Abstract network visualisation of two node clusters converging on one shared node, representing a joint venture under NIS2

NIS2 for Joint Ventures: Why Your JV Inherits 50% of Each Parent’s Headcount

A joint venture with forty staff and nine million euros of turnover looks, on its own accounts, like a small enterprise sitting comfortably outside NIS2. It usually is not. The size test in Article 2(1) does not read the JV’s accounts in isolation — it reads them through the Annex to Recommendation 2003/361/EC, which forces the JV to add a proportion of each parent’s figures to its own. For a two-parent JV, that proportion is rarely small.

This guide covers the scope arithmetic that decides the question, the shareholders’-agreement clauses that can double the number you have to add, which national authority supervises a JV owned across borders, and whose board carries the Article 20 liability. It is the entity-formation counterpart to our NIS2 due diligence checklist for mergers and acquisitions — the analysis there starts from a target with its own history, while a JV starts from nothing and inherits everything.

Does NIS2 Apply to Your Joint Venture?

Three conditions must all hold. Ownership structure is irrelevant to the first and third; it only bites on the second, and there it bites hard.

Test What it asks about the JV entity Does ownership matter?
1. Activity Does the JV itself carry out an activity of a type listed in Annex I or Annex II — energy, transport, health, digital infrastructure, manufacturing, waste, chemicals, and the rest? [1] No. The parents’ sectors are not inherited. A JV formed by two energy groups to run a logistics platform is assessed as transport, not energy.
2. Size Has the JV stopped being a small enterprise — 50 or more staff, or turnover and balance-sheet total both above EUR 10 million — after partner and linked data are aggregated under Annex Articles 3 and 6? [8] Yes, decisively. This is the whole of the JV problem.
3. Union nexus Does the JV provide its services or carry out its activities within the Union? [1] No. A JV incorporated outside the EU that serves EU customers is caught, and must designate a representative under Article 26(3). [5]

Two shortcuts bypass the size test entirely. If the JV provides public electronic communications networks or services, trust services, or operates a TLD registry or DNS service, Article 2(2)(a) applies it regardless of size [1]. And a Member State can designate any Annex I or II entity as in scope under Article 2(2)(b) to (e) — sole provider, public-safety impact, systemic risk, regional criticality. A single-purpose JV built to run one national piece of infrastructure is precisely the profile those points were written for.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

If the JV clears the activity test, everything now turns on arithmetic.

Why Most Two-Parent JVs Cannot Be Autonomous

The Annex sorts every enterprise into one of three boxes, and only the first one lets you use your own accounts alone. An autonomous enterprise is defined negatively: one that is "not classified as a partner enterprise within the meaning of paragraph 2 or as a linked enterprise within the meaning of paragraph 3" [8]. A partner relationship exists once an upstream enterprise holds "25 % or more of the capital or voting rights" of the downstream one.

Now do the structural check. In a JV with two parents, the shares sum to 100%, so at least one parent must hold 50% or more, and in a 50/50 vehicle both do. Either way the 25% line is crossed. A two-party joint venture between ordinary trading companies cannot be an autonomous enterprise. No cap table achieves it.

Two carve-outs qualify that, and both turn up regularly in JV work. Annex Article 3(2) allows an enterprise to be ranked as autonomous even above 25% where the holder is a business angel investing less than EUR 1,250,000, a university or non-profit research centre, an institutional investor including a regional development fund, or an autonomous local authority with a budget below EUR 10 million and fewer than 5,000 inhabitants — provided that investor is not also linked under paragraph 3 [8]. A spin-out held by a university and a development fund can therefore be autonomous where a commercial JV cannot.

The second carve-out is specific to this Directive. Article 2(1) provides that "Article 3(4) of the Annex to that Recommendation shall not apply for the purposes of this Directive" [1] — switching off the rule that 25% or more public ownership disqualifies an enterprise from SME status entirely. Public-private JVs, from municipal utilities to state-backed infrastructure vehicles, are therefore not pushed out of the SME category for NIS2 purposes the way they are under other EU programmes, and Germany’s BSI applies the Recommendation on exactly that basis, with the exception of Article 3(4) of the Annex [9]. Note the limit: paragraphs 3(2) and 3(3) are untouched, so aggregation still runs normally.

Widely syndicated ventures are the other route out. Five founding partners at 20% each are all below 25%, and the JV can be autonomous — provided no partner also holds a control right under paragraph 3, and provided none of them are linked to each other. All of this is worth knowing before the shareholding is negotiated rather than after.

