Network & Information Security Directive 2 (NIS2) – Summary

Directive (EU) 2022/2555

To view details of DataRep’s service to meet the Representative obligation under this Directive, please visit this page.

Enforceable with effect from18th October 2024 (by transposition of the Directive into law in each EU member state – no direct effect of an EU Directive)
Summary of purposeTo create a culture of cybersecurity across sectors that are vital for the economy and society and that rely heavily on technology; to ensure preparedness for cybersecurity events
Which organisations does it apply to?Almost all providers of services delivered online, providers of critical services (e.g. energy, transport, water, banking, financial market infrastructures, healthcare and digital infrastructure) and others
Major obligations of regulation

  • To take appropriate and proportionate technical, operational and organisational cybersecurity measures, including business continuity

  • Notify local authorities of incidents which impact service delivery (24 hours for initial notification, 72 hours for full report)

    Main relevant authorities

    • National member state competent authorities

    • National member state Computer Security Incident Response Teams (CSIRTs)

    • The European Union Agency for Cybersecurity (ENISA)

    • European cyber crisis liaison organisation network (EU-CyCLONe)

    • EU Cooperation Group

      Summary of Representative obligationCertain organisations (see below) offering their service in the EU, which have no EU establishment, are required to appoint an NIS2 Representative in the EU (Article 26)

      You can view DataRep’s service to meet this obligation here
      Which organisations require a Representative?DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines or of social networking services platforms offering their service in the EU, which have no EU establishment, are required to appoint an NIS2 Representative in the EU (no exclusions)
      Where should the Representative be established?In one of the EU member states where the organisation offers its service(s)
      Summary obligations placed on the RepresentativeReceive communications from competent authorities and CSIRTs on behalf of their clients, including incident reports
      Other relevant Representative aspects The details of the Representative must be notified to the member state competent authority (in the member state where the Representative is established) as part of the wider notification obligation placed on those companies

      Please reach out to us at contact@datarep.com if you have any questions, or require a quotation for the Representative service under this law.

      Please note that the contents of this document are not intended to provide complete or exhaustive information, nor should they be considered legal advice. Please ensure that you take legal advice before acting on the contents of this document.

      The dpr logo on a white background.
      Datarep logo with an orange and blue background.

      Thank you for visiting DPR Group’s website!

      We are still the same company, offering the most-compliant EU Representative service in the privacy marketplace, but we now have an exciting new brand!

      Although we now operate as DataRep, all our DPR Group clients continue to be represented by us, to enable their GDPR compliance.

      If you have any questions about the change, please don’t hesitate to contact us here!

      We see you’re leaving our site

      Can we help you further?

       If you have a question or you’d like more information, please leave your email address and someone will contact you: