Your Online Marketplace Is an NIS2 Important Entity: 7 Security Requirements Platform Operators Must Document Before an Audit
An online marketplace with 60,000 registered sellers and €30 million annual turnover qualifies as an NIS2 important entity under Annex II of the NIS2 Directive — even if you have never thought of your platform as critical infrastructure. The moment your service facilitates third-party transactions between buyers and sellers, the EU’s cybersecurity framework applies to you directly.
Most compliance guides for marketplaces stop at the surface: here are Article 21’s ten measures, report incidents within 24 hours. What they omit is the marketplace-specific layer — which Article 21 sub-clauses require documentation tailored to platform operators rather than standard enterprises, exactly when a DDoS attack during peak trading hours becomes a mandatory notification event, and how the Digital Services Act’s seller obligations interact with NIS2 so you are not running two separate compliance programmes. This guide covers what the regulation actually requires for your sector, based on the NIS2 Directive (EU) 2022/2555 and Commission Implementing Regulation (EU) 2024/2690.
Does Your Platform Qualify? The Marketplace vs. Retailer Test
The operative distinction is intermediary vs. direct seller. NIS2 Annex II, Section 7 includes “providers of online marketplaces” — platforms that use a website, application, or part of a website to allow consumers to conclude distance contracts with other traders or consumers. A business selling its own inventory directly to consumers is not an online marketplace under NIS2. The scope trigger is third-party seller functionality: if your platform gives sellers the ability to upload listings, set prices, and complete transactions on your infrastructure, you qualify.

As stated in the regulatory analysis: “If you as a public online platform provide functionality to third-party sellers to upload and list their products on your platform and sell them, then you come into the scope of Annex II.”
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
| Business model | In scope? | Reason |
|---|---|---|
| Multi-seller marketplace (Amazon model) | Yes | Facilitates third-party distance contracts |
| Pure e-retailer (sells own inventory only) | No | No intermediary function |
| Hybrid (own inventory + third-party sellers) | Yes — marketplace component | Third-party functionality triggers scope |
| B2B procurement platform with supplier listings | Yes | Intermediary test satisfied |
| Auction platform with third-party sellers | Yes | Facilitates distance contracts |
The size threshold is OR, not AND: ≥50 employees or ≥€10 million annual turnover. You need only one to qualify as an important entity. This catches most mid-size platforms well before they reach 100 employees — a marketplace with 55 staff and €8 million in commission revenue qualifies solely on headcount.
Important entity status carries reactive supervision: national authorities investigate based on reported incidents or complaints, rather than scheduling proactive audits. For a full breakdown of how the entity classification determines your supervisory regime, see Essential vs Important Entity Under NIS2 and the NIS2 scope guide.
Four Marketplace-Specific Risk Categories Your NIS2 Policy Must Address
Article 21(2)(a) requires a risk analysis and information system security policies as its first obligation. For marketplace operators, a standard corporate risk register does not capture the platform-specific exposure that auditors will look for. There are four risk categories that your NIS2 policy documentation must address explicitly.

1. Seller account hijacking leading to fraudulent transactions. Compromised seller credentials give attackers access to payment settlement controls, customer order data, and the ability to reroute purchases or drain settlement balances. Article 21(2)(i) mandates multi-factor authentication. Your risk register must document how MFA is enforced for seller logins, API tokens, and admin settlement functions — and what incident response steps activate when a seller account shows anomalous financial activity. This is not a general access control risk; it is a marketplace-specific threat vector with direct fraud and reputational consequences.
2. DDoS attacks timed to peak trading periods. A distributed denial-of-service attack launched during Black Friday, a flash sale, or a major product launch is not a general availability event — it is a targeted commercial attack on the window when your platform generates the highest transaction volume. NIS2 Article 21(2)(e) requires network security and, explicitly per Commission guidance, measures to minimise the attack surface. For marketplaces, your network security policy must document DDoS mitigation at the transaction-handling infrastructure layer, not just generic perimeter controls.
3. Payment gateway integrations and PCI-DSS overlap. Marketplace operators integrating payment gateways face obligations under both NIS2 and PCI-DSS v4.0. The two frameworks share substantial control alignment — access control, encryption, and vulnerability scanning appear in both. NIS2 Article 21(2)(h) requires cryptography and encryption policies; PCI-DSS Requirement 3 requires cardholder data protection. A single control set can satisfy both, but your NIS2 documentation must show the Article 21(2)(h) mapping explicitly — a PCI-DSS attestation alone does not satisfy your NIS2 auditor.
4. Fraudulent product listing injection via compromised seller accounts or exploited listing APIs. Malicious actors who gain access through compromised credentials or API vulnerabilities can inject counterfeit, unsafe, or prohibited product listings at scale. This is both a Digital Services Act risk (harmful content obligations) and a NIS2 supply chain security risk under Article 21(2)(d). Your supply chain security documentation must address seller onboarding verification procedures and listing integrity controls, treating the seller ecosystem as part of your supply chain for NIS2 purposes.
Article 21’s Seven Requirements in a Marketplace Context
Article 21(2) provides ten security measures. Seven translate directly to documentary obligations an auditor will examine for a marketplace operator. The remaining three — cybersecurity training, basic hygiene practices, and human resources security — require process records and policy documents, but the seven below demand documentation tied specifically to your platform architecture.

