NIS2 Entity Registration
NIS2 puts two different filings behind one word. Member States build the list and require entities to submit identifying information for it, on a two-week update clock, while a narrower set of digital entity types files a longer record with its national authority, corrects it on a three-month clock and has it forwarded to ENISA without its IP ranges. This guide separates the two, marks who is bound by each, and shows what national portals add on top.
- The Directive binds Member States to build a list, not entities to register Article 3(3) puts the list duty on the Member State and Article 3(4) tells it to require entities to submit at least four items, so the filing duty that reaches an entity is created in national law and the words at least leave a Member State free to ask for more.
- The size figures belong to a Recommendation, not to NIS2 Article 2(1) reaches entities that qualify as medium-sized or exceed those ceilings under Recommendation 2003/361/EC, whose Annex supplies the headcount below 250 and the EUR 50 million and EUR 43 million figures, while NIS2 states no number of its own and switches off the public-ownership disqualifier.
- The Article 27 registry is not a public register and never receives your IP ranges ENISA builds it from what national single points of contact forward, the forwarding rule excludes point (f), access is granted to competent authorities on request with confidentiality protected, and no ENISA registry page, portal or dataset exists to look anything up in.
- Jurisdiction decides where you file, and eleven entity types get a different test The default is the Member State of establishment, but the Article 26(1)(b) list files where its main establishment sits, resolved by a three-step cascade starting at where cybersecurity risk-management decisions are predominantly taken, and a non-EU entity in that list files through a designated representative.
- The headline NIS2 fines are tied to Article 21 or 23, not to a late filing Article 34(4) and 34(5) attach the EUR 10 000 000 and EUR 7 000 000 ceilings to infringements of the risk-management and incident-reporting articles, nothing in Articles 32 to 34 prices a registration failure, and what actually reaches a filing is the supervisory and enforcement toolkit plus whatever national law adds.
NIS2 entity registration is two filings wearing one word. Every essential or important entity, and every entity providing domain name registration services, is required by its Member State to hand the national authority a short set of identifying details, so that authority can build the list the Directive tells it to keep. A narrower set of digital entities makes a second, longer submission to its national authority, most of which is forwarded on to ENISA and never becomes public. The two carry different fields, different clocks and different populations, and a team that treats them as one event files the second one late. What follows is the filing side; the control side sits in our NIS2 compliance software requirements guide.
In short: The Directive does not order entities to register. It orders Member States to build a list and to require entities to submit information for it, which is why the mechanics differ by country and no Union filing form exists. Settle scope first: the size test lives in Article 2 and borrows its figures from a Commission Recommendation. Then submit what Article 3(4) names and keep it current within two weeks of any change. Entity types named in Article 27 file a longer record with their national authority and correct it on a three-month clock under Article 27(3), and the single point of contact forwards that record to ENISA without the IP ranges.
Two registration duties, not one
Read Article 3 in the order it is written and the addressee changes inside three sentences. The list duty lands on the Member State: "Member States shall establish a list of essential and important entities as well as entities providing domain name registration services. Member States shall review and, where appropriate, update that list on a regular basis and at least every two years thereafter." (Article 3(3)). Nothing in that sentence reaches an entity, and nothing in it names a portal or a form.
The entity duty arrives one paragraph later, and at one remove: "Member States shall require the entities referred to in that paragraph to submit at least the following information to the competent authorities" (Article 3(4)). Member States require, entities submit. No Union filing form exists because the Directive never asked for one, and the words "at least" set a content floor rather than a ceiling, so a Member State may ask for more than the four items named next.
The second duty sits in Article 27, covers a much narrower population and runs its own clock. Both, plus the domain-name database duty beside them, fit in one table.
| Duty | Legal basis | Who is bound | What is submitted | Update clock |
|---|---|---|---|---|
| Establish and maintain the national list | Article 3(3) | Member State | Nothing; the Member State compiles it | Reviewed and updated at least every two years |
| Require entities to submit identifying information | Article 3(4), first subparagraph | Member State requires, entity submits | Name; address and contact details including email, IP ranges and telephone; sector and subsector where applicable; Member States served where applicable | Without delay and in any event within two weeks |
| Offer a self-registration mechanism | Article 3(4), fourth subparagraph | Member State, optional | Not specified; design left to national law | None stated |
| Submit the registry information | Article 27(2) | Member State requires, entity submits | Name; sector, subsector and entity type where applicable; address of the main establishment and other EU establishments, or of the Article 26(3) representative; contact details; Member States served; IP ranges | Without delay and in any event within three months |
| Forward the registry information to ENISA | Article 27(4) | The single point of contact | Everything filed under Article 27(2) and 27(3) except IP ranges | Without undue delay |
| Create and maintain the registry | Article 27(1) | ENISA | Built from what single points of contact forward; opened to competent authorities on request | None stated |
| Keep domain name registration data | Article 28(1) and 28(2) | Member State requires, TLD name registries and entities providing domain name registration services keep it | Domain name; date of registration; registrant name, email and telephone; contact details of the administering point of contact where different | Access requests answered within 72 hours |
Two rows are the ones teams get wrong. One clock is measured in weeks and the other in months, and they attach to different submissions, so one office move can be late under one and early under the other. Onward paths differ too: Article 3 information stays with the competent authority, Article 27 information is forwarded to a Union agency minus one field.
