Network & Information Security Directive (NIS) – Summary

Directive (EU) 2016/1148

To view details of DataRep’s service to meet the Representative obligation under this Directive, please visit this page.

Enforceable with effect from9th May 2018 (by transposition of the Directive into law in each EU member state – no direct effect of an EU Directive)
Summary of purposeTo create a culture of cybersecurity across sectors that are vital for the economy and society and that rely heavily on technology; to ensure preparedness for cybersecurity events
Which organisations does it apply to?Online marketplace, online search engine and cloud computing service providers; operators of essential services identified by EU member states (including energy, transport, water, banking, financial market infrastructures, healthcare and digital infrastructure)
Major obligations of regulation

  • To take appropriate and proportionate technical, operational and organisational cybersecurity measures, including business continuity

  • Notify local authorities of incidents which impact service delivery (24 hours for initial notification, 72 hours for full report)

    Main relevant authorities

    • National member state competent authorities

    • National member state Computer Security Incident Response Teams (CSIRTs)

    • The European Union Agency for Cybersecurity (ENISA)

    • EU Cooperation Group

      Summary of Representative obligationCertain organisations (see below) offering their service in the EU, which have no EU establishment, are required to appoint an NIS Representative in the EU (Article 18)

      You can view DataRep’s service to meet this obligation here
      Which organisations require a Representative?Online marketplace, online search engine and cloud computing service providers
      offering their service in the EU, which have no EU establishment, are required to appoint an NIS Representative in the EU (no exclusions)
      Where should the Representative be established?In one of the EU member states where the organisation offers its service(s)
      Summary obligations placed on the RepresentativeReceive communications from competent authorities and CSIRTs on behalf of their clients, including incident reports

      Please reach out to us at contact@datarep.com if you have any questions, or require a quotation for the Representative service under this law.

      Please note that the contents of this document are not intended to provide complete or exhaustive information, nor should they be considered legal advice. Please ensure that you take legal advice before acting on the contents of this document.

      The dpr logo on a white background.
      Datarep logo with an orange and blue background.

      Thank you for visiting DPR Group’s website!

      We are still the same company, offering the most-compliant EU Representative service in the privacy marketplace, but we now have an exciting new brand!

      Although we now operate as DataRep, all our DPR Group clients continue to be represented by us, to enable their GDPR compliance.

      If you have any questions about the change, please don’t hesitate to contact us here!

      We see you’re leaving our site

      Can we help you further?

       If you have a question or you’d like more information, please leave your email address and someone will contact you: