← Back to insights

A Company Operates in Three EU Countries: Is the NIS2 Registration Request Ready for a Service Scope?

Separate NIS2 entity classification, main-establishment jurisdiction and national registration execution before offering one three-country compliance package.

A multi-country NIS2 request separates entity scope, main-establishment jurisdiction and each national action
#NIS2#Cybersecurity Compliance#Entity Registration#EU Jurisdiction

Signals to watch

  • A named legal entity and service category can be tested against NIS2 scope and national law
  • The place where cybersecurity risk-management decisions are predominantly taken is distinguished from sales offices and infrastructure locations
  • A filing, authority response, customer review or launch decision has a date and an accountable country owner

A company operating in three Member States does not automatically need three identical NIS2 registrations. A service request is ready only after the provider identifies the legal entity and service, determines which NIS2 jurisdiction rule applies, maps each establishment and national implementation, and names the exact filing or authority action with an owner and date. “We sell in France, Germany and Spain” is not a registration scope.

This is the issue for a cybersecurity-compliance BD lead reviewing authorized cloud, managed-service and regulated-industry Telegram groups. The useful Signal is not a country count. It is a jurisdiction or registration task blocking a launch, customer review or authority response. Seeing it a day late can miss the buyer’s national-law workshop. Quoting too early can promise three filings where one main-establishment route—or no Article 27 route—applies.

The following is an illustrative composite, not a real company request or legal conclusion:

“SaaS group has entities in DE, NL and FR. Customer says NIS2 registrations are missing. Need someone to handle all three.”

The message omits the legal entities, service category, size/scope basis, main establishment, cybersecurity decision location, national laws, competent authorities, current submissions, customer requirement and authority of the writer.

The central mistake is treating scope and registration as one service

Directive (EU) 2022/2555, known as NIS2, establishes EU-level cybersecurity risk-management and incident-reporting requirements for specified essential and important entities. Member States were required to transpose it into national law by 17 October 2024.

The Directive is not a single EU filing portal for every entity in Annex I or II. A provider first needs scope classification: legal entity, sector, service, size and any regardless-of-size rule. Then it needs jurisdiction analysis under Article 26. Only after that can a national registration or notification task be scoped.

The Commission’s NIS2 overview is useful for the common framework. Current national law and authority instructions control the execution details. A sales team should not convert an EU category into a national form without that second source.

One group of cross-border providers uses a main-establishment rule

Article 26 gives a special jurisdiction rule to DNS providers, top-level-domain registries, domain-registration services, cloud computing, data centres, content delivery networks, managed service providers, managed security service providers, online marketplaces, online search engines and social-networking platforms.

For those entities, jurisdiction generally follows the main establishment in the Union. The Directive first looks to the Member State where decisions about cybersecurity risk-management measures are predominantly taken. If that cannot be determined or those decisions are not taken in the Union, it looks to where cybersecurity operations are carried out; if that also cannot be determined, it uses the establishment with the highest number of employees in the Union.

A server location, sales office or incorporation certificate therefore cannot settle the question alone. The evidence needs board or management responsibility, security decision rights, operating teams and legal establishments.

Other entities can have a different country map

The main-establishment rule is not universal. Article 26 generally places an in-scope entity under the Member State where it is established, with separate rules for public electronic communications services, public administration and the named cross-border providers.

An industrial group with three manufacturing subsidiaries can therefore need a different analysis from one cloud provider serving three countries. Separate legal entities may have their own scope and national obligations even if a group security team is centralized.

This is why “three countries” is a poor unit for pricing. The useful unit is an entity-service-jurisdiction decision followed by the national action it creates.

Article 27 is specific, not a label for every national list

Article 27 requires Member States to collect registration information for the named cross-border providers. The fields include the entity name; sector, subsector and entity type; main and other EU establishments or an EU representative; current contact details; Member States where services are provided; and IP ranges. IP means Internet Protocol, the addressing system used by networked devices.

Changes must be notified without delay and no later than three months after the change. Authorities transmit specified information to the European Union Agency for Cybersecurity, ENISA, for a registry of these providers.

Other entities can still need to identify themselves under national mechanisms used to build national lists. Do not call every national intake form “Article 27 registration” without checking the entity type and local legal basis.

A non-EU provider needs a representative, not a fictional establishment

When a named Article 26 provider is not established in the Union but offers services there, it must designate a representative in one Member State where it offers services. The representative must be established in the Union and explicitly designated by written mandate to act on the provider’s behalf for NIS2 obligations.

That role does not make the representative the provider or erase the provider’s liability. A service quote should distinguish representative service, entity registration, legal-scope advice and ongoing incident/risk-management compliance.

The strongest counterargument: buyers want one accountable supplier

A group operating across Europe may reasonably want one supplier to coordinate the work. Central coordination can reduce duplicated discovery and inconsistent data. It does not make the legal outputs identical.

The responsible offer is a coordinated programme with country-specific work orders: common entity/service inventory, documented jurisdiction rationale, national-law check, authority/form, local language where required, filing owner and evidence of submission. One commercial agreement can contain several different legal tasks.

The scope note needs four layers

Write the candidate in four lines:

  1. Entity and service: exact legal entity, Annex sector/service and size/special-scope evidence.
  2. Jurisdiction: ordinary establishment, main establishment, service country or EU representative rule, with supporting facts.
  3. National action: law, authority, register/form, language, required fields and deadline.
  4. Commercial boundary: advice, representative mandate, preparation, filing, authority correspondence and ongoing updates—each included or excluded.

The NIS2 directive-versus-national-law article explains the two-source check. For an incident-reporting discussion rather than registration, use the NIS2 early-warning route. A generic regulation date should first pass the regulation-driven demand test.

TOP Prospect can connect fragments from groups the user deliberately connects and is authorized to access, preserve source and time, remove obvious duplicates and rank the request for human review. It cannot decide legal scope, identify a competent authority without evidence, sign a representative mandate, file a registration or contact the writer. The pricing page describes the discovery boundary.

The three-country request becomes serviceable when the provider can say, for each legal entity, why one jurisdiction rule applies and which national action follows. Until then, sell a bounded scope review—not three registrations by multiplication.

Frequently asked questions

Does operating in three EU countries always require three NIS2 registrations?

No. The answer depends on the entity and service. Article 26 gives specified cross-border digital providers a main-establishment jurisdiction rule, while other entities may fall under the Member State where they are established or provide services. National implementation still needs checking.

Which providers use the NIS2 main-establishment rule?

Article 26 names DNS services, TLD registries, domain-registration services, cloud computing, data centres, content delivery networks, managed and managed security services, online marketplaces, online search engines and social-networking platforms.

What if a covered provider is not established in the EU?

Specified providers offering services in the Union must designate a representative established in a Member State where services are offered. The representative needs a written mandate; this does not remove the provider’s obligations.

What information does Article 27 registration cover?

For the named cross-border providers, it includes the entity name, sector/type, main and other EU establishments or representative, current contact details, Member States served and IP ranges. Changes must be notified without delay and within three months.

Sources and further reading

RESEARCH & DEFINITIONS

How a Signal worth attention is found

See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

Open the methodology and core definitions

START WITH ONE MONITORED GROUP

Try the workflow free for seven days.

Open the product, connect one authorized group, and describe the Signal you want to find. If you need help choosing the scope, ask us on Telegram.

Back to homepage