The size test that comes before any filing
Scope is settled before anything is filed, and NIS2 settles it by pointing elsewhere. Article 2(1) says the Directive "applies to public or private entities of a type referred to in Annex I or II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises" (Article 2(1)) provided for in paragraph 1 of that Article, and which provide their services or carry out their activities within the Union.
The numbers live in the Recommendation rather than the Directive. Its Annex defines the category as "enterprises which employ fewer than 250 persons and which have an annual turnover not exceeding EUR 50 million, and/or an annual balance sheet total not exceeding EUR 43 million" (Recommendation 2003/361/EC, Annex Article 2(1)). Those are the ceilings of the whole SME category rather than a definition of medium size. Medium is the top band of that category, and the Annex sets the band below it in the next paragraph: "Within the SME category, a small enterprise is defined as an enterprise which employs fewer than 50 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 10 million." (Recommendation 2003/361/EC, Annex Article 2(2)). So an Annex I or II entity enters NIS2 scope once it passes that lower line of 50 persons and EUR 10 million, stays in scope through the medium band and remains in scope above the medium ceilings as well. NIS2 states no headcount and no euro figure of its own.
One paragraph of it is switched off on the way in: "Article 3(4) of the Annex to that Recommendation shall not apply for the purposes of this Directive." (Article 2(1), second sentence).
That paragraph says "an enterprise cannot be considered an SME if 25 % or more of the capital or voting rights are directly or indirectly controlled, jointly or individually, by one or more public bodies" (Recommendation 2003/361/EC, Annex Article 3(4)). Public ownership of a quarter or more of an enterprise therefore does not remove it from NIS2 scope the way it removes it from SME status generally, so a state-backed utility cannot use it as an exit.
For some entities size stops mattering. Article 2(2) applies the Directive regardless of size to several categories, and the one that decides a registration question is point (a)(iii): "top-level domain name registries and domain name system service providers;" (Article 2(2)). Both are in scope at any headcount, and both are also the first entries on the Article 27 list. Sole national providers of a service essential to critical societal or economic activities are size-independent too. The same paragraph reaches two further situations that have nothing to do with headcount: where disruption of the entity's service could have a significant impact on public safety, public security or public health, and where it could induce a significant systemic risk, in particular where that disruption would cross a border. A Member State may identify an entity under those limbs, and Article 3(2) then counts it among "entities identified by Member States as important entities pursuant to Article 2(2), points (b) to (e)" (Article 3(2)), which places it on the national list whatever its size.
What an entity submits under Article 3

Four items, two of them conditional. The name of the entity. Then "the address and up-to-date contact details, including email addresses, IP ranges and telephone numbers;" (Article 3(4), point (b)). Then the relevant sector and subsector referred to in Annex I or II, where applicable, and a list of the Member States where the entity provides services falling within the scope of the Directive, again where applicable. Those conditions are in the text and are not editorial hedging.
The IP ranges are the item that catches engineering teams. They sit inside a contact-details clause, so summaries drop them, and they are the field most likely to change without anybody thinking of it as a change to a filing. The clock over them is short: entities "shall notify any changes to the details submitted pursuant to the first subparagraph of this paragraph without delay, and, in any event, within two weeks of the date of the change." (Article 3(4), second subparagraph). Two weeks running from the date of the change rather than the date somebody notices, which makes the control a trigger on the systems owning the underlying facts rather than a diary entry.
What travels above the entity is narrower than most summaries suggest. Competent authorities notify the Commission and the Cooperation Group of the number of entities listed per sector and subsector, not of who they are, and names moved upward only on request inside a window that has since closed. Nothing in Article 3 builds a Union directory of named entities.
A self-service portal is optional at Union level: "Member States may establish national mechanisms for entities to register themselves." (Article 3(4), fourth subparagraph). May, not shall. Where a Member State built none, the information still has to reach the competent authority by whatever route national law provides. The Commission, assisted by ENISA, published guidelines on these obligations on 14 September 2023 (Commission guidelines, Article 3(4)).
The Article 27 registry and who can read it
Article 27 names its population precisely, because neighbouring instruments name overlapping but different sets. "ENISA shall create and maintain a registry of DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers" (Article 27(1)), then managed service providers, managed security service providers, providers of online marketplaces, of online search engines and of social networking services platforms. Eleven descriptors, and being one of them is what makes a Member State require the second filing of you.
One of the eleven is wider than it looks: "‘entity providing domain name registration services’ means a registrar or an agent acting on behalf of registrars, such as a privacy or proxy registration service provider or reseller;" (Article 6, point (22)). A reseller sits inside the Article 27 population on that definition, as does a privacy or proxy registration service.
The submission goes to the national competent authority rather than to ENISA: "Member States shall require entities referred to in paragraph 1 to submit the following information to the competent authorities by 17 January 2025" (Article 27(2)). That date is the statutory first-submission date written into the paragraph, and it is a rule about when the initial record was due rather than a Union-wide registration date for everybody: Article 27 binds only the eleven types it lists, and an entity outside them never owed this filing. Six items follow.
- Name of the entity
- Sector, subsector and type of entity referred to in Annex I or II, where applicable
- Address of the main establishment and of other legal establishments in the Union, or of the representative designated under Article 26(3)
- Contact details for the entity and where applicable its representative
- Member States where it provides services
- IP ranges of the entity
The clock is different here, and it is again a duty routed through the Member State. Member States must ensure the entities "notify the competent authority about any changes to the information they submitted under paragraph 2 without delay and in any event within three months of the date of the change." (Article 27(3)). Three months against two weeks under Article 3(4). One address change can be governed by both, on two deadlines, which argues for holding a single internal record of the regulated facts and deriving each filing from it.
What ENISA holds is not what the entity filed. "Upon receipt of the information referred to in paragraphs 2 and 3, except for that referred to in paragraph 2, point (f), the single point of contact of the Member State concerned shall, without undue delay, forward it to ENISA." (Article 27(4)). Point (f) is the IP ranges, so the most sensitive field stops at the national authority.
And the registry is not a public register. "Upon request, ENISA shall allow the competent authorities access to that registry, while ensuring that the confidentiality of information is protected where applicable." (Article 27(1), second sentence). No ENISA registry page, lookup portal or dataset sits behind it: a full read of ENISA's own sitemap at www.enisa.europa.eu/sitemap.xml on 8 September 2026 returned reports, guidance and news items and nothing resembling a registry. An entity cannot confirm its own record arrived and a buyer cannot use it for supplier diligence, so both are left with whatever the national authority chooses to confirm. Where a Member State built a self-registration mechanism, that is the route: "Where applicable, the information referred to in paragraphs 2 and 3 of this Article shall be submitted through the national mechanism referred to in Article 3(4), fourth subparagraph." (Article 27(5)).
Two comparisons stop registers being conflated. Commission Implementing Regulation (EU) 2024/2690 applies its technical requirements to a similar but not identical set, adding trust service providers and omitting entities providing domain name registration services (Article 1 of that Regulation). A register duty under a neighbouring financial regime is a third thing, covered in our DORA register of information piece.
Managed service providers and managed security service providers are on the Article 27 list in their own right, so an outsourcing arrangement can put a provider onto a register even where its customer owes no filing at all. That asymmetry is one our NIS2 compliance outsourcing piece works through.
Which Member State you file in
The default is establishment. Article 26(1) places entities in scope under the jurisdiction of the Member State in which they are established, with listed exceptions, and the main exception covers exactly the Article 27 population, "which shall be considered to fall under the jurisdiction of the Member State in which they have their main establishment in the Union under paragraph 2" (Article 26(1), point (b)).
For those entities main establishment is a cascade rather than a corporate address: "an entity as referred to in paragraph 1, point (b), shall be considered to have its main establishment in the Union in the Member State where the decisions related to the cybersecurity risk-management measures are predominantly taken." (Article 26(2)). Failing that, the Member State where cybersecurity operations are carried out, and failing that again the one with the largest establishment by headcount in the Union. None asks where the headquarters is registered or where the data sits.
An entity in that list with no EU establishment files through a representative: "If an entity as referred to in paragraph 1, point (b), is not established in the Union, but offers services within the Union, it shall designate a representative in the Union." (Article 26(3)). The representative is established in a Member State where the services are offered, and that fixes jurisdiction. Where none has been designated, any Member State in which the entity provides services may act against it.
Entities outside that list follow other rules. Providers of public electronic communications networks and services fall under the Member State where they provide those services, and public administration entities under the Member State that established them. Only the Article 26(1)(b) list gets one main-establishment answer.
Domain name data is a separate duty
Article 28 sits beside Article 27 and is not part of entity registration. "Member States shall require TLD name registries and entities providing domain name registration services to collect and maintain accurate and complete domain name registration data in a dedicated database" (Article 28(1)), for the purpose of contributing to the security, stability and resilience of the DNS and in accordance with Union data protection law where the data are personal data. The floor is the domain name, the date of registration, the registrant name with a contact email address and telephone number, and the contact details of the administering point of contact where those differ. Non-personal registration data is published without undue delay after a registration, specific data goes to legitimate access seekers on lawful and duly substantiated requests, and the registry or registrar is required "to reply without undue delay and in any event within 72 hours of receipt of any requests for access". This is a database about domain names rather than a register of entities, and maintaining it satisfies neither the Article 3(3) list nor the Article 27 registry.
What national portals actually ask for
Everything above is the Union floor. The form an entity fills in and the login it sits behind are national. The examples below were readable to an automated client, a sampling artifact.
In Germany, registration runs in two steps that have nothing to do with cybersecurity. An entity first obtains an ELSTER organization certificate through the Mein Unternehmenskonto service, then registers in the BSI portal with that certificate, under the national provision the BSI cites as section 33(6) of the BSIG. The BSI states on the same page that the statutory registration deadline has already passed and tells an affected entity that has not registered to do so immediately.
Germany also runs a separate scoping questionnaire, the NIS-2-Betroffenheitspruefung, whose own disclaimer is the most useful sentence any of these sites publishes. It describes itself as an automatic orientation aid built on self-declared information, says its result is not legally binding, and says it does not replace the entity's own self-identification. A scoping tool never moves the legal burden off the entity.
In the Netherlands the Cyberbeveiligingswet entered into force on 15 August 2026, and the NCSC states that organizations falling under it are legally obliged to register in the entiteitenregister, the national entity register. The regulator puts its own in-scope population at more than 8,000 organizations, which is an estimate of who owes a filing rather than a count of who has made one.
In France, ANSSI states that transposition is in progress and offers an online pre-registration service in the meantime, alongside a scope check. That is the fourth subparagraph of Article 3(4) in practice: an optional national mechanism, here running ahead of the transposing law rather than after it.
Ireland's National Cyber Security Centre publishes a NIS2 page describing a registration portal and an incident reporting portal as two separate services. On that design, identity would go one way and incidents another, on different systems. The incident side overlaps neighbouring regimes rather than duplicating them, which our CRA, NIS2 and DORA reporting overlap piece works through.
None of that is the Union rule. A national deadline, a register name, a certificate requirement and a pre-registration service are national implementations of the same two paragraphs, and they show how much room Article 3(4) leaves.
What the Directive says about not filing
The enforcement chapter prices cybersecurity measures and incident reporting rather than filings, though it names the Article 27 filing duty once in the supervisory powers, and that changes what a registration failure actually risks. Article 34(1) states the general rule, that Member States shall ensure that "administrative fines imposed on essential and important entities pursuant to this Article in respect of infringements of this Directive are effective, proportionate and dissuasive" (Article 34(1)), taking the circumstances of each case into account.
The numbers everybody quotes are narrower than that. Article 34(4) provides that "where they infringe Article 21 or 23, essential entities are subject, in accordance with paragraphs 2 and 3 of this Article, to administrative fines of a maximum of at least EUR 10 000 000" (Article 34(4)) or of at least 2 percent of the total worldwide annual turnover of the undertaking the entity belongs to in the preceding financial year, whichever is higher. For a subsidiary that is a group figure rather than its own. Article 34(5) sets EUR 7 000 000 or 1,4 percent on the same turnover basis for important entities. Both ceilings are tied to an infringement of Article 21 or Article 23, the risk-management and incident-reporting articles. Nothing in Articles 32 to 34 attaches a figure to a failure to submit registration information, so quoting the headline ceiling as the price of a late filing is wrong.
What does reach a filing is the supervisory apparatus around it. Competent authorities may subject essential entities to at least on-site inspections and off-site supervision, security audits, security scans and "requests for information necessary to assess the cybersecurity risk-management measures adopted by the entity concerned, including documented cybersecurity policies, as well as compliance with the obligation to submit information to the competent authorities pursuant to Article 27" (Article 32(2), point (e)). That closing clause is the one place in Articles 32 to 34 where the Article 27 filing duty is named. Enforcement powers run from warnings and binding instructions through orders to cease infringing conduct.
Important entities sit under a lighter regime that is explicitly reactive. Article 33(1) triggers "When provided with evidence, indication or information that an important entity allegedly does not comply with this Directive, in particular Articles 21 and 23 thereof" (Article 33(1)), and the measures that follow are ex post. Essential entities get proactive supervision including random checks; important entities get looked at once something surfaces.
The practical consequence is national and it is not theoretical. Germany's BSI tells unregistered affected entities that the deadline has passed and to act now, which is a regulator describing a live exposure rather than a sanction. National transposing laws may attach their own penalty to a missed filing, and the Directive's figures do not price it. The quieter cost is structural: an entity that has not filed is one the supervisor has no record of, so its first contact with the authority explains an absence instead of a control.
How Pharos Production helps
Registration is a data problem before it is a legal one. The fields the Directive names live in a company register, a contact directory and an IP address management system, none of which was built to raise a flag when a regulated fact changes, and two clocks of different lengths run over them. We build the plumbing that makes that survivable: one internal record of the regulated facts, change detection on the systems that own them, and an evidence trail a supervisor can follow. If you are working out which filings apply, our compliance and RegTech team can help.
Sources: Directive (EU) 2022/2555 (NIS2), Articles 2, 3, 6, 26, 27, 28, 32, 33 and 34, on EUR-Lex (CELEX 32022L2555); Commission Recommendation 2003/361/EC, Annex Articles 2(1) and 3(4) (CELEX 32003H0361); Commission Implementing Regulation (EU) 2024/2690, Article 1 (CELEX 32024R2690); the Commission guidelines on Article 3(4); national pages published by the BSI, the Dutch NCSC, ANSSI and Ireland's NCSC, read 8 September 2026. Engineering guidance, not legal advice.
FAQ
Quick answers to common questions about custom software development, pricing, process and technology.
Type to filter questions and answers. Use Topic to narrow the list.
Showing all 6
No matches
Try a different keyword, change the topic or clear filters
-
Not in those words, and the distinction changes who you deal with. The Directive requires Member States to establish a list and to require entities to submit information for it, and it separately permits Member States to set up mechanisms for entities to register themselves.
So the duty that reaches an entity is created by national transposing law rather than by the Directive directly, which is why the form, the portal, the login method and the deadline all vary by country while the minimum content does not.
-
They differ in who holds them, who is on them and how fast they have to be corrected. The Article 3 list is national, established by the Member State and built from information submitted to the competent authorities, and it covers every essential and important entity plus entities providing domain name registration services, with a two-week update clock.
The Article 27 registry is held by ENISA, covers eleven types of digital entity, is fed by national single points of contact rather than by entities, and the entities on it correct their submissions to the competent authority on a three-month clock. An entity can owe both.
-
No. ENISA opens the registry to competent authorities on request and protects the confidentiality of the information where applicable, and no public page, portal or dataset for it exists. A search of ENISA's own sitemap in September 2026 returned reports and guidance and nothing resembling a registry.
There is no Union-level lookup to fall back on, and whether a national authority will confirm a counterparty's status is a matter of national law rather than of the Directive.
-
It depends which filing the changed field belongs to. Changes to the Article 3(4) information are notified without delay and in any event within two weeks of the date of the change.
Changes to the Article 27(2) information go to the competent authority without delay and in any event within three months. Both clocks start at the date of the change rather than the date it is discovered, so the practical requirement is detection rather than paperwork, and an address change can be governed by both at once.
-
Most entities file where they are established. Eleven types of digital entity, including cloud, data center, CDN, DNS, TLD, managed service and managed security service providers and online platforms, instead file where their main establishment sits, which is defined as where decisions on cybersecurity risk-management measures are predominantly taken, then where cybersecurity operations are carried out, then where the largest establishment by headcount is.
Providers of electronic communications follow a different rule again.
-
Sometimes, because Article 2(2) applies the Directive at any size to several categories. Top-level domain name registries and DNS service providers are the ones that decide a registration question, and sole providers in a Member State of a service essential to critical societal or economic activities sit beside them.
The remaining size-independent limbs turn on the consequences of disruption rather than on the entity itself, and a Member State identification under any of them lands the entity on the national list whatever its headcount.
I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.
My focus is on complex products where mistakes are costly:
- Web3 and blockchain platforms
- FinTech and regulated products
- High-load startup systems
- MVP → scale transitions
We don’t do body-shopping.
We don’t sell generic outsourcing.Instead, we help founders:
- build the right team structure from day one
- keep technical ownership and transparency
- scale delivery without losing control
- avoid vendor lock-in and hidden risks
Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.