NIS2 Directive

NIS2 Representative for Non-EU Digital Service Providers

If your US or Canadian business offers certain digital services in the EU but has no EU establishment, NIS2 requires you to designate a representative in a Member State where you operate. DataShield acts as that representative: a single, named point of contact between your organization and the national competent authorities and CSIRTs, supporting your registration, your ENISA-facing obligations, and the secure relay of incident notifications. We help you meet the requirement cleanly, without setting up a local entity, under the oversight of a CNIL-designated DPO.

🛡 Overseen by a Data Protection Officer designated with the CNIL

What a NIS2 representative is

Under NIS2 (Article 26), an entity that is not established in the EU but offers in-scope digital services within the Union must designate a representative in a Member State where it provides those services. The entity is then treated as falling under that Member State's jurisdiction.

The representative is the legal and practical interface between your organization and the authorities. It does not assume your compliance duties, but it ensures the regulator and the CSIRT can reach you. Key functions include:

  • Acting as the addressable point of contact in the EU.
  • Receiving and relaying official communications.
  • Supporting registration and incident-related correspondence.

Designating a representative does not, by itself, establish your company in the EU.

Who needs a NIS2 representative

The representative obligation targets specific digital sectors. Non-EU providers of the following services that operate in the Union are in scope:

  • DNS service providers and TLD name registries, plus domain-name registration services.
  • Cloud computing, data centre, and content delivery network (CDN) providers.
  • Managed service providers and managed security service providers.
  • Online marketplaces, online search engines, and social networking platforms.

Crucially, the size-cap rule applies: NIS2 generally covers medium and large entities, that is, 50 or more employees, or annual turnover or balance sheet above EUR 10 million. Micro and small enterprises are usually excluded. However, certain providers, notably DNS services and TLD registries, fall in scope at any size, so smaller operators in these niches still need a representative.

What DataShield does as your representative

DataShield serves as your designated NIS2 representative in the EU, mirroring the model we operate for GDPR Article 27 representation. Our service covers:

  • Single point of contact for the national competent authority and the relevant CSIRT, with a named contact and EU address.
  • Registration support, helping you provide the entity information national registries and ENISA expect.
  • Incident notification channel, relaying your significant-incident notifications to authorities within statutory deadlines and forwarding their responses to you.
  • Ongoing correspondence handling and document retention.

Everything is overseen by a CNIL-designated DPO, so your privacy and cybersecurity representation stay coordinated and audit-ready across the US and Canada.

FAQ

NIS2 Representative for Non-EU Digital Service Providers

Does appointing a NIS2 representative mean my company is established in the EU?

No. Designating a representative gives you an addressable point of contact in a Member State, but it does not create an EU establishment, subsidiary, or branch. It satisfies the NIS2 obligation for non-EU providers without you having to incorporate a local entity. Your organization remains responsible for its own cybersecurity risk-management measures and reporting duties.

We are a small US company. Are we still covered by NIS2?

It depends on what you offer. NIS2 generally applies to medium and large entities, meaning 50 or more employees or annual turnover or balance sheet above EUR 10 million, so many micro and small businesses are excluded. But there are exceptions: providers such as DNS services and TLD name registries are in scope regardless of size. If you operate one of those services in the EU, you likely need a representative even as a small company.

How is a NIS2 representative different from a GDPR Article 27 representative?

They are separate roles under separate laws. A GDPR Article 27 representative handles data-protection matters for non-EU controllers and processors. A NIS2 representative is the contact point for cybersecurity supervision, dealing with competent authorities and CSIRTs on registration and incident notifications. A business may need both. DataShield can provide each role and coordinate them under one DPO-supervised service.

Work with a real DPO

Appoint an EU representative backed by genuine, verifiable expertise.

Get my quote →