The Commission’s own guidance is unusually direct on jointly controlled entities. Its glossary explains that proportionate consolidation is "usually used for the consolidation of a jointly controlled entity" and that enterprises consolidated on that basis "are usually treated as partner enterprises" [8]. So the default classification for a conventional JV is partner. The default is also the best case.

Partner or Linked? The Shareholders’ Agreement Decides, Not the Cap Table

The difference between the two classifications is a factor of two or more, and most JV teams assume equity settles it. It does not. Annex Article 3(3) lists four independent routes to a linked classification, and three of them are governance rights that live in the shareholders’ agreement or the articles of association rather than on the share register [8].

Feature commonly found in a JV agreement Annex Art. 3(3) route Result
Parent holds a simple majority of voting rights (a) majority of shareholders’ or members’ voting rights Linked — 100% of that parent’s group data
Parent has the right to appoint or remove a majority of the JV board, or appoints a chair with a casting vote that produces a board majority (b) "right to appoint or remove a majority of the members of the administrative, management or supervisory body" Linked — 100%
Reserved-matters list or a management agreement giving one parent decisive say over the JV’s operations (c) "right to exercise a dominant influence" under a contract or the articles Linked — 100%, on the facts
Voting agreement or pooling arrangement letting one shareholder control a majority of votes (d) shareholder that "controls alone, pursuant to an agreement with other shareholders", a majority of votes Linked — 100%
Genuine 50/50 with deadlock provisions, no casting vote, symmetric board rights None triggered Partner — 50% of each parent’s group data

The practical consequence: a 50/50 JV whose agreement gives Parent A the chair, the casting vote, and the right to appoint three of five directors is very likely a linked enterprise of Parent A, and takes 100% of Parent A’s consolidated group figures — not 50%. The equity split reads as balanced; the classification does not follow it.

Two cautions. First, paragraph 3(c) and (d) are fact-specific, and the assessment turns on the actual terms rather than on labels. Second, do not expect a regulator to confirm your answer in advance. Germany’s BSI states that it issues no binding notification of individual scope or non-scope, that it cannot carry out a legal assessment of the individual case in response to such enquiries, and that entities with remaining doubts should take external legal advice [9]. Whichever classification you adopt, the documented reasoning behind it is the defence you will have.

Running the Calculation: Article 6(2) and the Cascade Everyone Misses

Annex Article 6(2) sets the mechanics. Partner data is added "proportional to the percentage interest in the capital or voting rights (whichever is greater)", and 100% of the data of any linked enterprise is added on top [8]. The phrase "whichever is greater" matters in JVs, where economic and voting interests are frequently deliberately different — a 30% equity / 50% voting structure aggregates at 50%.

The step almost every commentary omits sits in Article 6(3): when you take a partner’s data, you first take that partner’s own accounts "and to these is added 100 % of the data of enterprises which are linked to these partner enterprises" [8]. You are not pro-rating the parent holding company. You are pro-rating the parent’s entire consolidated group.

A worked illustration, using hypothetical figures. A 50/50 JV has 40 staff and EUR 9 million turnover. Parent A’s group has 12,000 staff and EUR 4.1 billion turnover; Parent B’s group has 900 staff and EUR 180 million.

  • JV’s own data: 40 staff, EUR 9m
  • Plus 50% of Parent A’s group: 6,000 staff, EUR 2.05bn
  • Plus 50% of Parent B’s group: 450 staff, EUR 90m
  • Total: 6,490 staff, EUR 2.15bn

The JV is not merely in scope. It exceeds the medium-sized ceilings comfortably, which under Article 3(1)(a) makes it an essential entity if its activity sits in Annex I [2] — the higher supervisory tier, subject to the proactive inspections, random checks and security scans in Article 32(2) without any trigger [10]. Note the two boundaries do different work: 50 staff or EUR 10 million decides in or out, while 250 staff or EUR 50 million decides important or essential.

Run this calculation before the JV signs its first customer contract, not at its first audit. The same aggregation logic applies to wholly owned entities, which we cover in NIS2 subsidiary compliance.

A New JV Starts With a Business Plan, Not a Grace Period

Established companies get a cushion. Annex Article 4(2) provides that exceeding the ceilings does not change an enterprise’s status "unless those ceilings are exceeded over two consecutive accounting periods" [8]. A newly incorporated JV cannot use it, for the simple reason that it has no prior status and no approved accounts to be measured against.

What applies instead is Article 4(3): "In the case of newly established enterprises whose accounts have not yet been approved, the data to apply is to be derived from a bona fide estimate made in the course of the financial year" [8]. The Commission’s guide specifies what that estimate looks like — a declaration "in the form of a business plan" covering the profit-and-loss account, balance sheet and forecast headcount, with a narrative on the core activity, "dated and signed by a person entitled to engage the company" [8].

So the sequence at formation is: build the aggregated estimate, sign it, and if it clears the ceilings, treat the JV as in scope from the day it starts providing services. The parallel rule for acquisitions — where the Commission states that Article 4.2 does not apply to enterprises exceeding the thresholds through a change of ownership, so loss of SME status "may be immediate" [8] — points the same way. Neither route offers a runway.

Recital 16: The Independence Argument, and Why It Is a National Lottery

There is one relief mechanism, and it is narrower than it first appears. Recital 16 states that Member States "are able to take into account the degree of independence an entity enjoys in relation to its partner or linked enterprises when applying Article 6(2) of the Annex", specifically independence "in terms of the network and information systems that that entity uses in the provision of its services" [7]. The counterfactual it describes is whether the entity would have been under the ceilings "in the event that only its own data had been taken into account".

Three limits govern how you can use this. It is a recital — interpretive, not operative — so it creates no right and no obligation. It is an option, so it exists only where a Member State has taken it up; Germany has, in section 28(4) sentence 2 BSIG, which the BSI describes as excluding partner and linked data where the entity is independent as regards the nature and operation of its information systems, components and processes [9]. And the recital expressly "leaves unaffected the obligations laid down in this Directive of partner and linked enterprises which fall within the scope" [7] — the parents’ own duties are untouched.

For a JV the practical warning runs in the opposite direction to intuition. Sharing a parent’s ERP, identity provider, network or SOC is usually the cheapest way to launch a JV, and it is also the step that destroys the independence argument in the only Member States that offer it. If the relief matters to you, the IT separation decision has to be made at formation, and documented as such. If the JV instead buys those services from a parent, treat it as any other outsourcing arrangement — the analysis in our guide to outsourcing NIS2 obligations to an MSSP applies unchanged.

Which Authority Supervises a JV Owned Across Borders?

The default is simple and it disposes of most cases: entities fall under the jurisdiction of the Member State "in which they are established" [5]. A JV incorporated in Poland by a German parent and a French parent answers to Poland. The nationality of the shareholders is not a jurisdictional fact under Article 26(1), and there is no NIS2 one-stop shop.

The exception is Article 26(1)(b), which puts DNS providers, TLD registries, domain registration services, cloud, data centre and CDN providers, managed service and managed security service providers, online marketplaces, search engines and social platforms under the Member State of their main establishment [5]. That is where JV structures get genuinely difficult, because Article 26(2) defines main establishment as the place where "cybersecurity risk-management measures are predominantly taken" — and in a JV, security decisions are frequently taken in a parent’s head office in a different Member State from the JV’s registered seat. Where that cannot be determined, the test falls to where cybersecurity operations are carried out, and failing that to the establishment with the highest number of employees in the Union [5].

For a digital-infrastructure JV, therefore, delegating security governance to a parent’s group CISO function can move the supervising authority to that parent’s country. That is a defensible outcome if chosen deliberately and documented; it is an unpleasant surprise if discovered during registration. The full decision logic is set out in our guide to Article 26 jurisdiction. Whichever authority applies, changes to registered details are notifiable "without delay, and, in any event, within two weeks of the date of the change" under Article 3(4) [2] — a clause JV secretariats routinely miss when board composition or contact points change.

Governance: The JV Board Is Liable, and the Parents Are Suppliers

Article 20(1) requires that "the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements" [3]. The management body in question is the JV’s own board. Directors seconded from a parent sit on that board in their capacity as JV directors, and the training duty in Article 20(2) attaches to them personally [3]. A parent’s board approving a group cybersecurity policy does not discharge Article 20 for the JV, and Germany’s BSI is explicit on the analogous point: where a parent and a subsidiary are each an in-scope entity type, both are captured and both are subject to the security requirements — parent-level compliance does not cover the other [9].

There is a second consequence that JV teams consistently miss. If the JV runs on a parent’s infrastructure or buys security services from a parent, that parent is a direct supplier of the JV for the purposes of Article 21(2)(d), which covers "security-related aspects concerning the relationships between each entity and its direct suppliers or service providers" [4]. Article 21(3) then requires the JV to take into account "the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices" of that supplier [4]. In practice that means the JV must run a supplier assessment of its own shareholder, hold the evidence, and be prepared to show it. It is politically awkward, and Article 21(2)(d) contains no carve-out for a supplier that happens to be a shareholder.

Role Owns Cannot delegate
JV board (incl. seconded directors) Approval and oversight of Article 21 measures; Article 20(2) training Liability under Article 20(1) — it does not transfer to a parent board
JV compliance lead Registration and change notifications; incident reporting; the documented scope determination Filing on behalf of the JV as a distinct legal person
Parent group CISO (services provider) Delivering agreed security services to the JV under contract Being the subject of the JV’s own Article 21(2)(d) supplier assessment
Parent legal / corporate secretariat Keeping the shareholders’ agreement aligned with the classification actually relied on Notifying changes affecting the classification within the Article 3(4) two-week window

What a Fine Would Actually Be Calculated On

Article 34 sets the ceilings, and its turnover limb contains an unresolved question for jointly controlled entities.

Classification Maximum of at least Or Comparator
Essential entity EUR 10,000,000 2% of total worldwide annual turnover of "the undertaking to which the essential entity belongs" Whichever is higher [6]
Important entity EUR 7,000,000 1.4% of total worldwide annual turnover of "the undertaking to which the important entity belongs" Whichever is higher [6]

NIS2 does not define "undertaking". For a wholly owned subsidiary the answer is obvious. For a jointly controlled JV it is not, and two readings are genuinely available: the undertaking is the JV alone, putting a small venture close to the fixed euro floor; or the undertaking extends to a controlling parent’s group, putting the percentage limb into the billions. We found no competent-authority guidance resolving it and no published enforcement decision testing it. Treat the exposure range as open, plan against the higher reading, and note that Article 34(1) and (3) require fines to be effective, proportionate and dissuasive with regard to the individual case [6]. Fines are also not the first step — Article 32(4) runs warnings, binding instructions and orders before any fine, and Article 32(5)(b) can escalate to temporarily prohibiting a natural person responsible at chief executive officer or legal representative level from exercising managerial functions in that entity [10]. For a JV that is its own CEO or legal representative — frequently a parent secondee — and the prohibition bites on the JV role, not on the role held at the parent.

Frequently Asked Questions

Our JV has 12 employees. Do we really need to run this calculation?
Yes, if it carries out an Annex I or II activity. Headcount alone tells you nothing until aggregation is applied, and 12 own staff plus 50% of two large parents’ groups clears the ceilings without difficulty [8].

Both parents are already NIS2 compliant. Isn’t the JV covered?
No. Obligations attach to each legal person separately. Germany’s BSI confirms that where a parent and a subsidiary sharing IT are each an in-scope entity type, both are captured and both are subject to the requirements [9]. Recital 16 similarly leaves the parents’ own obligations unaffected [7].

One parent is outside the EU. Does its data still count?
Yes. The BSI states that linked enterprises which do not operate in Germany or in the EU are still included in the size-cap calculation [9]. The Annex draws no territorial limit on aggregation.

Can we structure the JV to stay out of scope?
Not through the two-parent equity split, which always crosses the 25% line. The available levers are the activity itself, keeping control rights symmetric so the classification stays partner rather than linked, and — only in Member States that have taken up the Recital 16 option — genuine independence of the JV’s own network and information systems [7][8].

Which parent files an incident report?
Neither. The JV is a distinct legal person under the jurisdiction of the Member State where it is established, and it files its own notifications with its own competent authority or CSIRT [5]. Parent reporting lines are an internal matter, not a substitute.

Where to Start

Do three things in order. Pull the shareholders’ agreement and the articles and test them against Annex Article 3(3)(a) to (d) — that single check decides whether you aggregate at 50% or 100%. Then run the Article 6(2) and 6(3) calculation against each parent’s full consolidated group, not the holding company, and write down the result with its reasoning and date. Finally, confirm the JV’s own registration and notification obligations in its state of establishment, and diary the two-week change window in Article 3(4).

If the answer comes out in scope, the JV needs its own control set, its own board approval record and its own evidence — three things that a parent’s programme cannot supply on its behalf. Our NIS2 scope test walks through the activity side of the assessment in more detail.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Directive (EU) 2022/2555, Article 2 — Scope
  2. Directive (EU) 2022/2555, Article 3 — Essential and important entities
  3. Directive (EU) 2022/2555, Article 20 — Governance
  4. Directive (EU) 2022/2555, Article 21 — Cybersecurity risk-management measures
  5. Directive (EU) 2022/2555, Article 26 — Jurisdiction and territoriality
  6. Directive (EU) 2022/2555, Article 34 — General conditions for imposing administrative fines
  7. Directive (EU) 2022/2555, Recital 16 (interpretive, non-binding)
  8. European Commission, User Guide to the SME Definition — reproducing the Annex to Recommendation 2003/361/EC
  9. Bundesamt für Sicherheit in der Informationstechnik, "FAQ zu NIS-2" (bsi.bund.de)
  10. Directive (EU) 2022/2555, Article 32 — Supervisory and enforcement measures in relation to essential entities
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: