Appoint us
Data centre operated by a provider designating a NIS2 representative

REP27 · NIS2 · Representative

Directive (EU) 2022/2555 · article 26(3) · article 27

NIS2 representative: the designation that decides your authority.

Article 26(3) is short and consequential. A provider of DNS, cloud, data centre, CDN, managed services, online marketplaces, search engines or social platforms that is not established in the Union must designate a representative in a Member State where it offers services. Unlike the GDPR, that designation does more than create a contact point: it determines which national authority has jurisdiction over you, and it comes with a registration duty that most companies discover after the fact.

Annex IAnnex IIArticle 26(3)Article 27 registrationJurisdiction

Request this service   Ask a question

Who has to designate

Which providers outside the Union must designate a NIS2 representative
Which providers outside the Union must designate a NIS2 representative

Notice what the list is not. It is not every company with European customers, and it is not decided by turnover. NIS2 works by sector: if the service you sell appears above and you have no establishment in the Union, Article 26(3) applies to you whatever your size.

The five steps, in order

The five steps to designate a NIS2 representative and register the entity
The five steps to designate a NIS2 representative and register the entity
  1. Establish the annex

    Annex I lists essential sectors, including DNS, TLD registries, cloud computing, data centres, content delivery networks and managed service providers. Annex II covers important entities, including online marketplaces, search engines and social platforms. The supervision regime differs between the two.

  2. Choose the Member State

    Article 26(3) says the representative must be established in one of the Member States where the services are offered. That choice is not administrative: jurisdiction over you follows it.

  3. Sign the mandate

    A written designation with an entity established in that Member State, accepting the tasks: receiving correspondence, cooperating with the authority, holding documentation available.

  4. Register under Article 27

    Entity name, address, contact details, sector, Member States served and public IP ranges, submitted to the competent authority through the national channel.

  5. Stay reachable and current

    Changes to the registered information must be notified, in most transpositions within three months.

What the representative does, and what it does not

It receives

Correspondence, questions and formal requests from the competent authority and the national CSIRT, at an address inside the Union.

It holds

The documentation you provide at the authority's disposal, so a request does not depend on a time zone or a holiday.

It cooperates

Procedurally, within the deadlines, in the language the request arrives in. This is what prevents a technical question becoming a compliance finding.

It does not report incidents

The early warning within 24 hours and the incident notification within 72 remain your duty. Nobody can perform them for you: they need facts only you have.

It does not implement Article 21

Risk management measures, supply chain security, encryption and incident handling stay with your organisation.

It does not absorb liability

The entity remains responsible. Designation makes you reachable and identifiable, which is exactly what the directive wanted.

Choosing the Member State

This is the decision people take casually and regret. The representative's Member State becomes your supervisory jurisdiction, so it decides who audits you, in which language, and under which national transposition.

ConsiderationWhy it mattersPractical note
Language of the authorityRequests and deadlines arrive in itA desk covering that language avoids translation delays
National transpositionDirective, not regulation: details differRegistration channels and deadlines vary between states
Where you actually sellArticle 26(3) requires services offered thereYou cannot pick a state where you have no customers
Supervisory workloadSome authorities are more active than othersActivity is not a reason to avoid a state, but it is a fact to know
Consistency with your other mandatesYou may also hold an Article 27 GDPR designationKeeping both in one country simplifies audits and renewals
Ours is the Czech Republic, which is where Europe Services, SE has been established since 2018. It is a Member State with a functioning authority, a straightforward registration channel and no reputation for either laxity or theatre.

What happens if you do not designate

NIS2 fines are set by sector rather than by breach type, and the absence of a representative is not a technicality: it is the thing that makes an entity unreachable, which is precisely what the directive set out to fix.

AspectEssential entities (Annex I)Important entities (Annex II)
Maximum fineAt least €10 million or 2% of worldwide turnover, whichever is higherAt least €7 million or 1.4% of worldwide turnover, whichever is higher
SupervisionProactive: inspections and audits without a triggerReactive: after evidence of non-compliance
Management accountabilityManagement bodies can be held personally liableSame principle, applied on evidence
Other measuresBinding instructions, suspension of certification, temporary bans on management rolesInstructions and orders
Practical effect of no representativeNo jurisdiction assigned, no registration, entity treated as unregisteredThe same

What we provide

  1. The mandate within 24 hours

    Signed by Europe Services, SE, Na Čečeličce 425/4, Praha 5, IČO 03571785, after a short intake call to confirm which annex applies to your services.

  2. The registration pack

    The data the authority asks for under Article 27, assembled with you: sector, subsector, Member States served, public IP ranges, contact points.

  3. A certificate with a verification code

    Checkable by a client, an auditor or the authority without contacting us, which is what enterprise procurement asks for.

  4. A desk that answers

    Correspondence logged the day it arrives, answered procedurally and forwarded to you the same working day, in eight languages.

  5. Documentation held

    What you give us stays available to the authority for as long as the mandate runs.

What we do not do, stated before you buy: we do not report your incidents, we do not implement your Article 21 measures, we do not run your risk assessments and we do not give legal advice on national transpositions. Those belong to your team and, where needed, to a law firm in the Member State concerned.

