Skip to main content
Back to overview

NIS2 Article 26: Which Regulator Actually Supervises Your Client?

By NIS2Certify
nis2article-26jurisdictionmspcompliance
NIS2 Article 26: Which Regulator Actually Supervises Your Client?

A managed service provider in Rotterdam runs security operations for a client with its legal headquarters in Frankfurt, three production sites in Poland, and a sales office in Milan.

Four countries. Four national NIS2 laws. Four supervisory authorities.

Which one gets to audit them?

Most consultants guess wrong. They assume NIS2 works like the GDPR one-stop-shop, or they assume every country of operation adds another regulator. Neither is right. NIS2 Article 26 sets the rule, and it splits entities into two groups that behave very differently.

For most sectors, jurisdiction follows establishment — in every country you operate

Article 26(1)(a) is short: entities fall under the jurisdiction of the Member State in which they are established.

Note the plural implication. A manufacturer with legal entities in Germany, Poland and Italy is established three times. If each of those entities crosses the size threshold in an Annex I or Annex II sector, each one is separately in scope, separately registered, and separately supervised by that country''s authority.

That is the default, and it catches most clients: energy, transport, banking, health, drinking water, wastewater, manufacturing, food, waste management, postal services, chemicals, digital providers, research.

Concrete example. A food producer runs a 60-person plant in Poland and a 40-person plant in Belgium. The Polish entity is in scope under the Polish act and must register there. The Belgian entity does not meet the size threshold on its own. Same group, different obligations, different regulators, two separate compliance programmes.

Consultants who build one central NIS2 programme for a group and stop there are leaving each local entity exposed. Group policy is useful. It is not a substitute for local registration and local supervision.

Digital and managed service providers get one regulator — and only one

Article 26(1)(b) carves out a specific list and gives those entities a single point of supervision, wherever in the EU they operate:

  • DNS service providers
  • TLD name registries
  • entities providing domain name registration services
  • cloud computing service providers
  • data centre service providers
  • content delivery network providers
  • managed service providers
  • managed security service providers
  • providers of online marketplaces, online search engines and social networking services platforms

These entities fall under the jurisdiction of the Member State in which they have their main establishment. One regulator. One registration. One national act, even if they serve clients in all 27 Member States.

If you run an MSP or MSSP, this is you — and it applies to your own compliance posture, not just your clients''. See our guide to NIS2 for MSPs and MSSPs for the double-obligation problem.

"Main establishment" is not your registered office

This is where most self-assessments break. Article 26(2) defines main establishment through a cascade, and legal headquarters appears nowhere in it.

  1. The Member State where decisions related to cybersecurity risk-management measures are predominantly taken.
  2. If that Member State cannot be determined, or those decisions are not taken in the Union — the Member State where cybersecurity operations are carried out.
  3. If that still cannot be determined — the Member State where the entity has the establishment with the highest number of employees in the Union.

Read step one again. It is about where the decisions are made. Not where the company is incorporated, not where the CEO sits, not where the invoices are issued.

An MSP incorporated in Luxembourg for tax reasons, with its CISO, its security steering committee and its risk register in Antwerp, has its main establishment in Belgium. Belgian law applies. The CCB supervises. The Luxembourg registration is irrelevant to Article 26.

Document which cascade step you landed on and why. When a regulator asks, "our lawyers said Luxembourg" is not an answer. Board minutes showing where risk-management decisions are approved is.

Non-EU providers must appoint a representative — and that choice sets the jurisdiction

Article 26(3) covers providers on the 26(1)(b) list that are not established in the Union but offer services inside it. They must designate a representative established in one of the Member States where they offer those services. The entity is then deemed to fall under the jurisdiction of the Member State where that representative is established.

Two consequences that consultants routinely miss.

Designating a representative does not shield the entity. Legal action can still be brought against the provider itself, even where a representative has been designated.

Failing to designate one does not create immunity. It creates an unrepresented provider selling into a market where authorities can act against it anyway.

Practical takeaway: if you resell or integrate a US, UK or Swiss cloud platform into a client''s essential service, ask for their EU representative and the Member State where that representative sits. If they cannot name one, you have a finding to write into the client''s supply chain assessment. That is exactly the kind of gap covered in NIS2 supply chain security.

One regulator does not mean one rulebook

Article 26 decides who supervises you. It does not harmonise what they supervise against.

NIS2 is a directive, not a regulation. Every Member State transposed it into its own act, with its own registration portal, its own deadlines, its own interpretation of the size thresholds and, in several cases, its own control framework — Belgium''s CyFun, Italy''s ACN categorisation, Germany''s BSIG.

And transposition is still incomplete. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify complete transposition measures, with financial sanctions requested in each case. We covered what that means for suppliers in France and Spain referred to the CJEU.

For a provider on the 26(1)(b) list, main establishment is therefore a real strategic variable. Where your security decisions are taken determines which portal you register in, which CSIRT you notify, which supervisory culture you deal with, and which framework your evidence has to map to. That is not something to discover during an audit. Check where each country stands in our NIS2 implementation timeline.

NIS2 Implementation Status by Country (2025–2026)

Fully in force

Belgium
Croatia
Hungary
Lithuania
Latvia
Italy
6 countries

Adopted — late 2025

Germany
Czech Republic
Finland
3 countries

In progress — expected 2026

Netherlands
France
Spain
Poland
Austria
Sweden
Ireland
7 countries

Article 27 means you cannot quietly pick a favourable jurisdiction

Article 27 requires Member States to collect identifying information from every entity on the 26(1)(b) list, through their single points of contact, and forward it to ENISA. ENISA maintains a Union-wide registry and gives competent authorities access on request.

The information submitted includes the entity''s name, the relevant sector and subsector from the Annexes, its address and contact details, the Member States where it provides services, and its IP ranges.

Those last two items matter more than they look. You declare the countries you serve, ENISA holds the registry, and any national authority can request access.

So a provider that registers in the Member State with the lightest supervisory reputation while its actual security decisions are taken elsewhere is not hiding. It is filing a declaration that gives regulators the raw material to notice the mismatch. Registration itself is already the most-missed obligation in NIS2 — see the registration obligation.

Getting jurisdiction wrong compounds into three separate failures

It rarely stays a paperwork problem.

Registration. Register in the wrong Member State and you are unregistered in the right one. In most national acts that is a standalone breach, entirely independent of how good your actual security posture is.

Incident reporting. The 24-hour early warning goes to the CSIRT of the Member State with jurisdiction. Send it to the wrong one and the clock keeps running while you find out. A late report is a separate violation from the incident itself. The deadlines are set out in NIS2 incident reporting.

Supply chain. Your clients are obliged to assess their suppliers under Article 21(2)(d). A supplier who cannot state its own supervisory authority is a supplier whose compliance status cannot be verified — and that goes straight into the client''s supplier documentation as an open risk.

NIS2 Penalty Escalation — Beyond the Fine

!

Trigger event

Non-Compliance Detected or Incident Occurs

A supervisory authority identifies a compliance gap or an organisation fails to meet NIS2 requirements

Authorities can impose
Non-Monetary Penalties
1

Compliance orders with binding deadlines

2

Mandatory security audits at your expense

3

Public disclosure of violations

4

Binding instructions on specific security measures

Escalates to
Operational & Personal Consequences
1

Suspension of certifications or operating licences

2

Temporary ban on management functions for individuals

3

Public naming of responsible natural persons

Trigger
Non-monetary
Operational / personal

What to document for every multi-country client

Four artefacts. None of them takes long. All of them get asked for.

  1. An entity map. Every legal entity, its country, headcount, turnover, and the Annex I or Annex II sector it sits in. This tells you which entities are separately in scope under Article 26(1)(a).
  2. A main-establishment memo for any entity on the 26(1)(b) list. State which cascade step applied, the evidence behind it, and the date. One page is enough.
  3. The registration record. Portal, submission date, reference number, competent authority, and the national CSIRT contact route for incident reports.
  4. Representative details for every non-EU provider in the client''s critical supply chain, including the Member State of that representative.

Review the main-establishment memo whenever the security function moves. Relocating a SOC, outsourcing security operations to a different country, or hiring a CISO in a new location can shift jurisdiction under the cascade. No regulator will send you a notice about it.

Most organisations discover their jurisdiction assumption was wrong at the point they are already being asked to prove something else. Our free NIS2 quick scan walks through scope, jurisdiction and the Article 21 measures in about ten minutes and gives you a gap analysis you can take straight to the client.

Article 26 is two paragraphs of legal text. Getting it wrong invalidates everything you build on top of it.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.

    NIS2 Article 26: Which Regulator Actually Supervises Your Client? — NIS2Certify