NIS2: Obligation to designate a representative for in-scope entities in third countries
July 06, 2026
NIS2: Obligation to designate a representative for in-scope entities in third countriesJuly 06, 2026 IntroductionThe NIS2 Directive (Directive (EU) 2022/2555) introduces a revised framework for cybersecurity within the European Union. Its scope is not limited to entities established in the EU, but also extends to certain providers located in third countries. The Directive entered into force on 16 January 2023 and Member States were required to transpose it into national law by 17 October 2024. As of mid-2026, approximately 24 of the 27 Member States have adopted national NIS2 laws, with enforcement timelines extending into 2025-2026 depending on the jurisdiction. Among the new elements introduced by NIS 2 are obligations that specifically target entities operating from outside the Union. One of these is the requirement for certain third-country entities to designate a representative within the EU. This requirement aims to ensure that competent authorities are able to effectively supervise and enforce compliance, even where relevant service providers are not physically established within the Union. Against this background, this article examines the representative obligation under NIS2, with a particular focus on its scope of application, the conditions triggering the obligation, and the legal and practical implications of designating a representative. 1. Territorial scope of applicationThe territorial scope of the NIS 2 Directive is not limited to entities established within the European Union, but also covers certain entities established in third countries. Under Article 2(1) NIS2 Directive, the rules apply to entities that provide services or carry out activities within the Union. This indicates that the place of establishment of the entity is not a decisive criterion. Rather, the relevant question is whether there is a sufficient connection between the services offered and the EU market. The notion of “providing services within the Union” requires further interpretation. Recital 116 of the NIS2 Directive clarifies that this threshold is not met merely because a website is accessible in the Union or contact details are available there. Similarly, the use of a language generally used in the third country of establishment does not, in itself, indicate that services are directed at the EU. By contrast, a sufficient connection may exist where an entity actively targets users in the Union, for example by offering services in a language or currency commonly used in one or more Member States, in particular where those services can be ordered in that language, or by referring to customers or users located within the EU. Article 26 NIS2 Directive specifies the territorial scope by providing that, in principle, the applicable law is that of the Member State in which the entity is established, or, where applicable, where its representative is established. 2. The obligation to designate a representativeArticle 26(3) NIS2 Directive requires certain entities that are not established in the EU, but provide services within it, to appoint a representative in the Union. This mechanism is intended to ensure that supervisory authorities have a clear point of contact for enforcement and compliance purposes, and is comparable to the representative requirement under the GDPR. The obligation applies to a specific category of entities listed in Article 26(1)(b) NIS2 Directive, including DNS service providers, top-level domain (TLD) name registries, providers of domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines, and social networking services platforms. These sectors are generally considered critical from a cybersecurity perspective and often operate on a cross-border basis. As a result, the requirement is particularly relevant in practice for companies that deliver digital or IT services remotely. For example, a managed service provider offering IT management, remote support and security monitoring to EU-based clients may fall within scope even if it operates exclusively from a third country, and would therefore be required to designate a representative in the Union. 3. Designation of the representative: role, jurisdiction and legal implicationsAccording to Article 6(34) NIS2 Directive, the representative may be either a natural or a legal person established within the European Union. The Directive does not impose specific qualification requirements, such as particular expertise or professional credentials. Recital 116 clarifies that the representative must be explicitly designated by the entity through a written mandate to act on its behalf in relation to its obligations under the Directive, including the reporting of security incidents. In practice, the representative functions as a point of contact for competent authorities. Article 26(3) NIS2 Directive provides that the representative must be established in one of the Member States in which the entity offers its services. The entity is then deemed to fall under the jurisdiction of that Member State. Where an entity provides its services in multiple Member States, the designation of a representative therefore allows the entity to effectively determine the applicable national framework. This is particularly relevant in light of the absence of full harmonisation under the NIS2 Directive. In the absence of a designated representative, any Member State in which the entity provides services may take enforcement action for non-compliance with the Directive. This can be disadvantageous for third-country entities, as Member States have in practice adopted differing and, in some cases, stricter or more detailed national rules. These differences are reflected, for example, in the scope of application, the applicable security standards, incident reporting requirements, as well as registration, classification and enforcement practices. As a result, entities may be exposed to multiple, divergent legal regimes when operating across several Member States. The fragmented implementation landscape underscores the importance of the representative designation mechanism, as national requirements may vary in scope, registration procedures, security standards, and enforcement practices. 4. Dutch implementation of the NIS2 DirectiveIn the Netherlands, the NIS2 Directive is being implemented through the Cyberbeveiligingswet (Cbw). The Cbw was approved by the Dutch Senate (Eerste Kamer) on 7 July 2026 and will enter into force on 15 August 2026. Until that date, the existing Network and Information Systems Security Act (Wbni), which implemented the original NIS Directive, remains applicable. From 15 August 2026, entities falling within scope will be subject to the new NIS2-based obligations. The Cbw largely follows the harmonised framework established by the Directive, without introducing significant deviations or additional layers of regulation. Upon its entry into force, the Wbni will be repealed and supporting legislation is expected to be aligned with the expanded scope and enhanced requirements introduced by NIS2. In addition, the Dutch framework continues to be characterised by a relatively supportive and proactive approach in practice. Both the competent supervisory authority, in particular the Rijksinspectie Digitale Infrastructuur (RDI), and the National Cyber Security Centre (NCSC), acting as the CSIRT, provide guidance, outreach and practical support to in-scope entities. To facilitate compliance, the NCSC has developed dedicated guidance materials, including a registration portal, registration checklist and FAQs, while the RDI has made available a NIS2 self-assessment tool to help organisations determine whether they fall within scope and whether they qualify as an essential or important entity. This approach supports compliance in practice, particularly for entities navigating the NIS2 framework for the first time, and contributes to an accessible and effective supervisory environment. 5. Relation with GDPRAlthough the concept of a representative under NIS 2 is comparable to that under the GDPR, the two roles are not identical. Both function as a local point of contact for authorities and may be outsourced, but they arise from different regulatory frameworks and address different risks. While the GDPR representative is concerned with data protection compliance and the exercise of data subject rights, the NIS 2 representative focuses on cybersecurity, including risk management and incident reporting. As a result, the scope of responsibilities and the practical expectations differ significantly. The roles may, in principle, be assigned to the same person or entity, provided that it is properly mandated and capable of fulfilling both functions. However, organisations should not assume that a GDPR representative will automatically be suitable for the NIS 2 role. Given the more operational and time-sensitive nature of NIS 2 obligations, in particular with regard to incident response and communication with authorities, it is advisable to assess carefully whether the appointed representative has the necessary expertise and capacity to perform both roles effectively. 6. Key takeaways
7. How Eversheds Sutherland can helpEversheds Sutherland offers EU Representative services under the NIS 2 Directive for third-country entities that provide services within the European Union. Our team can act as your designated representative, serving as the point of contact for competent authorities and CSIRTs across Member States. We assist with the selection of the most appropriate Member State jurisdiction, handle registration and notification requirements, coordinate incident reporting within the required timeframes, and provide ongoing support to ensure continued compliance with evolving national frameworks. With offices across the EU and deep expertise in cybersecurity regulation, we are well positioned to help your organisation navigate the NIS2 representative obligation effectively and efficiently. For more information, please contact our team. Latest Insights
Latest News
Latest Events
firm news July 10, 2026 Eversheds Sutherland advises OCBC on the landmark secondary dual listing of... client news July 10, 2026 Setting sail: Eversheds Sutherland advises senior management of D-Marin on ... client news July 09, 2026 Eversheds Sutherland advises Costello Medical on transition to employee own... client news July 07, 2026 Eversheds Sutherland advises PCProfi Informatique SA on its acquisition by ... in-person A leadership conversation for Global GCs September 02, 2026 17:30 - 19:30 MS Wädenswil, Bürkliplatz, Zurich Schiffstation virtual UAE - Employment law in the Dubai International Financial Centre September 10, 2026 9.30am - 1.30pm (GMT) Virtual in-person Managing AI use in the workplace: what every UK HR team needs to know September 10, 2026 9.30am - 1.00pm (BST) London, United Kingdom in-person Interaktiver LIVE Cyber Security Event September 10, 2026 07:30 – 11:00 Kinokoni, Lagerstrasse 104, Europaallee Zürich |