| Requirement | Article 21 sub-clause | What auditors look for in a marketplace context |
|---|---|---|
| Risk analysis policy | Article 21(2)(a) | Risk register covering the four marketplace-specific categories; residual risk acceptance documentation |
| Incident handling | Article 21(2)(b) | Incident response plan referencing CIR 2024/2690 Article 11 thresholds; escalation paths to national CSIRT |
| Business continuity | Article 21(2)(c) | BCP with recovery time objectives for checkout infrastructure; peak trading scenario planning |
| Supply chain security | Article 21(2)(d) | Seller onboarding security policy; third-party API security clauses; payment gateway risk assessment |
| Network security | Article 21(2)(e) | Architecture documentation; DDoS mitigation controls; firewall and malware detection configuration |
| Access control and MFA | Article 21(2)(i) | MFA enforcement for seller portals, admin panels, and settlement functions; access revocation procedures |
| Cryptography and encryption | Article 21(2)(h) | Encryption policy covering cardholder data, seller PII, and transaction data in transit and at rest |
The documentation requirement is not aspirational — under NIS2, management must approve these policies and accept accountability for their implementation. A security measure that exists operationally but lacks approved documentation does not satisfy Article 21. For the full context of what the directive requires, see the NIS2 Directive overview.
Article 11, CIR 2024/2690: When a Marketplace Outage Becomes a Mandatory Incident Report
Commission Implementing Regulation (EU) 2024/2690, which entered into force on 18 October 2024, defines exactly when an incident qualifies as significant for online marketplace providers. Article 11 sets four criteria — any one of which triggers reporting obligations.

Complete unavailability: Your marketplace is entirely unavailable to more than 5% of your EU user base or more than 1 million EU users, whichever threshold is smaller. For a platform with 500,000 EU registered users, complete unavailability affecting 25,000 users (5%) triggers the threshold. For a platform with 30 million EU users, the 1 million absolute cap applies before you reach 5%.
Degraded availability: Service is degraded — not fully unavailable, but materially impaired — at the same 5%/1 million user threshold.
Data compromise from malicious action: The integrity, confidentiality, or authenticity of stored, transmitted, or processed data is compromised through suspected malicious conduct, regardless of the number of users affected. A targeted breach of seller financial data triggers this criterion even if it affects only a small number of accounts.
Data compromise with broad user impact: A breach affecting more than 5% of your EU users or 1 million EU users triggers reporting even if the security event was not clearly malicious in intent.
A notable change in the final CIR: the draft implementing regulation referenced unavailability of “parts of [the marketplace’s] functionality” as a trigger. The final text narrowed this to the “entire service.” A checkout failure affecting one product category during a sale event is not automatically a significant incident; platform-wide unavailability is.
Once a significant incident occurs, the Article 23 reporting timeline applies: early warning to the national CSIRT within 24 hours; incident notification with initial severity assessment within 72 hours; and a final report with root cause analysis within one month.
NIS2 and the Digital Services Act: One Platform, Two Frameworks
Online marketplace operators above the 50-employee or €10M threshold face obligations under both NIS2 and the Digital Services Act (DSA, Regulation (EU) 2022/2065, applicable from February 2024). The two frameworks are complementary and address different dimensions of platform risk — but they target the same entities, and compliance planning should treat them together.
NIS2 covers: cybersecurity risk management across network and information systems, incident reporting to national competent authorities, and security of the platform’s own infrastructure.
DSA covers: illegal content and product removal obligations, seller identity verification (Know Your Business Customer, DSA Article 30), transparency in algorithmic recommendation systems, advertising disclosure, and complaint mechanisms for buyers.
The practical overlap is seller onboarding. NIS2 Article 21(2)(d) requires supply chain security documentation for direct suppliers — which, for a marketplace, includes the third-party sellers whose accounts access your infrastructure. DSA Article 30 requires verification of trader identity before allowing them to sell. A unified seller onboarding workflow that documents both the security assessment (NIS2) and identity verification (DSA) satisfies both obligations without duplicating effort.
Platforms exceeding 45 million active EU monthly users qualify as Very Large Online Platforms under the DSA, triggering systemic risk assessment obligations that go beyond what NIS2 requires. This threshold sits above the NIS2 important entity threshold, but growing platforms should track the 45 million user mark as a secondary compliance trigger.
Penalties, Management Liability, and Registration
Important entities face fines of up to €7 million or 1.4% of global annual turnover, whichever is higher. For a marketplace with €50 million global revenue, the effective ceiling is €700,000. The reactive supervision model means enforcement is triggered by incident reports and third-party complaints rather than scheduled inspections — but significant incident reports directly invite supervisory scrutiny.

NIS2 Article 20 requires senior management to approve cybersecurity risk management measures and to be held personally liable for infringements. For marketplace operators, the board or CEO cannot delegate compliance approval in its entirety to the security team. The governance paper trail — board resolution, management approval of the risk analysis, sign-off on the incident handling policy — is a distinct documentary requirement, separate from the technical security measures themselves.
Digital providers benefit from the one-stop-shop mechanism: your lead national authority is determined by where your main EU establishment is located, not by which member states your marketplace reaches. A marketplace with its main EU office in the Netherlands is supervised by the Dutch national authority, regardless of whether it serves buyers in 20 EU countries. Registration with the lead authority is required — timing varies by member state, so verify the current deadline with your national competent authority.
Frequently Asked Questions
Does NIS2 apply if our marketplace has no EU office but serves EU buyers? Yes, with a modification to the supervisory structure. The European Commission FAQ confirms that digital providers without an EU establishment must designate a representative in an EU member state and comply with the obligations of the member state where that representative is located. The one-stop-shop mechanism applies through the designated representative’s location.
Does ISO 27001 certification satisfy NIS2 Article 21? ISO 27001 provides a useful structural framework, and several NIS2 Article 21 obligations map to ISO 27001:2022 controls. However, certification does not constitute legal compliance — NIS2 adds specific obligations (incident reporting timelines, management accountability, CIR 2024/2690 sector-specific criteria) that ISO 27001 does not cover. The two frameworks are complementary, not interchangeable.
How does NIS2 incident reporting relate to GDPR breach notification? GDPR breach notification (72 hours to the data protection authority for breaches likely to result in a risk to individuals) and NIS2 incident reporting (24-hour early warning, 72-hour notification to the national CSIRT) run in parallel. A data breach affecting seller or buyer personal data may trigger both. The European Commission’s Digital Omnibus proposal (2026) is working toward a “report once, share many” mechanism to reduce duplication, but until that is in force, marketplace operators must file notifications separately under both regimes.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Advisera — Article 11: Significant incidents with regard to providers of online marketplaces [CIR 2024-2690]
- Advisera — CIR 2024-2690 Regulation full text in an easy-to-read format
- A&O Shearman — NIS2 Digital Providers get Implementing Regulation on cybersecurity risk management and significant incidents
- Flexiblebit — Whether online stores come into scope of NIS 2?
- Georg Keferböck — The NIS2 Directive Explained: What SaaS and eCommerce Businesses Actually Need to Do
- Gradum Blog — PCI DSS vs NIS2 — Comparison
- Pinsent Masons (Out-Law) — NIS2 cybersecurity standards proposed for digital providers
- ISMS.online — NIS 2 for Digital Providers: What Every Marketplace, Search, and Social Platform Must Know
- European Commission — NIS2 Directive FAQs
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