How NIS2 differs from the law you already know

Most companies arriving at NIS2 have already been through the GDPR, and they bring habits that do not transfer. Four of them cause almost all the confusion.

Habit from the GDPRWhat NIS2 does instead
One regulation, identical in every countryA directive, transposed nationally, with different registration channels and deadlines
Applies by activity, to almost everyoneApplies by sector, to a defined list of entities
The representative is a contact pointThe representative determines which Member State supervises you
No registry of representatives anywhereA registration duty with defined fields, including IP ranges
Enforcement follows complaintsEssential entities face proactive supervision without a trigger

The practical consequence is that NIS2 rewards deciding deliberately. Under the GDPR the choice of Member State barely matters once your data subjects are covered. Under NIS2 it selects your regulator, its language, its transposition and its supervisory practice, and it is awkward to change later because the registration follows it.

What an intake call covers

We do not sign a NIS2 mandate from a form alone, because the annex question decides everything downstream and it is answered by looking at what you actually sell.

  1. Your services, one by one

    Which are provided as cloud computing, data centre, CDN, managed or managed security services, and which are something else entirely.

  2. Which legal entity provides them

    Group structures often have an EU entity contracting with European customers, in which case Article 26(3) does not apply to it.

  3. Where you offer them

    The list of Member States, which both constrains the choice of representative and appears in the registration.

  4. What you already hold

    An existing Article 27 GDPR designation, a UK representative, a GPSR responsible person. Aligning renewal dates is easier now than later.

  5. What you do not have yet

    Usually the IP ranges and a written incident procedure. Both are yours to produce, and knowing it on day one saves the timetable.

The short version

If you provide DNS, cloud computing, data centre services, a content delivery network, managed or managed security services, an online marketplace, a search engine or a social platform in the Union, and the entity providing it is not established there, Article 26(3) requires a representative and Article 27 requires a registration. The designation decides which Member State supervises you, so it is a decision rather than a formality. Everything else about NIS2 — the security measures, the 24 and 72 hour reporting, the supply chain work, the management accountability — stays inside your organisation and always will.

Working out which annex of NIS2 a digital service falls under
Working out which annex of NIS2 a digital service falls under
Desk receiving correspondence from a national NIS2 authority

Questions we are actually asked

Is a NIS2 representative mandatory?

For the providers listed in Article 26(1)(b) that are not established in the Union, yes. It is not optional and there is no size threshold.

Which services are covered?

DNS providers, TLD name registries, cloud computing, data centre services, content delivery networks, managed service providers and managed security providers under Annex I; online marketplaces, search engines and social networking platforms under Annex II.

Does it replace the Article 27 GDPR representative?

No. They come from different laws and cover different things. A company can need both, and each requires its own written mandate.

Which Member State should we choose?

One where you offer services. That state becomes your supervisory jurisdiction, so choose it deliberately rather than alphabetically.

Does the representative report incidents for us?

No. The 24-hour early warning and the 72-hour notification stay with the entity, because they depend on facts only you hold.

What is the Article 27 registration?

A submission to the competent authority with your entity name, address, contact details, sector, the Member States where you offer services and your public IP ranges.

How long do we have to notify changes?

Most transpositions give three months from the change. Check the state you registered in, because NIS2 is a directive and details differ.

What are the fines?

For essential entities at least €10 million or 2% of worldwide turnover; for important entities at least €7 million or 1.4%, whichever is higher in each case.

Are small companies exempt?

The size-cap rule exempts many entities, but Article 26(1)(b) providers are caught regardless of size when they offer the listed services in the Union.

We have an EU subsidiary. Do we still designate?

If the entity providing the service is established in the Union, Article 26(3) does not apply to it. Check which legal entity actually provides the service.

Can the same company act as our NIS2 and GDPR representative?

Yes, and it is simpler: two mandates, two certificates, one invoice and one renewal date.

How fast is the designation?

The mandate is signed within 24 hours of the intake call. The registration takes as long as the national channel requires.

Does the representative need technical staff?

It needs to receive, log, hold documentation and cooperate. Technical security work is yours, and mixing the two roles helps nobody.

What if we serve several Member States?

You register in the one where your representative is established. The registration itself lists every state where you offer services.

Does NIS2 apply to us if our customers are businesses?

Yes. NIS2 does not distinguish between consumer and business customers; it looks at the service you provide.

What does it cost?

€490 a year for the NIS2 designation, €690 for the plan covering NIS2 and the Article 27 GDPR representative together.

Do you help with the registration form?

We assemble the data with you and tell you exactly what the authority asks for. The submission is made in your name.

What happens on the day the authority writes?

We log it, acknowledge within the deadline in the language it arrived in, and forward it to you the same working day with a summary in English.

Related: how it differs from Article 27 · the registration duty

Designated and reachable in the Union

Europe Services, SE in Prague as your NIS2 representative under Article 26(3), with the registration pack, a verifiable certificate and a desk that answers in eight languages.

Request this service