Domain & internet infrastructure
- DNS service providers
- TLD name registries
- Entities providing domain name registration services
NIS2 REPRESENTATIVE
Article 26 representation for specified digital and infrastructure entities that are not established in the European Union and offer services within the Union.
OSTRAI acts as NIS2 Representative for eligible organisations requiring an EU representative under Article 26.
Our service combines scope and jurisdiction assessment, formal appointment, regulatory contact infrastructure, competent-authority and CSIRT interface, onboarding and continuing representation within a specialist cybersecurity and technology-regulation practice.
Not sure whether your organisation falls within the Article 26 categories? Start with the scope assessment.
ARTICLE 26 / CURRENT LAW
If no: the current Article 26(3) representative rule does not apply.
If yes
If yes: the Article 26(3) representative requirement does not arise on the basis of being not established in the Union.
If no
If no: no Article 26(3) representative trigger.
If yes
The representative must be established in a Member State where the relevant services are offered.
CURRENT ARTICLE 26 SCOPE
The representative requirement under the current Article 26 framework is specific to these categories.
Not sure whether your organisation falls within Article 26?
TERRITORIAL REACH
For the relevant Article 26 providers, the assessment considers whether the entity intends to offer services to persons in one or more Member States.
Indicators of an intention to offer services in the Union may include the use of a Member State language or currency in connection with ordering services, or references to customers or users in the Union. No single indicator is necessarily determinative.
Mere accessibility in the Union of a website, email address or contact details is not sufficient by itself.
Not necessarily sufficient
Requires evidence of intention to serve persons in one or more Member States
EU JURISDICTION
Article 26 requires the representative to be established in one of the Member States where the entity offers the relevant services.
Services may be offered across multiple Member States. The representative does not need to be established in the entity's only or principal European market.
OSTRAI Limited is established in Cyprus.
Where Cyprus is among the Member States in which the relevant service is offered, OSTRAI can be considered for appointment, subject to the applicable Article 26 conditions and OSTRAI's onboarding process.
As part of onboarding, OSTRAI reviews whether the relevant service offering and jurisdictional conditions support the appointment. Where substantive legal analysis is required, that assessment is scoped separately.
The appointment is service-specific and entity-specific.
REGULATORY INTERFACE
Under the NIS2 definition of representative, the competent authority or CSIRT may address the representative in place of the entity itself regarding the entity's obligations under the Directive.
Article 26 also links the appointment to jurisdiction: the entity not established in the Union is considered to fall under the jurisdiction of the Member State where its representative is established.
The representative therefore sits inside the entity's regulatory relationship with the relevant Member State.
THE NIS2 REPRESENTATIVE INTERFACE
NIS2 REPRESENTATIVE
OSTRAI is the regulatory interface. The entity retains the underlying compliance role.
YOUR REPRESENTATION SERVICE
Written designation of OSTRAI within the agreed representative mandate.
A monitored OSTRAI channel for communications connected with the mandate.
A defined OSTRAI contact coordinates the representative relationship and material escalations.
Receipt and coordination of communications directed to OSTRAI in its representative capacity.
Receipt and escalation of communications involving the competent CSIRT where relevant to the mandate.
Defined provider contacts and procedures for urgent or time-sensitive communications.
Support with representative-related information required for applicable NIS2 registration processes.
Ongoing review of material changes affecting the entity, services, jurisdiction and representative appointment.
Need to appoint an NIS2 Representative?
Discuss the mandate with OSTRAIREGULATORY COMMUNICATIONS
The represented entity remains responsible for the substantive accuracy of information, technical decisions and underlying NIS2 compliance.
Where a matter requires substantive NIS2 advice or incident-response support outside the representative mandate, that work can be separately scoped.
RESPONSIBILITY
Designation of a representative does not prevent legal action against the entity itself.
Article 26(4) expressly preserves legal actions against the represented entity.
OSTRAI / NIS2 REPRESENTATIVE
Regulatory interface
in the European Union
JURISDICTION
An entity covered by Article 26(3) that is not established in the Union is considered to fall under the jurisdiction of the Member State where its representative is established.
This makes the choice of representative part of the entity's regulatory architecture, not simply an administrative appointment.
OSTRAI is established in Cyprus.
CYPRUS
Cyprus implemented NIS2 through amendments introduced by Law 60(I)/2025.
The Cyprus Digital Security Authority is the relevant national cybersecurity authority, and the national CSIRT framework operates under the Cyprus NIS legislation.
The Cyprus jurisdiction and territoriality rules reflect Article 26, including the representative mechanism for the specified entity categories not established in the Union.
