NIS2 Jurisdiction and Territoriality
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because NIS2 has specific provisions on jurisdiction and territoriality that determine how the regulation applies across member states and to third-country entities, which is not adequately covered by existing topics.
Overview
1 sources · Jul 14, 2026Legal Framework
Article 3 of Directive (EU) 2022/2555 (NIS2) establishes the directive's territorial scope through two distinct limbs. Article 3(1) applies NIS2 to entities providing their services or conducting their activities within the Union, regardless of where they are established. This covers both public and private entities listed in Annexes I and II that operate within EU borders. Article 3(2) extends reach to entities not established in the Union but offering goods or services to persons in the Union, or whose activities involve monitoring incidents in the Union. Such entities must designate a representative established in a Member State where they offer services, serving as a point of contact for competent authorities. Article 32 requires Member States to ensure cross-border cooperation among CSIRTs and competent authorities, reinforcing the multi-jurisdictional enforcement architecture. The rationale is clear: digital infrastructure and network threats transcend borders, so the regulatory perimeter must match the threat landscape.
Key Developments
Member State transposition has produced divergent interpretations of Article 3(2)'s "offering services to persons in the Union" threshold. Several national implementations—including Germany's NIS2UmsuCG and France's transposition discussions—signal that even indirect service provision to EU users triggers jurisdiction if the entity targets EU persons through localized interfaces, payment options in euros, or EU-based customer support. The representative requirement under Article 3(2)(b) mirrors the GDPR Article 27 model but operates within a security-incident reporting framework rather than a data-protection one. Enforcement remains nascent, but competent authorities are already coordinating through the EU Cyber Crises Liaison Organisation Network (EU-CyCLONe) to identify non-compliant third-country entities, particularly in cloud computing and managed service provider sectors where extraterritorial reach is most contested.
Practical Guidance
Map establishment status precisely: Determine whether your entity has a physical establishment in the EU under Article 3(1) or falls solely under Article 3(2). The distinction dictates which Member State's competent authority has primary jurisdiction and which substantive obligations apply directly.
Designate an EU representative if Article 3(2) applies: The representative must be established in a Member State where you offer services, must be mandated to act on your behalf, and must be addressable by competent authorities and CSIRTs for incident reporting and compliance inquiries.
Assess service-offering indicators: Evaluate whether your activities constitute "offering services to persons in the Union" by examining EU-directed marketing, EU language interfaces, euro pricing, and contractual willingness to serve EU customers. These factors determine jurisdictional exposure.
Prepare for multi-jurisdictional incident reporting: Under Article 23, incidents with cross-border impact may require notification to multiple CSIRTs. Establish protocols identifying which authorities must be notified based on where affected services are delivered and where the entity or its representative is established.
Monitor national transposition variations: Article 3 sets the floor, but Member States may impose additional territorial reach or stricter representative requirements. Track transposition in each Member State where you operate or offer services.