Abstract global network map symbolizing cross-border NIS2 cybersecurity compliance for non-EU companies

NIS2 for Non-EU Companies: The US, UK, and Global Operations Compliance Test

Most guidance on this question gets the scope wrong in the same direction: it treats “your company sells into the EU” as the trigger. It isn’t. NIS2 reaches non-EU companies through exactly three legal pathways, and two of them have nothing to do with where your customers sit — they depend on whether you have an EU-established entity, or whether you’re one of eleven specifically named digital-infrastructure providers. Get the pathway wrong and you’ll either build a compliance program you don’t need, or miss one you do.

This guide sorts US, UK, and other non-EU headquartered companies into the pathway that actually applies to them, using the Directive’s own jurisdiction rules — not the “if you have EU customers, you’re probably in scope” shortcut that dominates search results on this topic.

Does NIS2 Apply to You? The Three-Pathway Scope Test

In plain terms: NIS2 catches a non-EU headquartered company in one of three ways — your EU subsidiary is its own in-scope entity, you’re a narrow category of digital-infrastructure provider without any EU establishment, or your EU customer is contractually pushing NIS2 requirements down to you as a supplier. Only the second pathway is genuinely extraterritorial in the way most explainer articles describe.

Pathway What triggers it Who this is Governing provision
A — EU-established subsidiary A legally established EU branch or subsidiary meets the Annex I/II sector + size-cap test in its own right Most US and UK groups with any real EU footprint Article 2 (scope) + Article 26(1)
B — Digital-infrastructure representative route No EU establishment at all, but you provide one of eleven specifically listed digital services into the EU Cloud, DNS, CDN, MSP/MSSP, marketplace, search, social platform providers only Article 26(3)
C — Indirect supply-chain pressure Your EU customer is an essential or important entity and pushes cybersecurity terms into your contract Any non-EU vendor to a regulated EU company Article 21(2)(d)

The narrowness of Pathway B is the detail most competing guides skip [1]. Article 26(1)(b) names exactly eleven entity types that can fall under NIS2 jurisdiction through a representative alone, with zero EU establishment: DNS service providers, top-level domain name registries, domain name registration service providers, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines, or social networking services platforms [1]. A US industrial manufacturer, a UK professional-services firm, or a Canadian food exporter selling directly into the EU is not one of these — and Article 26 gives no member state jurisdiction over them on that basis alone. If you don’t recognize your business in that list, Pathway A or Pathway C is where your real exposure lives, not Pathway B. (For the full jurisdiction mechanics once an entity is already in scope — including how “main establishment” is determined — see our complete Article 26 breakdown.)

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The EU-Subsidiary Pathway: Why Most US and UK Companies Are Already In Scope

If your organization has an EU-established branch or subsidiary, that entity is evaluated exactly like a domestic EU company — the parent’s headquarters location is irrelevant to the test. Article 2 sets the bar: an entity in one of the eighteen Annex I/II sectors that qualifies as at least a medium-sized enterprise under Commission Recommendation 2003/361/EC (50+ employees, or over €10 million in both annual turnover and balance sheet total) is in scope as an important entity; cross into large-enterprise territory (250+ employees or over €50 million turnover) in an Annex I sector and it becomes an essential entity [2]. A handful of entity types — public electronic communications providers, trust service providers, TLD registries, and DNS providers — are in scope regardless of size [2].

This is the pathway that catches the majority of US and UK groups that discover a NIS2 obligation: not because headquarters in California or London sold anything into the EU, but because a German manufacturing subsidiary, an Irish shared-services center, or a French sales office already crossed the medium-enterprise threshold years ago and simply never had a NIS2 program built around it. Article 20 attaches liability directly to “management bodies of essential and important entities” that fail to approve or oversee Article 21 risk-management measures [4] — that’s the EU subsidiary’s own board or equivalent, not automatically the non-EU parent’s directors, though reputational and contractual fallout for the parent is a separate, real exposure.

The Representative Pathway: Article 26(3) for Cloud, SaaS, MSPs, and Digital Platforms

For the eleven entity types in Pathway B, the rule is unambiguous: if you’re not established in the Union but offer that service within it, you must designate a representative established in one of the member states where you offer the service, and that member state becomes your jurisdiction [1]. Skip this and you don’t escape enforcement — you invite it from more places at once. Without a designated representative, “any Member State in which the entity provides services may take legal actions against the entity for the infringement of this Directive” [1]. Designating a representative afterward doesn’t retroactively shield you from action already initiated against the entity directly, either [1].

In practice, representative selection is a strategic decision, not an administrative afterthought — and it’s one most guides skip entirely. Two factors should drive the choice: first, whether the target member state’s NIS2 transposition is actually operational (see the country snapshot below — a representative registered in a country whose registration portal hasn’t opened yet buys you paperwork, not protection); second, whether the same legal entity can plausibly serve as your representative under other EU regimes at once. A 2024 IAPP analysis of overlapping EU-representative obligations across GDPR, the Digital Services Act, and NIS2 found the roles are legally distinct — a GDPR representative is a contact point for data-subject rights and regulatory correspondence, while a NIS2 representative faces a separate registration and must be equipped for time-critical, technically detailed incident communications [11] — so treat them as separate appointments even if you consolidate them with one provider.

The UK Angle: Why “We Follow UK Rules” Isn’t the Same as NIS2 Compliance

UK companies routinely assume that domestic cybersecurity regulation gets them equivalent coverage. It doesn’t, and the UK government’s own framing makes that explicit. The Cyber Security and Resilience Bill — introduced to Parliament on 12 November 2025 and still under Parliamentary consideration through mid-2026 [10] — updates the UK’s post-Brexit NIS Regulations 2018, adding managed service providers (medium and large), data centres as essential services, large electricity load controllers, and designated critical suppliers to scope [9]. The government’s own factsheet is direct about its limits: “The regime does not cover every UK organisation. It is about those services which are so essential, that their disruption would affect our daily lives” [9].

Two things follow. First, the Bill is a UK-only instrument — the National Cyber Security Centre (NCSC) receives incident notifications and issues guidance, but it isn’t NIS2’s enforcement mechanism, and compliance with it creates no legal presumption of EU NIS2 compliance [9]. Second, a UK company with an EU subsidiary or with EU customers demanding Article 21(2)(d) supply-chain assurances still needs a separate, EU-facing compliance track — Pathway A or Pathway C above — regardless of what the Bill eventually requires domestically. Treat the two as parallel obligations you track separately, not one regime with two names.

What Happens Once You’re In Scope: Obligations and Penalties

Once a pathway confirms an obligation, the exposure is immediate and specific, not aspirational. Essential entities face administrative fines of a maximum of at least €10 million or 2% of total worldwide annual turnover, whichever is higher; important entities face a maximum of at least €7 million or 1.4% [3]. Incident notification runs on a fixed clock: an early warning within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report not later than one month after that 72-hour notification is submitted [5]. None of that is negotiable once you’re inside Pathway A or B — and it applies identically to a US-parented EU subsidiary as it would to a purely domestic EU company.

Entity classification Maximum fine Supervisory posture
Essential entity (large, Annex I sector) €10,000,000 or 2% of global turnover, whichever is higher Proactive supervision
Important entity (medium, or large in Annex II) €7,000,000 or 1.4% of global turnover, whichever is higher Reactive supervision (post-incident/complaint)

Current State: Which EU Countries Are Actually Enforcing NIS2 Right Now (Mid-2026 Snapshot)

The Directive’s transposition deadline was 17 October 2024, applying from 18 October 2024 [7]. Most member states missed that deadline outright [7][8], which matters directly for representative selection: a representative registered in a country whose national law isn’t yet in force is a paper appointment, not an operational one. As of mid-2026, that gap is closing unevenly and the Commission is applying real pressure. On 7 May 2025 the Commission sent reasoned opinions to 19 member states for failing to notify full transposition; by its July 2026 infringement package, it had referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU for still not fully transposing the Directive [7].

Germany is the clearest counter-example and the one non-EU companies should study. Its NIS2 Implementation Act (BSIG) became binding on 6 December 2025 with no transition period, pulling roughly 29,500 entities into scope — about five times the number covered under the prior regime — and requiring registration with the Federal Office for Information Security (BSI) within three months, a deadline that landed around 6 March 2026 [6]. Ireland, by contrast, still had no live registration portal as of its own regulator’s public guidance, pending national legislation [8]. The practical takeaway for a non-EU parent choosing where to route a Pathway B representative, or deciding which of several EU subsidiaries to prioritize for a Pathway A program: Germany is enforceable today; several other member states remain a moving target. Build to the Directive’s requirements everywhere, but sequence your registration and audit-readiness work around the countries where the law is already live.

