Only a narrow set of non-EU digital providers need a NIS2 representative, and it comes from Article 26(3), not Article 27. Engage Compliance acts as that representative from its EU establishment for the entities that are actually caught.

The short answer: if your entity is non-EU, sits in the Article 26(1)(b) list of digital infrastructure and digital service providers, and offers services in the Union, Article 26(3) of Directive (EU) 2022/2555 requires you to designate a representative established in a Member State where those services are offered. Engage Compliance provides that representative directly from its EU establishment. If you are a non-EU energy, transport, health, water, manufacturing, food, or postal entity, you have no NIS2 representative obligation at all, and we will tell you so rather than sell you one.

Key takeaways

  • The correct provision is Article 26(3) of Directive (EU) 2022/2555, not Article 27. Getting the article right matters, because much of the market cites the wrong one.
  • Engage Compliance acts as your NIS2 Article 26(3) representative directly from its EU establishment, which is where the law requires the representative to sit.
  • The trigger is narrow. Only the digital providers listed in Article 26(1)(b) are caught. Most sectors named in the NIS2 annexes carry no representative duty.
  • The size test is broadly medium-sized, at least 50 staff or turnover and balance sheet above €10 million, with Article 2(2) and Article 2(4) both overriding that cap. Domain name registration services, TLD name registries and DNS service providers carry no size threshold at all.
  • There is no specific penalty for failing to designate. The consequence is losing the single-jurisdiction benefit and facing enforcement in every Member State where you provide services.
  • Appointing a representative fixes your regulator: you fall under the jurisdiction of the Member State where the representative is established.

Who needs a NIS2 representative

The representative duty in Article 26(3) reaches only the entities named in Article 26(1)(b). That list is:

  • DNS service providers
  • TLD name registries
  • entities providing domain name registration services
  • cloud computing service providers
  • data centre service providers
  • content delivery network providers
  • managed service providers
  • managed security service providers
  • providers of online marketplaces
  • providers of online search engines
  • providers of social networking services platforms

If your entity is established outside the Union, sits in that list, and offers services within the Union, you need to designate a representative. That is the whole trigger.

Who is exempt

The duty is keyed to the entity type in Article 26(1)(b), not to your sector label. Article 26(1)(a) and (c) carry no representative obligation, so a non-EU provider of public electronic communications networks or publicly available electronic communications services owes nothing under Article 26(3), and neither does a non-EU trust service provider, even though both are firmly in scope for NIS2 itself and both lose the size cap under Article 2(2). The same goes for a non-EU entity whose only activity is in energy, transport, health, water, food or postal services. Being an important or essential entity under NIS2 is not the same as owing a representative duty.

Read that as a test on what you do, not on what industry you are in, because a flat sector exclusion gets it wrong in both directions. A manufacturer is the clearest case. Manufacturing is not in the 26(1)(b) list, so a non-EU manufacturer selling machines into the EU appoints nobody. But if the same company also runs a cloud platform, a managed service or a managed security service for EU customers, that arm is a covered entity under 26(1)(b) and the company does owe a representative. The question is whether any part of what you offer in the Union appears in that list.

Entities below the size threshold are also out, subject to the Article 2(2) and Article 2(4) overrides described next. If you provide domain name registration services, stop here: your size does not matter.

What size a company has to be

The size test is broadly medium-sized. In practice that means at least 50 staff, or annual turnover and balance sheet total above €10 million.

Two provisions override the size cap. Article 2(2) covers DNS service providers, TLD name registries, trust service providers, and providers of public electronic communications networks or services, which are in scope regardless of how small they are. Article 2(4) is a paragraph of its own and reads in full: “Regardless of their size, this Directive applies to entities providing domain name registration services.”

That third category is the one most often missed, and it is the one where missing it costs most, because registrars are also named in the Article 26(1)(b) list that carries the representative duty. A registrar with three staff and no EU establishment owes a representative; a much larger company in an exempt sector owes nothing. NIS2 also treats registrars separately from everyone else in Article 3(3), where Member States list “essential and important entities as well as entities providing domain name registration services”, which is the drafting tell that they are covered without being classified as either.

