# NIS2 Jurisdiction and Territoriality — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/nis2-jurisdiction-territoriality
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because NIS2 has specific provisions on jurisdiction and territoriality that determine how the regulation applies across member states and to third-country entities, which is not adequately covered by existing topics.

## Overview

## Legal Framework

Article 3 of Directive (EU) 2022/2555 (NIS2) establishes the directive's territorial scope through two distinct limbs. Article 3(1) applies NIS2 to entities providing their services or conducting their activities within the Union, regardless of where they are established. This covers both public and private entities listed in Annexes I and II that operate within EU borders. Article 3(2) extends reach to entities not established in the Union but offering goods or services to persons in the Union, or whose activities involve monitoring incidents in the Union. Such entities must designate a representative established in a Member State where they offer services, serving as a point of contact for competent authorities. Article 32 requires Member States to ensure cross-border cooperation among CSIRTs and competent authorities, reinforcing the multi-jurisdictional enforcement architecture. The rationale is clear: digital infrastructure and network threats transcend borders, so the regulatory perimeter must match the threat landscape.

## Key Developments

Member State transposition has produced divergent interpretations of Article 3(2)'s "offering services to persons in the Union" threshold. Several national implementations—including Germany's NIS2UmsuCG and France's transposition discussions—signal that even indirect service provision to EU users triggers jurisdiction if the entity targets EU persons through localized interfaces, payment options in euros, or EU-based customer support. The representative requirement under Article 3(2)(b) mirrors the GDPR Article 27 model but operates within a security-incident reporting framework rather than a data-protection one. Enforcement remains nascent, but competent authorities are already coordinating through the EU Cyber Crises Liaison Organisation Network (EU-CyCLONe) to identify non-compliant third-country entities, particularly in cloud computing and managed service provider sectors where extraterritorial reach is most contested.

## Practical Guidance

- **Map establishment status precisely**: Determine whether your entity has a physical establishment in the EU under Article 3(1) or falls solely under Article 3(2). The distinction dictates which Member State's competent authority has primary jurisdiction and which substantive obligations apply directly.

- **Designate an EU representative if Article 3(2) applies**: The representative must be established in a Member State where you offer services, must be mandated to act on your behalf, and must be addressable by competent authorities and CSIRTs for incident reporting and compliance inquiries.

- **Assess service-offering indicators**: Evaluate whether your activities constitute "offering services to persons in the Union" by examining EU-directed marketing, EU language interfaces, euro pricing, and contractual willingness to serve EU customers. These factors determine jurisdictional exposure.

- **Prepare for multi-jurisdictional incident reporting**: Under Article 23, incidents with cross-border impact may require notification to multiple CSIRTs. Establish protocols identifying which authorities must be notified based on where affected services are delivered and where the entity or its representative is established.

- **Monitor national transposition variations**: Article 3 sets the floor, but Member States may impose additional territorial reach or stricter representative requirements. Track transposition in each Member State where you operate or offer services.

## Legislation (full text of key provisions)

### Recital 114 — single Member State jurisdiction for digital service providers

*Source: NIS2, nis2-rec-114-en, 2022-12-14 — https://overview.legal/posts/96756*

In order to take account of the cross-border nature of the services and operations of DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines and of social networking services platforms, only one Member State should have jurisdiction over those entities. Jurisdiction should be attributed to the Member State in which the entity concerned has its main establishment in the Union. The criterion of establishment for the purposes of this Directive implies the effective exercise of activity through stable arrangements. The legal form of such arrangements, whether through a branch or a subsidiary with a legal personality, is not the determining factor in that respect. Whether that criterion is fulfilled should not depend on whether the network and information systems are physically located in a given place; the presence and use of such systems do not, in themselves, constitute such main establishment and are therefore not decisive criteria for determining the main establishment. The main establishment should be considered to be in the Member State where the decisions related to the cybersecurity risk-management measures are predominantly taken in the Union. This will typically correspond to the place of the entities’ central administration in the Union. If such a Member State cannot be determined or if such decisions are not taken in the Union, the main establishment should be considered to be in the Member State where cybersecurity operations are carried out. If such a Member State cannot be determined, the main establishment should be considered to be in the Member State where the entity has the establishment with the highest number of employees in the Union. Where the services are carried out by a group of undertakings, the main establishment of the controlling undertaking should be considered to be the main establishment of the group of undertakings.

### Recital 113 — member state jurisdiction over entities

*Source: NIS2, nis2-rec-113-en, 2022-12-14 — https://overview.legal/posts/96754*

Entities falling within the scope of this Directive should be considered to fall under the jurisdiction of the Member State in which they are established. However, providers of public electronic communications networks or providers of publicly available electronic communications services should be considered to fall under the jurisdiction of the Member State in which they provide their services. DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines and of social networking services platforms should be considered to fall under the jurisdiction of the Member State in which they have their main establishment in the Union. Public administration entities should fall under the jurisdiction of the Member State which established them. If the entity provides services or is established in more than one Member State, it should fall under the separate and concurrent jurisdiction of each of those Member States. The competent authorities of those Member States should cooperate, provide mutual assistance to each other and, where appropriate, carry out joint supervisory actions. Where Member States exercise jurisdiction, they should not impose enforcement measures or penalties more than once for the same conduct, in line with the principle of ne bis in idem.

## Guidance

### Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications

*Source: EDPB, edpb-guidelines-on-processing-personal-data-in-the-context-of-connected-vehicles-and-mobility-rel, 2020-01-01 — https://overview.legal/posts/38135*

The EDPB adopted Guidelines 1/2020 to provide guidance on the application of the GDPR to the processing of personal data in connected vehicles and mobility-related applications. The guidelines address key issues including data minimisation, data protection by design and by default, transparency obligations, data subjects' rights, security, third-party data sharing, and international transfers, with practical case studies covering services provided by third parties, eCall, accidentology, anti-theft measures, and rental car information. The document does not impose fines but offers recommendations to help controllers and processors in the automotive ecosystem comply with their GDPR obligations.

## Related topics

- **Cloud Computing** — https://overview.legal/topics/cloud-computing
  Use of cloud services and associated data protection requirements
- **Telecommunications** — https://overview.legal/topics/telecommunications
  Processing by telecom providers and eprivacy
- **Territorial scope (GDPR)** — https://overview.legal/topics/territorial-scope
  When the GDPR applies geographically: establishment in the Union, targeting (offering goods or services), and behavioural monitoring by non-EU controllers (Arti
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Data Subject Rights Exercise Modalities and Procedures** — https://overview.legal/topics/data-subject-rights-exercise-modalities
  This content specifically addresses the transparent communication and practical modalities for how data subjects can exercise their GDPR rights, which is not ad
- **Profiling** — https://overview.legal/topics/profiling
  Automated processing to evaluate personal aspects

---
Generated by overview.legal · https://overview.legal/topics/nis2-jurisdiction-territoriality · 2026-08-22
