
Directive (EU) 2022/2555 · article 26(3) · article 27
Article 26(3) is short and consequential. A provider of DNS, cloud, data centre, CDN, managed services, online marketplaces, search engines or social platforms that is not established in the Union must designate a representative in a Member State where it offers services. Unlike the GDPR, that designation does more than create a contact point: it determines which national authority has jurisdiction over you, and it comes with a registration duty that most companies discover after the fact.
Annex IAnnex IIArticle 26(3)Article 27 registrationJurisdiction

Notice what the list is not. It is not every company with European customers, and it is not decided by turnover. NIS2 works by sector: if the service you sell appears above and you have no establishment in the Union, Article 26(3) applies to you whatever your size.

Annex I lists essential sectors, including DNS, TLD registries, cloud computing, data centres, content delivery networks and managed service providers. Annex II covers important entities, including online marketplaces, search engines and social platforms. The supervision regime differs between the two.
Article 26(3) says the representative must be established in one of the Member States where the services are offered. That choice is not administrative: jurisdiction over you follows it.
A written designation with an entity established in that Member State, accepting the tasks: receiving correspondence, cooperating with the authority, holding documentation available.
Entity name, address, contact details, sector, Member States served and public IP ranges, submitted to the competent authority through the national channel.
Changes to the registered information must be notified, in most transpositions within three months.
Correspondence, questions and formal requests from the competent authority and the national CSIRT, at an address inside the Union.
The documentation you provide at the authority's disposal, so a request does not depend on a time zone or a holiday.
Procedurally, within the deadlines, in the language the request arrives in. This is what prevents a technical question becoming a compliance finding.
The early warning within 24 hours and the incident notification within 72 remain your duty. Nobody can perform them for you: they need facts only you have.
Risk management measures, supply chain security, encryption and incident handling stay with your organisation.
The entity remains responsible. Designation makes you reachable and identifiable, which is exactly what the directive wanted.
This is the decision people take casually and regret. The representative's Member State becomes your supervisory jurisdiction, so it decides who audits you, in which language, and under which national transposition.
| Consideration | Why it matters | Practical note |
|---|---|---|
| Language of the authority | Requests and deadlines arrive in it | A desk covering that language avoids translation delays |
| National transposition | Directive, not regulation: details differ | Registration channels and deadlines vary between states |
| Where you actually sell | Article 26(3) requires services offered there | You cannot pick a state where you have no customers |
| Supervisory workload | Some authorities are more active than others | Activity is not a reason to avoid a state, but it is a fact to know |
| Consistency with your other mandates | You may also hold an Article 27 GDPR designation | Keeping both in one country simplifies audits and renewals |
NIS2 fines are set by sector rather than by breach type, and the absence of a representative is not a technicality: it is the thing that makes an entity unreachable, which is precisely what the directive set out to fix.
| Aspect | Essential entities (Annex I) | Important entities (Annex II) |
|---|---|---|
| Maximum fine | At least €10 million or 2% of worldwide turnover, whichever is higher | At least €7 million or 1.4% of worldwide turnover, whichever is higher |
| Supervision | Proactive: inspections and audits without a trigger | Reactive: after evidence of non-compliance |
| Management accountability | Management bodies can be held personally liable | Same principle, applied on evidence |
| Other measures | Binding instructions, suspension of certification, temporary bans on management roles | Instructions and orders |
| Practical effect of no representative | No jurisdiction assigned, no registration, entity treated as unregistered | The same |
Signed by Europe Services, SE, Na Čečeličce 425/4, Praha 5, IČO 03571785, after a short intake call to confirm which annex applies to your services.
The data the authority asks for under Article 27, assembled with you: sector, subsector, Member States served, public IP ranges, contact points.
Checkable by a client, an auditor or the authority without contacting us, which is what enterprise procurement asks for.
Correspondence logged the day it arrives, answered procedurally and forwarded to you the same working day, in eight languages.
What you give us stays available to the authority for as long as the mandate runs.
What we do not do, stated before you buy: we do not report your incidents, we do not implement your Article 21 measures, we do not run your risk assessments and we do not give legal advice on national transpositions. Those belong to your team and, where needed, to a law firm in the Member State concerned.
Most companies arriving at NIS2 have already been through the GDPR, and they bring habits that do not transfer. Four of them cause almost all the confusion.
| Habit from the GDPR | What NIS2 does instead |
|---|---|
| One regulation, identical in every country | A directive, transposed nationally, with different registration channels and deadlines |
| Applies by activity, to almost everyone | Applies by sector, to a defined list of entities |
| The representative is a contact point | The representative determines which Member State supervises you |
| No registry of representatives anywhere | A registration duty with defined fields, including IP ranges |
| Enforcement follows complaints | Essential entities face proactive supervision without a trigger |
The practical consequence is that NIS2 rewards deciding deliberately. Under the GDPR the choice of Member State barely matters once your data subjects are covered. Under NIS2 it selects your regulator, its language, its transposition and its supervisory practice, and it is awkward to change later because the registration follows it.
We do not sign a NIS2 mandate from a form alone, because the annex question decides everything downstream and it is answered by looking at what you actually sell.
Which are provided as cloud computing, data centre, CDN, managed or managed security services, and which are something else entirely.
Group structures often have an EU entity contracting with European customers, in which case Article 26(3) does not apply to it.
The list of Member States, which both constrains the choice of representative and appears in the registration.
An existing Article 27 GDPR designation, a UK representative, a GPSR responsible person. Aligning renewal dates is easier now than later.
Usually the IP ranges and a written incident procedure. Both are yours to produce, and knowing it on day one saves the timetable.
If you provide DNS, cloud computing, data centre services, a content delivery network, managed or managed security services, an online marketplace, a search engine or a social platform in the Union, and the entity providing it is not established there, Article 26(3) requires a representative and Article 27 requires a registration. The designation decides which Member State supervises you, so it is a decision rather than a formality. Everything else about NIS2 — the security measures, the 24 and 72 hour reporting, the supply chain work, the management accountability — stays inside your organisation and always will.


For the providers listed in Article 26(1)(b) that are not established in the Union, yes. It is not optional and there is no size threshold.
DNS providers, TLD name registries, cloud computing, data centre services, content delivery networks, managed service providers and managed security providers under Annex I; online marketplaces, search engines and social networking platforms under Annex II.
No. They come from different laws and cover different things. A company can need both, and each requires its own written mandate.
One where you offer services. That state becomes your supervisory jurisdiction, so choose it deliberately rather than alphabetically.
No. The 24-hour early warning and the 72-hour notification stay with the entity, because they depend on facts only you hold.
A submission to the competent authority with your entity name, address, contact details, sector, the Member States where you offer services and your public IP ranges.
Most transpositions give three months from the change. Check the state you registered in, because NIS2 is a directive and details differ.
For essential entities at least €10 million or 2% of worldwide turnover; for important entities at least €7 million or 1.4%, whichever is higher in each case.
The size-cap rule exempts many entities, but Article 26(1)(b) providers are caught regardless of size when they offer the listed services in the Union.
If the entity providing the service is established in the Union, Article 26(3) does not apply to it. Check which legal entity actually provides the service.
Yes, and it is simpler: two mandates, two certificates, one invoice and one renewal date.
The mandate is signed within 24 hours of the intake call. The registration takes as long as the national channel requires.
It needs to receive, log, hold documentation and cooperate. Technical security work is yours, and mixing the two roles helps nobody.
You register in the one where your representative is established. The registration itself lists every state where you offer services.
Yes. NIS2 does not distinguish between consumer and business customers; it looks at the service you provide.
€490 a year for the NIS2 designation, €690 for the plan covering NIS2 and the Article 27 GDPR representative together.
We assemble the data with you and tell you exactly what the authority asks for. The submission is made in your name.
We log it, acknowledge within the deadline in the language it arrived in, and forward it to you the same working day with a summary in English.
Related: how it differs from Article 27 · the registration duty
Europe Services, SE in Prague as your NIS2 representative under Article 26(3), with the registration pack, a verifiable certificate and a desk that answers in eight languages.
Request this service