When it applies from

NIS2 had a transposition deadline of 17 October 2024. Because it is a Directive rather than a Regulation, the binding obligation lives in each country’s national law, not in the Directive itself, and Member States have diverged in both the timing and the drafting of their transposition. So the answer to “does this apply to me yet” depends on the specific Member States where you offer services, and it is worth checking those national laws rather than reading the deadline as a single switch that flipped everywhere on the same day.

Where transposition stands, as at 2 September 2026

Three Member States are still outstanding, and the picture has moved, so a list you read a few months ago is out of date.

Member StateNational measures notifiedWhere it stands
Ireland0Nothing notified. The NIS2 obligations have no Irish national law to sit in yet.
Spain0Nothing notified. Same position as Ireland.
France15Partial. Measures have been notified, but transposition is not complete.
Netherlands3Done. The Cyberbeveiligingswet and its implementing decree entered into force on 15 August 2026.
Every other Member State1 or moreMeasures notified. Check the national law for how it treats your entity type.

The counts are the national transposition measures each Member State has communicated to the Commission for Directive (EU) 2022/2555, read on 2 September 2026. The Dutch date comes from Article 35 of the Cyberbeveiligingsbesluit, Staatsblad 2026 number 189.

The Netherlands is why the older four-country list is worth retiring. A referral list from 8 July 2026 named four Member States; the Dutch law came into force on 15 August 2026, so that list no longer describes the position. If you serve the Netherlands, the obligation is live.

Where the representative must be established

The representative must be established in one of the Member States where the services are offered. Engage Compliance meets that from its EU establishment, so for a provider serving the Netherlands, or serving the Union broadly, we can act as the representative directly, with no separate local entity needed.

Article 26(3) says only “designate”. It does not require the appointment to be in writing, unlike the GDPR, the DSA, and the AI Act. A contract is still how the appointment is evidenced, and with no writing requirement in the text, the contract becomes the only proof the designation happened.

What the penalty is

There is no specific fine for failing to designate a NIS2 representative. The consequence written into Article 26(3) is different in kind: you lose the single-jurisdiction benefit, and any Member State where you provide services can take legal action against you for infringing the Directive. In other words, the sanction for not appointing is broader exposure, not a set fine.

The NIS2 fines people quote, up to €10 million or 2 percent of worldwide turnover for essential entities and up to €7 million or 1.4 percent for important entities, come from Article 34 and are keyed to Articles 21 and 23, the risk-management and incident-reporting duties. They are not the penalty for missing the Article 26 designation.

Appointing a representative chooses your regulator

This is the part clients tend to value most. Under Article 26(3), the entity is considered to fall under the jurisdiction of the Member State where the representative is established. So the appointment does more than tick a box: it settles which single national authority you answer to for NIS2, instead of leaving you exposed across every country you serve. Without a representative, any Member State where you provide services can pursue you. With one, you have one regulator and one point of contact.

What Engage Compliance delivers

  • The Article 26(3) representative appointment, performed directly from our EU establishment.
  • A contract that evidences the designation, since the text sets no writing requirement and the contract is your proof.
  • A named, published point of contact for the national authority in your jurisdiction of establishment.
  • Handling of correspondence from the competent authority, routed to your internal owner with the substance within one business day.
  • A scoping review first, so if you are not actually caught by Article 26(1)(b), we say so and stop rather than sell you a mandate you do not owe.

There is no record-keeping duty on the NIS2 representative, so this is a point-of-contact and jurisdiction role, not a document-custody one.

What it costs

The appointment is €550 a year at the smallest band, for a company with 1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold, charged once, up front, with no setup fee. Whichever of headcount, revenue or the number of people whose data you hold puts you highest sets the band.

