NIS2 Entity Registration: The 5-Step Process From Document Prep to Post-Submission Sign-Off
Most NIS2 entities register once and rarely think about it again — until an auditor asks for proof, or a national portal bounces the submission back because a required field was missing. The registration itself is a paperwork exercise; getting it right on the first attempt is a small project with a defined scope, a document list, and an owner. This guide walks through that project end to end: five steps from confirming which registration obligation actually applies to you, through submission, to what you’re on the hook for afterward.
Two clarifications up front. First, “NIS2 registration” is actually two separate legal obligations that a lot of guidance on this topic conflates: the general national list under Article 3(4), which is what the large majority of essential and important entities go through, and a narrower EU-level registry under Article 27 that applies only to specific digital-infrastructure and digital-service providers. Which one applies changes your update-notification deadline from three months to two weeks — a detail worth getting right before you file anything. Second, this is a process guide, not a field-by-field reference — for the complete list of required data points and a country-by-country portal directory, see our entity registration reference guide.
Which Registration Applies to You: Article 3(4) or Article 27?
Confirm which obligation you’re actually fulfilling before you touch a portal — the paperwork looks similar, but the legal basis, and the deadlines that follow from it, are different.
Most essential and important entities — across all the sectors listed in NIS2 Annexes I and II, from energy to healthcare to manufacturing — register under Article 3(4) [1]. By 17 April 2025, Member States were required to establish, and now review at least every two years, a list of these entities, and the Directive explicitly lets each Member State choose its own mechanism: “Member States may establish national mechanisms for entities to register themselves” [1]. In practice, nearly every Member State chose a self-registration portal — Germany’s BSI-Portal, Austria’s national system, Romania’s NIS2@RO tool, and similar systems elsewhere. If you update your submitted information later, Article 3(4) gives you “without delay, and, in any event, within two weeks of the date of the change” [1] — a tighter window than most compliance teams expect.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
A second, narrower obligation sits under Article 27 [2]: a registry limited to DNS service providers, TLD name registries, domain-name registration service entities, cloud computing providers, data-centre providers, content delivery network providers, managed service and managed security service providers, and providers of online marketplaces, online search engines, or social networking platforms. These entities submitted by 17 January 2025, and their change-notification window is three months, not two weeks [2] — the opposite of what most guidance assumes when it treats “NIS2 registration” as one thing. If your organisation falls into one of these specific categories, you may be completing both registrations, not one.
| Article 3(4) — General List | Article 27 — Registry of Entities | |
|---|---|---|
| Who | All essential/important entities (Annex I & II sectors) | DNS/TLD/cloud/CDN/MSP/MSSP/marketplace/search/social platform providers only |
| Deadline | 17 April 2025 (list established; reviewed at least every 2 years) | 17 January 2025 |
| Mechanism | Member State’s choice — usually a national self-registration portal | ENISA-maintained registry, forwarded via national single point of contact |
| Update window | Within 2 weeks of a change | Within 3 months of a change |
For the exact information fields and a country-by-country list of live portals, see our entity registration guide — this article focuses on the process of getting from “I need to register” to “submitted and confirmed.”
The 5-Step Registration Process, and Who Should Own Each Step
Treat registration as a small project with five steps, not a single form-filling task, and assign an owner to each one before you start. The delays that show up most often across the registration workflows reviewed for this guide aren’t legal complexity — they’re a step sitting unowned for two weeks because IT assumed Compliance was handling it, or the reverse.
| Step | Owner | Effort | What it involves |
|---|---|---|---|
| 1. Confirm scope & prepare documents | Compliance / Legal | Medium | Self-identification check, gather entity data, name a 24/7 contact |
| 2. Identify your portal & authority | IT + Compliance | Low | Confirm the national system, request access or credentials |
| 3. Gather required information fields | IT + Compliance | Medium–High | IP ranges, sector classification, service footprint |
| 4. Submit | Compliance | Low | Complete and file the registration itself |
| 5. Post-submission: confirm, calendar, monitor | Compliance | Low (ongoing) | Confirm receipt, calendar update deadlines, treat as a live record |
Step 1 — Confirm Scope and Prepare Your Documents
The most expensive mistakes in registration happen before anyone opens a portal, in scoping. Four patterns show up repeatedly among organisations self-identifying for the first time:
- Confusing core business with what’s actually regulated. A manufacturer that provides IT support to a subsidiary can be classified as a managed service provider for that specific activity alone, even though IT support isn’t the main business [5].
- Undercounting headcount by excluding affiliated entities. Size thresholds should include employees at parent companies, subsidiaries, and holding-company affiliates connected through ownership links, not just the registering legal entity on its own [5].
- Defaulting to the lighter of several applicable obligation tiers. Organisations providing more than one regulated service sometimes pick whichever regime looks lighter; the rule that actually applies is the highest tier across all services provided, not an average [5].
- Assuming supplier status equals regulated status. Supplying a regulated entity doesn’t automatically make you regulated yourself — you still have to independently meet the sector and size criteria [5].
Once scope is confirmed, assemble the document list before opening any portal: legal entity name and registration number, registered address plus every EU establishment address, a named 24/7 incident contact point [6], a full IP address range inventory in CIDR notation, sector and subsector classification, the list of Member States where in-scope services are provided, and a documented impact or scope assessment — several national authorities and auditors treat this last item as your evidence that the classification wasn’t guessed [6]. IP ranges are usually the item that surprises compliance teams: it requires an IT deliverable with its own timeline, not a five-minute lookup, particularly if no current network inventory already exists.
The 24/7 contact point deserves more thought than a name in a spreadsheet cell. It’s the individual (or shared inbox) a national authority or CSIRT reaches when they need to act fast — during a cross-border incident, or when your organisation’s infrastructure shows up in a threat notification from another Member State. A registration that lists a person who left the company six months ago doesn’t just look sloppy at audit time; it’s a genuine operational gap the field was designed to close.
Step 2 — Identify Your National Portal and Authority
Every Member State runs its own registration system, and — with the narrow Article 27 exception — there’s no single EU-wide portal to check. What’s consistent across the national systems reviewed for this guide is a two-stage pattern: an identity-verification or business-account step first, then the actual NIS2 registration form second.
Germany’s system is a representative example. Registration for facilities in scope under §33(6) of the German IT Security Act runs through the Federal Office for Information Security (BSI) [3]. The process is two-tiered: first obtain a business identity via “Mein Unternehmenskonto,” authenticated through the German tax administration’s ELSTER system — a step that reportedly takes anywhere from a few working days to roughly two weeks to issue if you don’t already hold an ELSTER organisational certificate, depending on the source [4][6] — then complete the actual registration in the BSI-Portal [3]. Germany’s registration deadline was 6 March 2026, against roughly 29,000 companies in scope, and German technology press reported that fewer than half had registered by that date [4].
Across the national systems reviewed for this guide, that identity-verification step — not the registration form itself — is consistently the part that blows past a compliance team’s timeline expectations. Build in one to three weeks of lead time for it rather than assuming registration can happen in a single sitting. For the specific portal, authority, and credential process in your own country, see our Germany, Austria, and Romania competent-authority guides, or the full portal directory in our entity registration reference.
Step 3 — Gather the Required Information Fields
The specific fields depend on which obligation from Step 1 applies, but they overlap heavily. At minimum, expect to provide: entity name and sector/subsector classification, registered address and any additional EU establishment addresses, up-to-date contact details including a named security contact, the list of Member States where in-scope services are provided, and IP address ranges in CIDR notation [1][2].
Two fields cause disproportionate delay. IP ranges require pulling from network documentation that frequently doesn’t exist as a single source — treat this as an IT deliverable with its own timeline, not a checkbox on a compliance form. And multi-sector organisations need to file each facility type as a separate registration rather than bundling everything into one blended submission [6]: an organisation that is both a manufacturer and, through a subsidiary, a managed service provider registers as both, not once.
If your organisation only holds a handful of static IP ranges, this step is a Low-effort lookup. If IT infrastructure has grown through acquisitions, cloud migrations, or multiple business units provisioning their own ranges over the years, budget real time for it — a network inventory that was never centralised in the first place doesn’t get faster to compile just because a deadline is attached to it. Start this specific item first among the Step 3 fields; everything else on the list can typically be pulled from a company registry or an HR system in under an hour.
