CHAPTER V
NIS2 Article 26: Jurisdiction and territoriality
1. Entities falling within the scope of this Directive shall be considered to fall under the jurisdiction of the Member State in which they are established, except in the case of:
(a) providers of public electronic communications networks or providers of publicly available electronic communications services, which shall be considered to fall under the jurisdiction of the Member State in which they provide their services;
(b) DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines or of social networking services platforms, which shall be considered to fall under the jurisdiction of the Member State in which they have their main establishment in the Union under paragraph 2;
(c) public administration entities, which shall be considered to fall under the jurisdiction of the Member State which established them.
2. For the purposes of this Directive, an entity as referred to in paragraph 1, point (b), shall be considered to have its main establishment in the Union in the Member State where the decisions related to the cybersecurity risk-management measures are predominantly taken. If such a Member State cannot be determined or if such decisions are not taken in the Union, the main establishment shall be considered to be in the Member State where cybersecurity operations are carried out. If such a Member State cannot be determined, the main establishment shall be considered to be in the Member State where the entity concerned has the establishment with the highest number of employees in the Union.
3. If an entity as referred to in paragraph 1, point (b), is not established in the Union, but offers services within the Union, it shall designate a representative in the Union. The representative shall be established in one of those Member States where the services are offered. Such an entity shall be considered to fall under the jurisdiction of the Member State where the representative is established. In the absence of a representative in the Union designated under this paragraph, any Member State in which the entity provides services may take legal actions against the entity for the infringement of this Directive.
4. The designation of a representative by an entity as referred to in paragraph 1, point (b), shall be without prejudice to legal actions, which could be initiated against the entity itself.
5. Member States that have received a request for mutual assistance in relation to an entity as referred to in paragraph 1, point (b), may, within the limits of that request, take appropriate supervisory and enforcement measures in relation to the entity concerned that provides services or which has a network and information system on their territory.
What this article means in practice
Written by Engage Compliance. The text above is the article itself, reproduced from its official source and unchanged. Everything in this section is ours, and last read against the current text on 2026-09-07.
Article 26 decides which Member State has jurisdiction over you, and paragraph 3 is where the representative comes in: a digital-infrastructure or digital-provider entity not established in the Union but offering services in it designates a representative there, and that designation is what fixes its jurisdiction. Without one, any Member State where you provide services can act against you.
Who it binds
- Only the entities listed in Article 26(1)(b): DNS service providers, TLD name registries, domain name registration services, cloud computing providers, data centre providers, content delivery networks, managed service providers, managed security service providers, online marketplaces, online search engines and social networking platforms.
- It does not reach the rest of the Directive's scope. Most NIS2 entities fall under the jurisdiction of the Member State where they are established (Article 26(1)), and the representative duty in Article 26(3) is written only for the point (b) list.
- Providers of public electronic communications networks or services fall under the jurisdiction of each Member State where they provide services (Article 26(1)(a)), with no representative mechanism.
- This is a Directive, so what binds you is your Member State's transposing law rather than this text directly.
What it makes somebody do
- You, the entity. Designate a representative in the Union, established in one of the Member States where the services are offered (Article 26(3)).
- You, the entity. Work out your main establishment first, because Article 26(2) decides it by where cybersecurity risk-management decisions are predominantly taken, then by where cybersecurity operations are carried out, then by headcount. Only if none of those lands in the Union does Article 26(3) engage.
- The representative. Be the point at which jurisdiction attaches. Article 26(3) makes the entity fall under the jurisdiction of the Member State where the representative is established.
What it does not say
- It does not move your liability. Article 26(4) says designating a representative is without prejudice to legal actions which could be initiated against the entity itself.
- Not appointing is worse than appointing, not neutral. Article 26(3) says that in the absence of a designated representative, any Member State in which the entity provides services may take legal action against it for infringement.
- It does not set the obligations. Article 26 is about who has jurisdiction; the cybersecurity risk-management measures are in Article 21 and the reporting duties in Article 23.
- The Article 26(2) main-establishment test is not about where you are incorporated. It turns on where cybersecurity decisions are taken, which for many groups is a different country from the registered office.
- The Article 26(1)(b) list is closed. An entity in NIS2 scope that is not on it does not get a representative route and is dealt with under Article 26(1) instead.
How it sits beside the other mandates
- Article 34 sets the administrative fines, and they are keyed to Articles 21 and 23 rather than to Article 26. So the sanction for not appointing is the broader exposure Article 26(3) creates across every market you serve, rather than a set figure attached to the appointment.
- Several entities on the Article 26(1)(b) list are also providers of intermediary services under the Digital Services Act, so a Digital Services Act Article 13 appointment and a NIS2 one commonly sit together and are separate.
- Because NIS2 is a Directive, two Member States can transpose the same provision differently, and the country in which the representative sits is therefore a decision about which national rules apply to you.
NIS2 is a Directive: the binding obligations live in each Member State's transposing national law, and this is the EU Directive text those laws implement.
Source text: EUR-Lex, Official Journal HTML (CELEX 32022L2555). The parser was validated against the anchor articles verified in REP-08.