NIS2 REPRESENTATIVE

NIS2 Representative
in the European Union

Article 26 representation for specified digital and infrastructure entities that are not established in the European Union and offer services within the Union.

NIS2 ARTICLE26EU REPRESENTATION

OSTRAI acts as NIS2 Representative for eligible organisations requiring an EU representative under Article 26.

Our service combines scope and jurisdiction assessment, formal appointment, regulatory contact infrastructure, competent-authority and CSIRT interface, onboarding and continuing representation within a specialist cybersecurity and technology-regulation practice.

Not sure whether your organisation falls within the Article 26 categories? Start with the scope assessment.

ARTICLE 26 / CURRENT LAW

The conditions
behind the appointment.

  1. Is the entity within one of the Article 26 categories?

    If no: the current Article 26(3) representative rule does not apply.

    If yes

  2. Is it established
    in the Union?

    If yes: the Article 26(3) representative requirement does not arise on the basis of being not established in the Union.

    If no

  3. Does it offer services
    within the Union?

    If no: no Article 26(3) representative trigger.

    If yes

EU Representative required

The representative must be established in a Member State where the relevant services are offered.

CURRENT ARTICLE 26 SCOPE

Which entities can require
an NIS2 Representative?

Domain & internet infrastructure

  • DNS service providers
  • TLD name registries
  • Entities providing domain name registration services

Cloud & digital infrastructure

  • Cloud computing service providers
  • Data centre service providers
  • Content delivery network providers

Managed services & security

  • Managed service providers
  • Managed security service providers

Digital platforms

  • Providers of online marketplaces
  • Providers of online search engines
  • Providers of social networking services platforms

The representative requirement under the current Article 26 framework is specific to these categories.

Not sure whether your organisation falls within Article 26?

Request an Article 26 scope assessment

TERRITORIAL REACH

Offering services in the Union requires more than accessibility.

For the relevant Article 26 providers, the assessment considers whether the entity intends to offer services to persons in one or more Member States.

Indicators of an intention to offer services in the Union may include the use of a Member State language or currency in connection with ordering services, or references to customers or users in the Union. No single indicator is necessarily determinative.

Mere accessibility in the Union of a website, email address or contact details is not sufficient by itself.

Accessible from the EU

Not necessarily sufficient

Offering services in the EU

Requires evidence of intention to serve persons in one or more Member States

EU JURISDICTION

Where can the NIS2 Representative be established?

Article 26 requires the representative to be established in one of the Member States where the entity offers the relevant services.

Services may be offered across multiple Member States. The representative does not need to be established in the entity's only or principal European market.

OSTRAI Limited is established in Cyprus.

Where Cyprus is among the Member States in which the relevant service is offered, OSTRAI can be considered for appointment, subject to the applicable Article 26 conditions and OSTRAI's onboarding process.

As part of onboarding, OSTRAI reviews whether the relevant service offering and jurisdictional conditions support the appointment. Where substantive legal analysis is required, that assessment is scoped separately.

The appointment is service-specific and entity-specific.

REGULATORY INTERFACE

A representative inside the NIS2 supervisory framework.

Under the NIS2 definition of representative, the competent authority or CSIRT may address the representative in place of the entity itself regarding the entity's obligations under the Directive.

Article 26 also links the appointment to jurisdiction: the entity not established in the Union is considered to fall under the jurisdiction of the Member State where its representative is established.

The representative therefore sits inside the entity's regulatory relationship with the relevant Member State.

THE NIS2 REPRESENTATIVE INTERFACE

Two regulatory routes.
A defined relationship.

Competent
authority

CSIRT

NIS2 REPRESENTATIVE

OSTRAI

  • Regulatory contact
  • Authority communications
  • CSIRT interface
  • Escalation
  • Mandate coordination

Represented entity

  • Cybersecurity governance
  • Risk management
  • Incident response
  • Technical / operational compliance

OSTRAI is the regulatory interface. The entity retains the underlying compliance role.

YOUR REPRESENTATION SERVICE

A functioning NIS2
regulatory interface.

Formal Article 26 appointment

Written designation of OSTRAI within the agreed representative mandate.

Designated regulatory channel

A monitored OSTRAI channel for communications connected with the mandate.

Designated lead

A defined OSTRAI contact coordinates the representative relationship and material escalations.

Competent-authority communications

Receipt and coordination of communications directed to OSTRAI in its representative capacity.

CSIRT interface

Receipt and escalation of communications involving the competent CSIRT where relevant to the mandate.

Regulatory escalation

Defined provider contacts and procedures for urgent or time-sensitive communications.

Entity information

Support with representative-related information required for applicable NIS2 registration processes.

Mandate maintenance

Ongoing review of material changes affecting the entity, services, jurisdiction and representative appointment.

Need to appoint an NIS2 Representative?

Discuss the mandate with OSTRAI

REGULATORY COMMUNICATIONS

From regulatory contact
to coordinated response.

  1. Receive
  2. Log
  3. Triage authority / deadline
  4. Escalate
  5. Obtain entity information and instructions
  6. Coordinate
  7. Relay / facilitate
  8. Record

The represented entity remains responsible for the substantive accuracy of information, technical decisions and underlying NIS2 compliance.

Where a matter requires substantive NIS2 advice or incident-response support outside the representative mandate, that work can be separately scoped.

RESPONSIBILITY

Representation does not replace cybersecurity governance.

Designation of a representative does not prevent legal action against the entity itself.

Article 26(4) expressly preserves legal actions against the represented entity.

Represented entity

  • Cybersecurity risk management
  • Management oversight
  • Incident handling
  • Supply-chain measures
  • Business continuity
  • Compliance evidence

OSTRAI / NIS2 REPRESENTATIVE

Regulatory interface
in the European Union

JURISDICTION

Appointment determines
the Member State interface.

An entity covered by Article 26(3) that is not established in the Union is considered to fall under the jurisdiction of the Member State where its representative is established.

This makes the choice of representative part of the entity's regulatory architecture, not simply an administrative appointment.

OSTRAI is established in Cyprus.

CYPRUS

A European mandate.
A national supervisory interface.

Cyprus implemented NIS2 through amendments introduced by Law 60(I)/2025.

The Cyprus Digital Security Authority is the relevant national cybersecurity authority, and the national CSIRT framework operates under the Cyprus NIS legislation.

The Cyprus jurisdiction and territoriality rules reflect Article 26, including the representative mechanism for the specified entity categories not established in the Union.

ARTICLE 27
REGISTRATION INFORMATION

Among the information required:

  • Entity name
  • Sector / subsector / entity type
  • Representative address where applicable
  • Representative contact details
  • Member States where services are provided
  • IP ranges where required

CONTROLLED ACCEPTANCE

We assess the mandate before accepting the role.

Before accepting a NIS2 Representative mandate, OSTRAI reviews the entity, relevant services, Article 26 category, EU offering, establishment position, proposed representative jurisdiction, regulatory history and operational readiness.

Where scope, classification or jurisdiction requires substantive legal analysis, that assessment is scoped separately before the representative mandate.

The regulatory position and risk profile determine whether the mandate can proceed.

Discuss whether OSTRAI can accept the mandate

ONBOARDING

The information behind
an effective appointment.

Entity
Correct legal entity for the covered service
Article 26 category
Applicable provider classification
Services
Services covered by the mandate
EU offering
Member States in which the relevant services are offered
EU establishment
Relevant establishment analysis
Representative jurisdiction
Basis for the selected Member State and confirmation that it is among the Member States where the relevant service is offered
Regulatory history
Existing authority communications, investigations or material matters
Regulatory contacts
Primary · Emergency · Legal · Security
Registration information
Information required for relevant NIS2 registration processes
Operational readiness
Ability to support authority / CSIRT communications and regulatory deadlines
Start NIS2 representative onboarding

OPERATIONAL READINESS

A representative needs a responsive cybersecurity organisation behind it.

  • Primary regulatory contact
  • Cybersecurity / CISO contact
  • Secondary / emergency contact
  • Internal legal contact
  • Incident-response contact
  • Regulatory inbox
  • External cyber / legal advisers where relevant

The represented entity must be able to provide accurate and current information, instructions and technical context when authority or CSIRT communications arise.

SCOPE

Representation and
NIS2 implementation are distinct.

Standard representative mandate

  • Formal Article 26 appointment
  • Designated regulatory channel
  • Authority / CSIRT communications
  • Routine administrative coordination
  • Representative-related registration support where applicable
  • Escalation and mandate maintenance

Separately scoped support

  • NIS2 scope / classification assessment
  • Essential / important entity analysis
  • Cybersecurity risk-management implementation
  • Management-body governance
  • Incident-reporting support
  • Implementing Regulation 2024/2690 work
  • Supply-chain security
  • Business continuity / crisis management
  • Policies and evidence
  • Regulatory-response work
  • Cybersecurity certification / standards questions
  • Broader NIS2 advisory support

CYBERSECURITY REGULATION PRACTICE

Representation backed by substantive NIS2 capability.

OSTRAI's NIS2 Representative service sits within a specialist technology-regulation practice with substantive legal, cybersecurity and implementation expertise.

Our wider NIS2 work includes scope and classification, cybersecurity governance, Article 21 risk-management measures, incident reporting, implementation, supply-chain questions, regulatory interaction and the relationship between NIS2 and European cybersecurity standards and certification.

REGULATORY DEVELOPMENT

PROPOSAL / NOT CURRENT LAW

Article 26 is under
legislative review.

In January 2026, the European Commission proposed targeted amendments to NIS2.

Among other changes, the proposal would broaden the Article 26 representative rule beyond the specific provider categories currently listed in Article 26(1)(b), so that non-EU essential or important entities offering services in the Union would be required to designate an EU representative.

The proposal remains part of an ongoing legislative procedure.

OSTRAI monitors the development and will update its representation framework if the law changes.

WHY OSTRAI

Why organisations appoint
OSTRAI as NIS2 Representative

OSTRAI combines Article 26 representation infrastructure with cybersecurity-regulatory judgement, controlled acceptance and direct access to the team handling the mandate.

Article 26 focus

Representation structured around the actual jurisdiction and territoriality framework.

Controlled acceptance

The entity, services and jurisdictional basis are reviewed before representation begins.

Direct regulatory access

A designated OSTRAI contact and monitored regulatory channel.

Cybersecurity regulatory depth

Substantive NIS2 governance, implementation and regulatory capability.

Defined escalation

Clear routes for competent-authority and CSIRT communications.

Cross-regulatory view

Ability to identify intersections with DORA, CER, GDPR, CRA, cybersecurity certification and other European frameworks.

QUESTIONS & ANSWERS

Before
appointment.

Under current Article 26(3), an entity of a type listed in Article 26(1)(b) that is not established in the Union but offers services within the Union must designate a representative in a Member State where those services are offered. The entity, service classification and applicable NIS2 scope must be assessed.

No. Under the current Article 26 framework, the rule applies to the specified Article 26(1)(b) provider categories. It is not a general representative requirement for every essential or important entity.

The Article 26(1)(b) categories are DNS service providers, TLD name registries and entities providing domain name registration services; cloud computing, data centre and content delivery network providers; managed service and managed security service providers; and providers of online marketplaces, online search engines and social networking services platforms.

Cloud computing service providers are a listed Article 26(1)(b) category. Where the entity falls within the relevant NIS2 framework, is not established in the Union and offers services within the Union, Article 26(3) requires an EU representative. The actual service, entity and establishment position must be considered.

The representative must be established in one of the Member States where the relevant services are offered. The representative does not need to be established in the entity's only or principal EU market.

No. Cyprus only needs to be one of the Member States in which the relevant service is offered. It does not need to be the entity's sole or principal EU market. The relevant service and jurisdictional conditions are reviewed during onboarding before OSTRAI accepts a mandate.

Under Article 6(34), the representative is explicitly designated to act on behalf of the covered entity and may be addressed by the competent authority or CSIRT in place of the entity itself regarding its obligations under NIS2. OSTRAI provides the agreed regulatory interface, communications, escalation and mandate coordination.

No. The entity retains its underlying cybersecurity governance, risk-management and compliance responsibilities. Article 26(4) preserves legal actions that could be initiated against the entity itself.

Under current Article 26(3), in the absence of a designated EU representative, any Member State in which the entity provides services may take legal action against it for infringement of the Directive.

A Commission proposal published in January 2026 would broaden the representative rule to non-EU essential or important entities offering services in the Union. The legislative procedure remains ongoing. This is proposed scope, not the current enacted rule; the existing Article 26 framework remains the basis of the service until changes are adopted and applicable.

Still unsure whether Article 26 applies?

Discuss your position with OSTRAI

NIS2 REPRESENTATIVE

Put the right Article 26
representation structure in place.

OSTRAI supports eligible organisations without an establishment in the Union from Article 26 scope and jurisdiction assessment through onboarding, regulatory interface and continuing NIS2 representation in the European Union.