Company sizeNIS2 Representative
1 to 10 people, under €2m revenue, and under 5,000 people in the EU and UK whose data you hold€550
11 to 50 people, or €2m to €10m revenue, or 5,000 or more people in the EU and UK whose data you hold€790
51 to 250 people, or €10m to €50m revenue€1,830
251 or more people, or over €50m revenueFrom €3,590

The smallest band is for very small organizations only: 1 to 10 people, under €2m in global annual revenue, and under 5,000 people in the EU and UK whose personal data you hold. All three must be true. If any one of them is not, the next band up applies.

Commercial pricing bands based on familiar market-size and market-pricing thresholds. They are not a statutory size test.

Every appointment you hold is a separate mandate, and only the highest-priced one in the basket is charged in full. Every other appointment is charged at a share of its own price, and for this one that share is half its own price. So adding this to an appointment you already hold costs €275 at band 0, €395 at band 1, €915 at band 2, €1,795 at band 3, rather than a second full price.

Two extras are optional, and each is charged once per order rather than once per appointment. Higher-risk processing, which covers special category data and criminal offense data, is €250 at band 0, €500 at band 1, €750 at band 2, €1,000 at band 3. Same-business-day response is a service level on authority and data subject correspondence rather than substantive advice, and is €1,200 a year.

Every band is published and buyable, so you can see your price and appoint online without talking to anyone first. The full table for every mandate is on representative services.

The appointment issues in seconds. After payment you answer a short form about your company and who we should send correspondence to, about three minutes of typing, and the appointment document, the certificate, the public verification link and the wording you need all issue automatically at that moment. Nobody at Engage has to approve anything.

Sources and references

Representative mandates

These mandates stack rather than replace each other. One company selling into Europe can be caught by several at once, each is a separate appointment with its own published contact point, and an EU representative does not cover the UK. Engage Compliance holds them together so you have one point of contact across the set.

  • Same-business-day response
  • Professional indemnity and cyber insurance
  • Named DPO notified to the supervisory authority

FAQ

Frequently asked questions

Is the NIS2 representative under Article 26 or Article 27?

Article 26(3) of Directive (EU) 2022/2555. Vendors frequently cite Article 27, which is the wrong provision. Article 26(3) requires a non-EU entity in the Article 26(1)(b) list that offers services in the Union to designate a representative established in one of the Member States where those services are offered.

Who needs a NIS2 representative?

Only entities named in Article 26(1)(b): DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines, or social networking services platforms. If you are non-EU and fall in that list and meet the size test, you are caught. Three of those types have no size test at all: Article 2(4) puts entities providing domain name registration services in scope regardless of their size, and Article 2(2)(a)(iii) does the same for TLD name registries and DNS service providers.

Does a non-EU energy, health, or manufacturing company need a NIS2 representative?

No. Article 26(1)(a) and (c) carry no representative duty, so a non-EU entity in energy, transport, health, water, manufacturing, food, or postal services has no NIS2 representative obligation. This is the most mis-sold point in the market. The representative duty attaches only to the digital infrastructure and digital service providers in Article 26(1)(b).

What size does a company have to be before NIS2 applies?

Broadly medium-sized: at least 50 staff, or annual turnover and balance sheet total above €10 million. Two provisions override that cap. Article 2(2) covers DNS service providers, TLD name registries, trust service providers, and providers of public electronic communications networks or services. Article 2(4) is its own paragraph and covers entities providing domain name registration services: 'Regardless of their size, this Directive applies to entities providing domain name registration services.' A one-person registrar is in scope.

What is the penalty for not appointing a NIS2 representative?

There is no specific penalty for failing to designate. The consequence written into Article 26(3) is that you lose the single-jurisdiction benefit and expose yourself to enforcement in every Member State where you provide services. The Article 34 fines, up to €10 million or 2 percent for essential entities and €7 million or 1.4 percent for important entities, are keyed to Articles 21 and 23, not to Article 26.

Does appointing a representative decide which regulator we answer to?

Yes, and clients value this. Under Article 26(3) the entity falls under the jurisdiction of the Member State where the representative is established. Appointing a representative in one country gives you one national authority to deal with instead of scattered exposure across every market you serve.