GDPR Déjà Vu: How the Article 27 Representative Playbook Applies Here

If your organization already went through GDPR’s non-EU representative exercise, the underlying logic will feel familiar — and the differences matter more than the similarity. GDPR’s Article 3(2) extends the Regulation to non-EU controllers and processors whenever their processing relates to “the offering of goods or services… to such data subjects in the Union” or “the monitoring of their behaviour” within it [12]. That’s a genuinely broad test tied to individuals, not entity type. NIS2’s Article 26(3) representative obligation is much narrower — it only reaches the eleven digital-infrastructure entity types in Pathway B — but where it does apply, the representative’s job is operationally heavier: incident notification deadlines measured in hours, not the weeks typical of a GDPR data-subject request. Don’t assume your existing GDPR representative arrangement covers NIS2 by default; confirm the appointment, and the provider’s incident-response capability, separately against the two regimes.

Frequently Asked Questions

Does NIS2 apply to my US company if we have no EU office at all?
Only if you fall into one of the eleven Pathway B entity types (cloud, DNS, CDN, MSP/MSSP, marketplace, search engine, or social platform) and actively offer that service into the EU — in which case you need an Article 26(3) representative [1]. Outside that list, with no EU establishment, direct NIS2 jurisdiction generally doesn’t reach you; your exposure is more likely indirect, through an EU customer’s supply-chain security requirements under Article 21(2)(d).

What if my only EU presence is a distributor or reseller, not a subsidiary?
An independent distributor is its own legal entity and doesn’t automatically extend NIS2 jurisdiction to you. What it can do is create commercial pressure: if your distributor or an end customer is itself an essential or important entity, expect supply-chain security clauses in the contract regardless of your own scope status.

Can one representative cover both GDPR and NIS2?
Legally, nothing prevents the same provider from holding both roles, but they are distinct appointments with distinct responsibilities [11] — a GDPR representative is not automatically a valid NIS2 representative. Verify the provider explicitly accepts and is resourced for the NIS2 role, including 24-hour incident-notification capability.

My company is in the UK — do I still need to worry about EU NIS2?
Yes, if you have an EU subsidiary in scope (Pathway A), fall into a Pathway B entity type and serve the EU without EU establishment, or supply an EU-regulated customer (Pathway C). The UK’s own Cyber Security and Resilience Bill is a separate, UK-only regime and doesn’t substitute for EU NIS2 obligations on your EU-facing operations [9].

What happens if a non-EU company in scope simply ignores NIS2?
For Pathway A entities, enforcement runs exactly like it would against a domestic EU company, including fines up to €10 million or 2% of global turnover for essential entities [3]. For Pathway B entities without a designated representative, the Directive explicitly allows any member state where you provide services to bring action directly [1] — ignoring the representative requirement multiplies your exposure rather than avoiding it.

Key Takeaways

Sort yourself into a pathway before you sort your compliance program. If you have an EU subsidiary that clears the Annex I/II size-cap test, that entity needs a full Article 21 compliance program regardless of where its parent is headquartered. If you’re one of the eleven Pathway B digital-infrastructure types with no EU establishment, your obligation is narrower but non-negotiable: designate a representative in an EU country where NIS2 is actually in force, not just transposed on paper. If neither applies directly, assume Pathway C — contractual pressure through an EU customer’s own compliance program — is coming regardless. UK companies should treat the Cyber Security and Resilience Bill and EU NIS2 as two separate compliance tracks, not one regime under two names.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS 2 Directive, Article 26: Jurisdiction and Territoriality — nis-2-directive.com
  2. NIS 2 Directive, Article 2: Scope — nis-2-directive.com
  3. NIS 2 Directive, Article 34: Penalties — nis-2-directive.com
  4. NIS 2 Directive, Article 20: Governance — nis-2-directive.com
  5. NIS 2 Directive, Article 23: Incident Reporting Obligations — nis-2-directive.com
  6. NIS 2 Directive Transposed in Germany – Time to Register with the BSI — DLA Piper (dlapiper.com)
  7. NIS2 Directive Transposition in EU Countries — European Commission, Digital Strategy
  8. NIS2 FAQ — National Cyber Security Centre Ireland
  9. Summary of the Bill, Cyber Security and Resilience (NIS) Bill Factsheets — GOV.UK
  10. Cyber Security and Resilience Bill — Wikipedia
  11. The “Hidden Obligation” Rides Again! EU Representatives Under GDPR, DSA, NIS2 and Others — IAPP
  12. Art. 3 GDPR – Territorial Scope — gdpr-info.eu
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: