The question arrives in two forms: "do we have to register under NIS2?" and "we missed the registration date, what now?". Both have the same first answer: there are two registrations in Directive (EU) 2022/2555, with different entities, different items, different deadlines and different recipients, and most companies that ask are on one list and a few are on both. This article is the two lists as the Directive writes them, read from the text, with the dates and what to keep.
The first list: every essential and important entity (Article 3(3) and (4))
Article 3(3): "By 17 April 2025, Member States shall establish a list of essential and important entities as well as entities providing domain name registration services", reviewed and updated regularly and "at least every two years thereafter". The list is the state's, not the entity's, but the entity feeds it. Article 3(4) makes the member states require those entities to submit "at least the following information to the competent authorities":
| Article 3(4) | What is submitted |
|---|---|
| (a) | The name of the entity |
| (b) | The address and up-to-date contact details, "including email addresses, IP ranges and telephone numbers" |
| (c) | Where applicable, the relevant sector and subsector of Annex I or II |
| (d) | Where applicable, a list of the member states where the entity provides services in scope of the Directive |
Changes are notified "without delay, and, in any event, within two weeks of the date of the change". The Commission, with ENISA, provides guidelines and templates, and member states "may establish national mechanisms for entities to register themselves", which is the self-registration portal a company meets in practice. "At least" means a state may ask for more through those mechanisms.
Article 3(5) says what the list is for: by 17 April 2025 and every two years, the competent authorities notify the Commission and the Cooperation Group of the number of essential and important entities per sector and subsector, and the Commission of information about the entities identified under the size-blind rules of Article 2(2), points (b) to (e). The list is how a supervisor knows whom to supervise, and how the Union counts its regulated population.
The second list: ENISA's registry of digital entities (Article 27)
Article 27(1) has ENISA "create and maintain a registry" of eleven types of entity: DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, of online search engines and of social networking services platforms. These are the entities whose jurisdiction follows their main establishment rather than every state they serve (Article 26(1)(b)), which is why the Union wants one register of them. A SaaS company is a cloud computing service provider and an MSP or MSSP is on the list by definition, so most software and IT-services companies that are in scope at all are on this second list too.
Article 27(2) makes the member states require those entities to submit the following "by 17 January 2025":
| Article 27(2) | What is submitted |
|---|---|
| (a) | The name of the entity |
| (b) | The relevant sector, subsector and type of entity of Annex I or II, where applicable |
| (c) | The address of the entity's main establishment and its other legal establishments in the Union or, if not established in the Union, of its representative designated under Article 26(3) |
| (d) | Up-to-date contact details, including email addresses and telephone numbers of the entity and, where applicable, of its representative |
| (e) | The member states where the entity provides services |
| (f) | The entity's IP ranges |
Changes are notified "without delay and in any event within three months of the date of the change" (Article 27(3)). The single point of contact forwards the information to ENISA, "except for that referred to in paragraph 2, point (f)": the IP ranges stay national (Article 27(4)). Where a state has a national self-registration mechanism under Article 3(4), the Article 27 submission goes through it (Article 27(5)). The registry is not public: ENISA gives the competent authorities access on request, "while ensuring that the confidentiality of information is protected" (Article 27(1)), so a company cannot look itself up, and a customer cannot check a supplier there.
Which state, and what registering does not decide
The recipient is the competent authority of the state that has jurisdiction. For most entities that is the state of establishment (Article 26(1)); for the eleven digital types it is the state of the main establishment, "the Member State where the decisions related to the cybersecurity risk-management measures are predominantly taken", failing that where cybersecurity operations are carried out, failing that the establishment with the most employees in the Union (Article 26(2)). An entity not established in the Union that offers those services in it designates a representative in one of the states where it does (Article 26(3)), and registers there. Each member state's page names the act the state communicated as its NIS2 law and its CSIRT; the transposition register is where the national mechanism is found, because the Directive does not name it.
Registering does not decide whether you are essential or important; the size rule and the size-blind rules do, and the state's list records the outcome. Not registering does not take you out of scope: Article 3(4) is an obligation on the entity, and Article 36 makes the member states lay down penalties for infringements of the national measures, "effective, proportionate and dissuasive", which is where a late or missing registration is sanctioned. The two dates, 17 January 2025 and 17 April 2025, have passed; an entity that missed them still has the obligation and discharges it by submitting now, through the national mechanism where one exists, and by keeping the two-week and three-month change deadlines from then on.
The record to keep
What survives an authority's question is a registration record: the items submitted, under which article, to which authority, on which date, with the acknowledgement; and a change log, because the items that change most, contact details, IP ranges, the states served, are the ones with a deadline of two weeks or three months attached. The Annex I or II type in item (b) of Article 27(2) is the same row the scope determination starts from, in the reader's language, and the state it names is the one whose authority receives the submission.
Sources
- Directive (EU) 2022/2555 (NIS2), Article 2(2), Article 3(3) to (5), Article 26(1) to (3), Article 27, Article 36, recital 117.
This is not legal advice. The registration mechanism, the form and the penalty for a missed date are in each member state's transposing act, which is the text to read after the Directive.