Skip to content

Guide

Does NIS2 Apply to Non-EU Companies?

Reviewed 2026-08-21

Short answer

NIS2 does not automatically apply to every non-EU SaaS or technology company selling into Europe. Direct statutory scope depends on the company's own service/entity category, size and other Article 2 conditions, checked against the applicable national implementation. Separately, and independently of that direct-scope question, a non-EU vendor may receive NIS2-driven security and evidence requests from an EU customer that is itself regulated. That request alone does not make the vendor directly subject to NIS2.

See the full 9-step checklist below.

Who this is relevant to

Technology companies serving sectors that may be covered by NIS2, digital-service providers whose own scope needs checking, and suppliers receiving cybersecurity or supply-chain requests from an EU customer.

The assessment starts with the entity and activity facts, not with the assumption that a customer relationship or a country of headquarters decides the outcome.

  • Cloud computing, data-centre, content-delivery-network, managed-service and managed-security providers
  • DNS service providers and TLD name registries
  • Suppliers supporting essential or important entities in another sector
  • Teams preparing governance, incident and supply-chain evidence for an EU customer

How NIS2 can reach a non-EU technology company

NIS2 is implemented through Member State law and its direct application depends on the relevant entity, sector, service, size and other conditions. Those conditions must be checked against the applicable implementation context rather than assumed from a short label such as SaaS or supplier.

A separate customer-driven route is common in technology procurement. An EU customer within NIS2 scope may ask suppliers for security governance, risk-management, incident-handling, continuity or supply-chain evidence because of its own obligations.

The customer's request can create real commercial work without turning the supplier into a directly regulated entity. Keep the direct legal-scope analysis separate from the customer's procurement and contractual requirements.

Direct application vs customer flow-down

Direct NIS2 scope is an entity-level question under applicable national implementation conditions. Customer-driven requirements are the controls, documents and contractual provisions an EU customer may require to manage its own cyber and supply-chain risk.

A supplier may need to prepare strong evidence even when its own direct NIS2 status is unresolved or different from the customer's status. That is why the two tracks should be recorded independently.

  • Direct: the entity is within applicable NIS2 scope under the relevant implementation conditions
  • Customer-driven: an EU customer passes security, incident or supply-chain requirements through the relationship
  • Possible: sector, service, size or national-law facts still need verification

If NIS2 is customer-driven rather than directly applicable, what should you prepare?

The exact request varies by customer and service, and no single EU buyer typically asks for every item below. The following are practical evidence categories, not a promise that every item is a direct statutory obligation for every supplier.

Preparing this evidence is a readiness question, not a compliance score: holding a document does not by itself make a company NIS2-compliant, and a gap here is not proof that a legal obligation has been breached.

  • Security governance, ownership and policy review records
  • Risk-management method and material-risk treatment records
  • Incident detection, response, escalation and notification procedures
  • Business continuity, crisis management and recovery evidence
  • Supply-chain and subcontractor inventory with change controls
  • Security testing, remediation tracking and technical safeguards
  • A clear answer to customer questions about service scope and dependencies

Common misconceptions

“Selling to an NIS2-regulated customer makes us directly subject to NIS2.”
The customer relationship may create security and supply-chain requirements, but direct NIS2 scope depends on the supplier entity, service, sector, size and applicable national implementation conditions.
“NIS2 is applied uniformly across every Member State.”
NIS2 is a directive. National implementation and the facts of the relevant entity matter, so a general EU-level description is not a substitute for the applicable national context.
“A security questionnaire proves that NIS2 applies directly to us.”
A questionnaire usually shows what the customer needs to manage its own risk. It is evidence of a commercial or supply-chain request, not by itself a legal classification of the supplier.
“No NIS2 match means the law cannot apply.”
An assessment result reflects the supplied facts and model scope. A zero result is not a legal non-applicability determination, especially where national implementation or missing facts remain relevant.
“We are outside Europe, so NIS2 cannot affect us.”
Location alone does not settle the question either way. A non-EU company can fall within NIS2's own service/entity categories in its own right, and separately, EU customers can pass down security and evidence requirements regardless of where the supplier is based.
“If NIS2 does not directly apply to us, we can ignore the customer's questionnaire.”
Direct legal scope and commercial reality are different questions. Even where NIS2 does not directly regulate the supplier, the customer's own contractual, procurement or supply-chain requirements may still need to be met to keep or win the deal.

Practical checklist

  1. 01Identify your entity type, sector, service and size against the applicable national implementation context
  2. 02List EU customers that may be essential or important entities and record what they have actually requested
  3. 03Separate direct-scope questions from customer-driven supply-chain requirements
  4. 04Assign owners for security governance, incident handling and customer evidence
  5. 05Map critical suppliers, subcontractors and service dependencies
  6. 06Test continuity, incident escalation and recovery processes and retain the evidence
  7. 07Keep a current security questionnaire pack without presenting it as a legal certificate
  8. 08Where your company is established, and whether an EU representative or registration obligation could apply to your specific service category if you are in scope
  9. 09Mark unresolved national-law, sector and scope facts for verification

What RegRoute can and cannot determine

RegRoute can organize the company, service, customer and evidence facts that distinguish direct NIS2 questions from customer-driven requirements and possible exposure. It can also keep uncertainty visible when a national implementation or scope fact is not settled.

It does not replace the applicable Member State law, certify NIS2 compliance, or determine that a company is outside scope merely because no requirement matched the supplied answers.

Own NIS2 scope vs. customer-driven NIS2 requirement

The same word, "NIS2", describes two different things depending on which question you are actually answering.

QuestionOwn NIS2 scopeCustomer-driven NIS2 requirement
What creates the obligation?The Directive itself, once the applicable Article 2 scope conditions are metA contract or procurement requirement set by a regulated EU customer
Who is regulated?The company itself, as an essential or important entityThe EU customer: the vendor is not thereby regulated
Can an EU customer trigger it by asking?No: a request does not by itself create direct scopeYes: this is exactly how this route arises
Do company size/service facts matter?Yes: size thresholds and service/entity category are central, subject to category-specific exceptionsOnly to how much evidence the customer expects, not to the vendor's own legal status
Typical evidence pressureThe full NIS2 risk-management, governance and incident-reporting obligations, if in scopeA security questionnaire, contract clauses, or supply-chain evidence request
What RegRoute classification may reflect it?Direct (or Possible, where a scope fact is still unresolved)Customer-driven

Service categories that most often confuse SaaS and cloud companies

These are the categories most likely to make a technology company wonder whether NIS2 reaches it directly. Fitting a general description is a fact worth checking, not a conclusion. The applicable Article 2 conditions still decide the answer.

CategoryWhat it generally meansWhy a SaaS/cloud company might think it fitsWhat fact still needs establishing
Cloud computing serviceOn-demand, scalable, remotely accessible computing resourcesMost SaaS products are delivered from cloud infrastructureWhether the company itself provides the cloud computing service, rather than merely running its own software on someone else's cloud
Data centre serviceProviding the physical/logical facility used to host IT systems"We host data" sounds close to "we run a data centre"Whether the company operates a data-centre service for others, versus simply using hosting infrastructure to run its own product
Content delivery network (CDN)Distributing content/traffic across a geographically dispersed network to improve deliveryMany SaaS products use or resemble edge/caching infrastructureWhether the company itself operates the CDN service, rather than being a customer of one
Managed service / managed security serviceOngoing operation, administration or security monitoring of a customer's IT on the customer's behalfMany B2B SaaS and IT-services companies describe themselves loosely as "managed"Whether the offering meets the specific managed-service or managed-security-service definition, versus a self-service software product
DNS service provider / TLD name registry / domain-name registration serviceOperating domain name resolution, top-level-domain registries, or domain registrationRarely confused in practice, but sits in the same Annex I digital-infrastructure group as the categories aboveWhether the company actually provides one of these specific services, as opposed to merely owning a domain name

If you are not established in the EU: representative and registration mechanics

Scope comes first. Articles 26 and 27's representative and registration mechanics apply on top of NIS2 scope, never instead of it. A company only needs to consider them once it has already established that it is in scope as an essential or important entity under Article 2.

For a specific, named subset of digital categories, including DNS service providers, TLD name registries, domain-name registration services, cloud computing service providers, data-centre service providers, content-delivery-network providers, managed service providers, managed security service providers, online marketplaces, online search engines and social networking platforms, NIS2 fixes jurisdiction by main establishment (the Member State where cybersecurity risk-management decisions are predominantly taken) rather than by registered office. A company in one of these categories that is in scope and has no main establishment in the Union must designate a representative in a Member State where it offers its services; that representative's Member State becomes the competent authority for supervision (Article 26). The same categories are recorded, together with the non-EU company's designated representative and contact details, in ENISA's central registry of entities (Article 27).

None of this changes whether a company is in scope in the first place. A DNS provider, cloud provider or managed-service provider established outside the EU does not become subject to NIS2 merely because it appears on this list of categories. The Article 2 conditions still have to be met. Equally, a non-EU company outside these specific listed categories is not automatically outside NIS2's reach: this list only identifies which categories carry a special representative/registration mechanic, not the full set of entities NIS2 can otherwise cover.

Official EU sources

Every conclusion on this page traces back to the primary legal text. We link only to official EU sources.

RegulationsMethodologySee what the EU Readiness Pack includes

Mini-check: what NIS2 questions should you review?

Two screening questions about your service and customer context. Answers carry into the full assessment.

Has an EU customer explicitly referred to NIS2 in a security or procurement request?
Which service description is closest to what you provide?

This is a screening fact, not a conclusion that NIS2 applies.

Start the full assessment instead

General information, not legal advice. Applicability can depend on facts and national implementation. Verify material legal conclusions with qualified counsel.