NIS2 Registration: Getting Your Entity Onto the National Register Before the Regulator Finds You

NIS2 registration is not an invitation you wait for. It is a self-assessment you are expected to have already done, and the entities that get caught out are the ones that assumed silence from the authority meant they were out of scope.

Most of the NIS2 commentary treats registration as an administrative afterthought — the box you tick once the security controls are built. That has the sequence backwards. Registration is the moment the supervisory relationship begins: it puts your name, your sector classification and your contact details on a list a competent authority maintains, and from that point the obligations attach whether or not your control programme is ready. The Directive (EU) 2022/2555 does not wait for you to feel prepared. This is a reading of how to work out whether you are in scope, where and how to file, and what the filing actually commits you to.

The duty is self-identification, not notification

The single most common misreading is that a national authority will write to you if you are in scope. It will not, as a rule. NIS2 places the onus on the entity to assess its own status and come forward. Article 3(3) required member states to establish a list of essential and important entities by 17 April 2025, and Article 3(4) requires the entities themselves to submit the information that populates that list — name, address and up-to-date contact details including email addresses, IP ranges and telephone numbers, the relevant sector and subsector, and the list of member states in which they provide in-scope services.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

The practical consequence is that “we never heard from the regulator” is not a defence. If your authority identifies you before you identify yourself — through a sector mapping exercise, an incident at a peer, or a supply-chain enquiry from one of your customers — you begin the relationship as the entity that failed a basic obligation. That is a poor place to start a supervisory conversation.

Scope is a two-part test: sector, then size

Work out scope in the correct order. First, does your activity fall within one of the sectors in Annex I (sectors of high criticality — energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space) or Annex II (other critical sectors — postal and courier, waste management, chemicals, food, manufacturing of certain products, digital providers, research)? If no sector applies, you are generally out.

Second, apply the size-cap rule. The default entry point is the medium-sized enterprise threshold: at least 50 staff, or annual turnover and balance-sheet total above €10 million. Below that you are usually excluded — unless a specific carve-out pulls you in regardless of size, which applies to entities such as DNS service providers, TLD registries, trust service providers and public electronic communications providers. Above it, the sector then decides the tier. Large enterprises in Annex I sectors — 250 or more staff, or turnover above €50 million and a balance sheet above €43 million — are generally essential; medium-sized entities, and most of Annex II, are generally important. The distinction changes the supervisory regime, not whether you register. We have set out the sector-and-size mechanics in more detail in our note on the technology implications for essential and important entities.

One trap worth naming: the thresholds are not read on the standalone legal entity alone. Partner and linked enterprises within a group are consolidated, so a small subsidiary of a large parent can be dragged over the line on group headcount and turnover it does not itself generate.

There are two registers, and they are not the same thing

Do not conflate the general registration under Article 3 with the specialised registry under Article 27. Most in-scope entities register with their national competent authority under the Article 3 mechanism. A narrower set of digital service providers — DNS providers, TLD registries, domain-name registration services, cloud computing and data-centre providers, content delivery networks, managed service providers, managed security service providers, and providers of online marketplaces, search engines and social networking platforms — additionally submit a defined set of information that is forwarded to ENISA for a Union-level registry, with a submission expectation of 17 January 2025.

These providers register in the single member state where they have their main establishment — broadly, where decisions on cybersecurity risk-management measures are predominantly taken — which fixes their primary supervisor. Most other entities do not get that single-forum simplification, which is where cross-border filing gets awkward.

Register where you operate, and mind the uneven transposition

If you provide in-scope services in several member states and you are not one of the Article 27 main-establishment providers, you are potentially registrable in each of them, under each transposing law, on each authority’s portal, with each authority’s field definitions. This matters in 2026 because transposition has proceeded unevenly. The deadline was 17 October 2024; by mid-2026 most member states had adopted transposing legislation, but several — including France, Ireland, Luxembourg, the Netherlands and Spain — were still completing the legislative process, and the Commission had opened infringement proceedings against the majority of states for missing the deadline. The obligation to register bites when the national law commences, not on a single Union-wide date, so your filing calendar is a patchwork keyed to each jurisdiction. Building one control set that satisfies these divergent regimes is a problem in itself, which we have written about in NIS2 is transposed unevenly.

What the filing discloses, and what it commits you to

Registration is not neutral paperwork. It discloses your sector self-classification — which is, in effect, a statement of the tier you accept — your establishment footprint, and technical contact points including IP ranges. It also starts three concrete commitments. You must keep the details current: changes to the Article 3 submission are notified without delay and within two weeks, and changes to the Article 27 submission within three months. You accept the incident-notification clock, running to the same authority you have just handed your contact details to. And you place yourself inside the supervisory regime for your tier — ex-ante supervision for essential entities, ex-post for important — with the management-body accountability and the risk-management measures that follow. Those attaching obligations are the substance of the exercise, and we have set them out in the obligations the highest tier actually carries.

The instinct to delay registration until the controls are perfect is understandable and wrong. The register is a list of who is accountable, not a certificate that you are compliant. Get onto it deliberately, with a scope assessment you can defend and a sector classification you have chosen rather than one an authority chooses for you — because the alternative is being named on it by someone whose first impression of you is that you did not know you belonged there.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming