYesData centre services are listed separately in Annex I
Managed services and managed securityYesBoth appear in Annex I, added precisely because of supply chain risk
On-premise software licenceNoNo service provided by you; the customer runs it
Professional services and consultancyNoUnless bundled with a managed service component
Reselling another provider's cloudDependsWho provides the service to the customer decides it

What stays yours, whatever you designate

Buying a representative solves the reachability problem and nothing else. These duties remain with the entity, and a provider who tells you otherwise is selling you a story.

  1. Article 21 measures

    Risk analysis, incident handling, business continuity, supply chain security, vulnerability handling and disclosure, cryptography, access control, multi-factor authentication. All of it internal work.

  2. Incident reporting

    Early warning within 24 hours of becoming aware of a significant incident, notification within 72 hours, final report within a month. Deadlines you cannot delegate.

  3. Supply chain

    Security of your own suppliers and service providers, assessed and documented, because Annex I entities are judged on it.

  4. Management accountability

    Management bodies approve the measures and can be held personally responsible. Training is expressly required.

  5. Registration accuracy

    Keeping the registered data current, including IP ranges, which change more often than anyone plans for.

The order of work for a provider outside the Union

Week one

Map which of your services fall in Annex I, and which legal entity actually provides each one to European customers.

Week one

Choose the Member State. Where you have real customers, whose language your desk can handle, and where your other mandates already sit if you have them.

Within 24 hours of the call

Sign the mandate. Registration asks for the representative's details, so this comes first.

Week two

Assemble the registration data: sector, subsector, Member States served, public IP ranges, contact points for security matters.

Ongoing

Keep the file current and answer what arrives. Most supervisory friction comes from silence, not from imperfect answers.

In parallel

Check whether Article 27 GDPR also reaches you. A cloud provider with European customers usually processes personal data as a processor, which is a separate designation.

Questions cloud providers ask us first

Five that come up in almost every intake call, answered here so the call can be about your architecture instead.

QuestionShort answer
Does hosting in an EU region make us established?No. Infrastructure is not establishment; effective activity through stable arrangements is
Does a reseller in Europe cover us?Only if the reseller provides the service to the customer in its own name
We only serve businesses. Are we out?No. NIS2 does not distinguish consumer from business customers
Do we need one representative per Member State?No. One, in a state where you offer services
Can you handle our incident notifications?No, and nobody honest will. They depend on facts only your team has

The security duties nobody can take off your hands

Article 21 lists the measures, and for a cloud provider they are read strictly, because your customers depend on them. This is the shortest honest summary of what your own team has to own.

MeasureWhat it means for a cloud provider
Risk analysis and information system security policiesDocumented, approved by management, reviewed on a stated cadence
Incident handlingDetection, triage, escalation and the reporting chain with named people
Business continuity and crisis managementBackups, restore testing, failover, and a plan somebody has actually rehearsed
Supply chain securityAssessment of your own providers, including the ones customers never see
Vulnerability handling and disclosureA published route for researchers and a defined patch timeline
Cryptography and encryption policyAt rest and in transit, with key management written down
Access control and asset managementLeast privilege, joiners and leavers, inventory that matches reality
Multi-factor authenticationFor administrative access above all, and for customer accounts where relevant

A representative does not touch any of that. What it does is make sure that when an authority asks about it, the question reaches a person in the Union who answers within the deadline, in the right language, with the documentation you have provided.

Jurisdiction, chosen rather than inherited

The rule

Article 26(3): the entity falls under the jurisdiction of the Member State where its representative is established.

Why it matters

That state's authority supervises you, in its language, under its transposition, with its own registration channel and deadlines.

The constraint

It has to be a state where you actually offer the services. You cannot choose one for convenience alone.

What we suggest

Align it with your other mandates. One country for NIS2 and Article 27 means one set of correspondence habits and one audit story.

Changing later

Possible, but it means a new mandate and an updated registration. Deciding once, deliberately, is cheaper.

Ours

The Czech Republic, where Europe Services, SE has been established since 2018, with a straightforward registration channel.

What a cloud provider should do this week

  1. List your services against Annex I

    Infrastructure, platform, software as a service, colocation, managed and managed security. Write down which is which and why, and date the note.

  2. Identify the contracting entity per service

    If a European entity in the group contracts with the customer and operates the service, Article 26(3) does not apply to that entity.

  3. Ask engineering for the public IP ranges now

    It is the single slowest field in the registration and the only one that depends on someone outside compliance.

  4. Choose the Member State deliberately

    It becomes your supervisory jurisdiction. Language, transposition and consistency with your other mandates all count.

  5. Sign the mandate, then register

    In that order, because the registration asks for the representative's details.

Everything after that is ordinary operations: keep the registration current, answer what arrives within the deadline, and keep the security file in a state where it can be described without a project.

Three questions your customers will ask you

NIS2 does not stop at your own compliance. Because supply chain security is one of the Article 21 measures, your European customers are now obliged to ask about you, and the questions arrive in a predictable order.

What they askWhat they want to seeWhat to have ready
Are you in scope of NIS2?A clear yes or no with the annex namedYour dated service analysis
Who is your representative and where?An entity, an address, a Member StateThe mandate and a verifiable certificate
Are you registered?The reference the authority returnedThe confirmation, stored with the mandate
How do you report incidents to us?A named contact and a timelineYour incident procedure, in writing
What are your Article 21 measures?A description, not a certificateThe security file, kept current

Providers who can answer all five in one email win procurement cycles that others spend a month on. That is the commercial argument for doing this properly, and it is a better one than the fines.

The short version for a cloud provider

Cloud computing and data centre services are Annex I, which makes you an essential entity with proactive supervision. If the entity contracting with your European customers is not established in the Union, designate a representative in a Member State where you sell, register the entity under Article 27, and keep the public IP ranges current. Everything else — the Article 21 measures, the 24 and 72 hour reporting, the supply chain assessments — is your team's work and cannot be bought from anyone.

Reviewing which cloud services fall inside the NIS2 obligation
Reviewing which cloud services fall inside the NIS2 obligation
Cloud provider assembling its NIS2 registration data

Questions we are actually asked

Are cloud providers really in scope of NIS2?

Cloud computing services and data centre services are named in Annex I, which makes providers essential entities, subject to proactive supervision.

Does an EU hosting region make us established in the Union?

No. Establishment means effective and real activity through stable arrangements. Servers are infrastructure, not an establishment.

What about software as a service?

It is covered where it is provided as a cloud computing service, which is the normal case for a multi-tenant hosted product.

Do managed service providers count?

Yes. Managed services and managed security services were added to Annex I precisely because of supply chain risk.

Which Member State should a cloud provider choose?

One where you actually offer services. That state becomes your supervisory jurisdiction under Article 26(3).

Does the representative handle incident reporting?

No. The 24-hour early warning and the 72-hour notification remain the entity's duty and depend on facts only your team holds.

Is registration separate from designation?

Yes. Article 27 requires the entity's details, sector, Member States served and public IP ranges to be submitted to the competent authority.

What data do we have to keep current?

Everything in the registration, including IP ranges. Most transpositions require notification of changes within three months.

Are we exempt if we are small?

The general size cap does not rescue the providers listed in Article 26(1)(b): they are caught regardless of size.

Do we need this as well as an Article 27 GDPR representative?

Usually yes. A cloud provider handling customer data is normally a processor reached by Article 3(2) GDPR, which is a separate designation.

Can we appoint our EU reseller?

Only if that entity is established in the Union and signs the mandate accepting the tasks. A commercial relationship is not an appointment.

What happens if an authority writes and nobody answers?

It is recorded as a failure to cooperate, which is heavier than the question that started it and easier to prove.

Does NIS2 require certification?

No. It requires risk management measures appropriate to the risk. Certification can help demonstrate them but is not the obligation.

What are the maximum fines?

For essential entities, at least €10 million or 2% of worldwide annual turnover, whichever is higher.

Can management be held personally responsible?

Yes. NIS2 makes management bodies accountable for approving and overseeing the measures, with training expressly required.

How long does the designation take?

The mandate is signed within 24 hours of the intake call. Registration then follows the national channel's own timing.

What does it cost?

€490 a year for the NIS2 designation, €690 for the plan that also covers the Article 27 GDPR representative.

What is explicitly not included?

Incident reporting, Article 21 implementation, penetration testing, certification and legal advice on national transpositions.

Related: the designation explained · what registration asks for

A representative in the Union for your cloud service

Europe Services, SE in Prague under Article 26(3), with the registration pack, a verifiable certificate and correspondence answered in eight languages.

Request this service