ARTICLE 27
REGISTRATION INFORMATION
Among the information required:
CONTROLLED ACCEPTANCE
Before accepting a NIS2 Representative mandate, OSTRAI reviews the entity, relevant services, Article 26 category, EU offering, establishment position, proposed representative jurisdiction, regulatory history and operational readiness.
Where scope, classification or jurisdiction requires substantive legal analysis, that assessment is scoped separately before the representative mandate.
The regulatory position and risk profile determine whether the mandate can proceed.
Discuss whether OSTRAI can accept the mandateONBOARDING
OPERATIONAL READINESS
The represented entity must be able to provide accurate and current information, instructions and technical context when authority or CSIRT communications arise.
SCOPE
CYBERSECURITY REGULATION PRACTICE
OSTRAI's NIS2 Representative service sits within a specialist technology-regulation practice with substantive legal, cybersecurity and implementation expertise.
Our wider NIS2 work includes scope and classification, cybersecurity governance, Article 21 risk-management measures, incident reporting, implementation, supply-chain questions, regulatory interaction and the relationship between NIS2 and European cybersecurity standards and certification.
REGULATORY DEVELOPMENT
PROPOSAL / NOT CURRENT LAW
In January 2026, the European Commission proposed targeted amendments to NIS2.
Among other changes, the proposal would broaden the Article 26 representative rule beyond the specific provider categories currently listed in Article 26(1)(b), so that non-EU essential or important entities offering services in the Union would be required to designate an EU representative.
The proposal remains part of an ongoing legislative procedure.
OSTRAI monitors the development and will update its representation framework if the law changes.
WHY OSTRAI
OSTRAI combines Article 26 representation infrastructure with cybersecurity-regulatory judgement, controlled acceptance and direct access to the team handling the mandate.
Representation structured around the actual jurisdiction and territoriality framework.
The entity, services and jurisdictional basis are reviewed before representation begins.
A designated OSTRAI contact and monitored regulatory channel.
Substantive NIS2 governance, implementation and regulatory capability.
Clear routes for competent-authority and CSIRT communications.
Ability to identify intersections with DORA, CER, GDPR, CRA, cybersecurity certification and other European frameworks.
QUESTIONS & ANSWERS
Under current Article 26(3), an entity of a type listed in Article 26(1)(b) that is not established in the Union but offers services within the Union must designate a representative in a Member State where those services are offered. The entity, service classification and applicable NIS2 scope must be assessed.
No. Under the current Article 26 framework, the rule applies to the specified Article 26(1)(b) provider categories. It is not a general representative requirement for every essential or important entity.
The Article 26(1)(b) categories are DNS service providers, TLD name registries and entities providing domain name registration services; cloud computing, data centre and content delivery network providers; managed service and managed security service providers; and providers of online marketplaces, online search engines and social networking services platforms.
Cloud computing service providers are a listed Article 26(1)(b) category. Where the entity falls within the relevant NIS2 framework, is not established in the Union and offers services within the Union, Article 26(3) requires an EU representative. The actual service, entity and establishment position must be considered.
The representative must be established in one of the Member States where the relevant services are offered. The representative does not need to be established in the entity's only or principal EU market.
No. Cyprus only needs to be one of the Member States in which the relevant service is offered. It does not need to be the entity's sole or principal EU market. The relevant service and jurisdictional conditions are reviewed during onboarding before OSTRAI accepts a mandate.
Under Article 6(34), the representative is explicitly designated to act on behalf of the covered entity and may be addressed by the competent authority or CSIRT in place of the entity itself regarding its obligations under NIS2. OSTRAI provides the agreed regulatory interface, communications, escalation and mandate coordination.
No. The entity retains its underlying cybersecurity governance, risk-management and compliance responsibilities. Article 26(4) preserves legal actions that could be initiated against the entity itself.
Under current Article 26(3), in the absence of a designated EU representative, any Member State in which the entity provides services may take legal action against it for infringement of the Directive.
A Commission proposal published in January 2026 would broaden the representative rule to non-EU essential or important entities offering services in the Union. The legislative procedure remains ongoing. This is proposed scope, not the current enacted rule; the existing Article 26 framework remains the basis of the service until changes are adopted and applicable.
Still unsure whether Article 26 applies?
Discuss your position with OSTRAINIS2 REPRESENTATIVE
OSTRAI supports eligible organisations without an establishment in the Union from Article 26 scope and jurisdiction assessment through onboarding, regulatory interface and continuing NIS2 representation in the European Union.