Step 4 — Submit, and Avoid the Mistakes That Trigger a Resubmission
Most rejected or bounced-back submissions trace back to one of six recurring mistakes, and nearly all of them are caught after the fact rather than before:
| Mistake | Where it bites | Fix |
|---|---|---|
| Wrong account/entity type selected (e.g. personal instead of organisational) | Portal access step | Confirm you’re registering as the legal entity before starting [6] |
| Registered-entity data doesn’t match the national business registry | Submission | Correct the source system first — the registration portal often can’t override it [6] |
| Headcount excludes affiliated companies | Scope/threshold | Recalculate including parent, subsidiary, and holding-company employees [5] |
| One blended submission for a multi-sector organisation | Submission | File each facility type as a separate registration [6] |
| No 24/7 incident contact designated | Submission | Name the contact before you start — some portals block submission without it [6] |
| No documented scope/impact assessment on file | Post-submission audit | Produce this alongside the submission, not after a supervisory request [6] |
Step 5 — What Happens After You Submit
Submission isn’t the end of the process; it starts two ongoing obligations.
First, changes to your submitted information have a hard deadline: two weeks under Article 3(4), three months under Article 27 [1][2]. Calendar this the same day you submit — “without delay” language in the Directive means authorities don’t treat a missed update as a technicality.
Second, your data doesn’t stay with the national authority alone. Under Article 3(4), competent authorities report entity counts by sector to the European Commission and the Cooperation Group at least every two years [1]. Under Article 27, the national single point of contact forwards your submitted information directly to ENISA, which maintains the EU-level registry [2]. Neither process typically requires action from you, but it’s a reason to correct an error at the source rather than let a stale record propagate.
In several member states, including Germany, the same portal used for registration doubles later as the channel for incident reporting [4] — worth confirming early, since it means the credentials from Step 2 aren’t a one-time login.
FAQ
Do I need to register if my country hasn’t finished transposing NIS2 into national law yet?
No. National registration obligations only apply once your Member State’s transposing law is in force. Check your country’s transposition status before assuming a deadline applies to you.
What if my organisation operates in more than one Member State?
List every Member State where you provide in-scope services in your submission [1][2]. Depending on how each country structured its national mechanism, you may also need to register separately with each Member State’s own authority — check the relevant country-specific guide for your situation.
Is there a fee to register?
The Directive doesn’t set a registration fee, and none of the national portals reviewed for this guide charge one. Registration is a compliance obligation, not a paid service.
What happens if I miss the deadline?
Missing the registration deadline is a compliance failure the authority can act on independently of your Article 21 security-measure compliance. In Germany, only around half of the roughly 29,000 in-scope companies had registered by the original deadline [4] — if you’re in a similar position, don’t assume a blanket grace period applies. Any leniency a national authority grants late registrants is a discretionary enforcement decision, not a legal entitlement, and it doesn’t change the underlying deadline in the transposing law. Confirm the exact terms with your national competent authority directly rather than relying on a forum post or a blog summary.
Key Takeaways
Registration fails for procedural reasons far more often than legal ones: a missing 24/7 contact, a headcount that excludes affiliates, a blended submission that should have been filed twice. Confirm which obligation applies to you, assign an owner to each of the five steps above, and treat the document-prep list as work to finish before you open a portal, not while you’re inside one. Once you’re on the national register, the document template library and free compliance checklist cover the Article 21 measures that follow.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- “Directive (EU) 2022/2555 (NIS2), consolidated text, Article 3” — EUR-Lex
- “Article 27, Registry of Entities” — The NIS 2 Directive
- “Registrierungspflicht” — Bundesamt für Sicherheit in der Informationstechnik (BSI)
- “The clock is ticking: NIS2 registration deadline at BSI expires on March 6, 2026” — heise online
- “NIS2: The Most Common Mistakes in Self-Identification” — Cybrela
- “NIS2 Registration with BSI: Complete Instructions in 3 Steps” — ADVISORI
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
