Skip to main content
Back to overview

NIS2 Online Marketplaces: Is Your E-Commerce Client in Scope?

By NIS2Certify
nis2online-marketplacedigital-providersscopearticle-26msp
NIS2 Online Marketplaces: Is Your E-Commerce Client in Scope?

A 70-person company in Utrecht runs a platform where hobbyists sell vintage camera parts to each other. Buyers pay through the site, sellers ship directly, and your MSP hosts the stack. Ask the founder whether NIS2 applies and you will hear: "We are a small web shop. That is retail, not critical infrastructure."

Under the directive, that answer can be wrong. A platform that lets buyers conclude contracts with third-party sellers is an NIS2 online marketplace, and digital providers of that kind sit in Annex II with their own jurisdiction rule, their own registry duty and their own incident thresholds. Here is how to test it for a client, and what the test changes.

NIS2 online marketplaces: what the directive actually covers

Annex II of the directive lists "digital providers" as a sector. Three types matter here: providers of online marketplaces, providers of online search engines, and providers of social networking services platforms. They are treated as important entities, not essential ones, so supervision is mainly reactive. That does not make them optional. The Article 21 risk-management measures and Article 23 incident reporting apply in full.

The Commission added detail in Implementing Regulation (EU) 2024/2690, in force since 7 November 2024. Article 1 names marketplaces, search engines and social networks among the ten entity types it covers. It sets the technical and methodological requirements for the Article 21(2) measures and specifies when an incident counts as significant.

If you already read our guide on digital infrastructure and the 30-minute incident rule, note the difference. The strict time-based triggers there belong to DNS, cloud and similar providers. Marketplaces, search engines and social networks have user-based triggers instead.

The three definitions that decide scope

Scope turns on Article 6, not on how the client describes itself.

An online marketplace is defined by reference to Directive 2005/29/EC, Article 2(n). In plain terms: a service, run by or for a trader, that allows consumers to conclude distance contracts with other traders or consumers. A shop that sells only its own stock does not meet that test. A platform where third parties list and sell does.

An online search engine is defined by reference to Regulation (EU) 2019/1150, Article 2(5). A site search box does not qualify. A service that searches across websites does.

A social networking services platform is defined in Article 6 itself: a platform that enables end-users to connect, share, discover and communicate with each other across multiple devices, in particular via chats, posts, videos and recommendations. Community features bolted onto a product usually fall short. A product whose main purpose is that interaction does not.

Borderline cases are common: a niche forum with paid listings, a B2B ordering portal where distributors resell, an app with a messaging layer. Write down the reasoning for each client. A documented "out of scope because X" is worth more in an audit than an undocumented assumption.

Size and classification: the test most clients skip

The size rule still applies. A provider must be at least medium-sized: 50 or more staff, or annual turnover and balance sheet both above €10 million. Our 70-person Utrecht platform passes. A 12-person startup running the same service does not.

Passing the size test makes the client an important entity under Annex II. In practice that means fines of up to €7 million or 1.4% of worldwide annual turnover, whichever is higher, under the directive's ceiling for important entities, and a management body that carries the responsibility. For the wider scoping logic, see Does NIS2 apply to my organisation?.

Does NIS2 Apply to Your Organisation?

1

Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?

Yes ↓No →
2

Does your organisation have 50 or more employees, or both an annual turnover and a balance sheet total exceeding €10 million?

Yes ↓No →
3

Is your organisation a critical infrastructure provider or a qualified trust service provider?

Yes ↓No →
✗

NIS2 does not directly apply to your organisation.

✓

NIS2 applies to your organisation as an Essential or Important Entity.

!

NIS2 may apply to your organisation — seek legal advice to confirm your status.

Applies
Possibly applies
Does not apply

One regulator for the whole EU: Article 26

Most sectors fall under the country where they operate. Marketplaces, search engines and social networks follow a different rule. Under Article 26(1)(b), they fall under the Member State where they have their main establishment in the Union.

Article 26(2) defines that as the Member State where decisions on cybersecurity risk-management measures are predominantly taken. If that cannot be determined, it is where cybersecurity operations are carried out. If that fails too, it is the Member State with the establishment that has the most employees.

This matters for your MSP clients. A platform run from Utrecht but selling in Germany, France and Poland answers to one national authority, not four. And under Article 26(3), a provider established outside the EU that offers services inside it must designate a representative in a Member State where it offers services. The Member State of that representative gets jurisdiction. Our post on which regulator supervises your client walks through the cascade in detail.

Registration under Article 27: a duty that does not wait for audits

Article 27 requires these providers to submit identifying data for the registry that ENISA maintains. The list is specific: entity name, sector and type under Annex II, the address of the main establishment and other EU establishments (or the representative), current contact details, the Member States where services are offered, and the entity's IP ranges.

The first submission was due by 17 January 2025. Any change must be reported without delay and in any event within three months. IP ranges are the item clients forget. They change whenever a CDN or hosting arrangement changes, and nobody tells the compliance owner.

National registers add their own portals and dates. Germany's registration backlog shows what happens when nobody owns the task.

Incident thresholds: 5% of users or 1 million

For marketplaces, search engines and social networks, the Implementing Regulation sets user-based triggers in Articles 11, 12 and 13. An incident is significant if the service is completely unavailable for, or has limited availability for, more than 5% of its users in the Union or more than 1 million users, whichever is smaller. A data compromise affecting that many users also qualifies.

A suspected malicious compromise of data integrity, confidentiality or authenticity is significant regardless of user count. Article 3 adds general triggers that apply to everyone, including direct financial loss above €500,000 or 5% of annual turnover, whichever is lower.

Take a marketplace with 400,000 EU users. Five percent is 20,000. An outage hitting 20,000 users, or a credential leak affecting 20,000 accounts, is significant. Many teams assume the one-million figure is the bar. For small and mid-sized platforms, the percentage is the bar.

Once an incident is significant, the three-step Article 23 sequence applies. The reporting deadlines are 24 hours for the early warning, 72 hours for the incident notification, and one month for the final report.

NIS2 Incident Reporting Timeline

24h

Early Warning

Notify the competent authority (CSIRT/NCA) within 24 hours of becoming aware of a significant incident.

72h

Incident Notification

Submit a detailed notification within 72 hours with an initial assessment of severity, impact and indicators of compromise.

1mo

Final Report

Deliver a comprehensive final report within one month covering root cause, remediation taken and cross-border impact.

Where the supervisor stands in October 2026

Your client's obligations depend on how its main-establishment country transposed the directive. The picture is uneven: some Member States are fully live, others are still legislating. France and Spain face Court of Justice proceedings for non-transposition. See the implementation timeline for the full list.

NIS2 transposition by country

  • AustriaIn force
    • In force since October 1, 2026
    • Act: NISG 2026 (BGBl. I Nr. 94/2025)
    • Registration due December 31, 2026

    Authority: Federal Office for Cybersecurity · Source

  • NetherlandsIn force
    • In force since August 15, 2026
    • Act: Cyberbeveiligingswet (Stb. 2026, 187)
    • Registration required, no transition period

    Authority: NCSC (MijnNCSC) · Source

  • LuxembourgIn force
    • In force since May 10, 2026
    • Act: Law of 5 May 2026
    • Registration due July 10, 2026

    Authority: ILR (CSSF for finance) · Source

  • PolandIn force
    • In force since April 3, 2026
    • Act: UKSC (Dz.U. 2026 poz. 252)
    • Registration due October 3, 2026
    • Measures due April 3, 2027

    Authority: Minister Cyfryzacji (Wykaz KSC) · Source

  • PortugalIn force
    • In force since April 3, 2026
    • Act: Decree-Law 125/2025 (RJC)

    Authority: CNCS · Source

  • BulgariaIn force
    • In force since February 13, 2026
    • Act: Cybersecurity Act amendment (State Gazette No 17/2026)

    Authority: Ministry of e-Government · Source

  • MaltaIn force
    • In force since January 23, 2026
    • Act: S.L. 460.41

    Authority: Critical Infrastructure Protection Department · Source

  • SwedenIn force
    • In force since January 15, 2026
    • Act: SFS 2025:1506

    Authority: NCSC-SE · Source

  • EstoniaIn force
    • In force since January 1, 2026
    • Act: Cybersecurity Act (KüTS) amendment
    • Registration within 3 months

    Authority: RIA · Source

  • GermanyIn force
    • In force since December 6, 2025
    • Act: NIS2UmsuCG
    • Registration due March 6, 2026
    • 17,729 registered by June 30, 2026

    Authority: BSI · Source

  • CzechiaIn force
    • In force since November 1, 2025
    • Act: Act No 264/2025 Coll.
    • Registration within 60 days

    Authority: NÚKIB · Source

  • DenmarkIn force
    • In force since July 1, 2025
    • Act: NIS 2 Act No 434 of 6 May 2025
    • Registration due October 1, 2025

    Authority: Danish Agency for Societal Security · Source

  • SloveniaIn force
    • In force since June 19, 2025
    • Act: ZInfV-1 (OG 40/25)
    • Registration within 30 days

    Authority: URSIV · Source

  • CyprusIn force
    • In force since April 25, 2025
    • Act: Law 60(I)/2025

    Authority: Digital Security Authority · Source

  • FinlandIn force
    • In force since April 8, 2025
    • Act: Cybersecurity Act 124/2025
    • Registration due May 8, 2025
    • Measures due July 8, 2025

    Authority: Traficom (NCSC-FI) · Source

  • HungaryIn force
    • In force since January 1, 2025
    • Act: Act LXIX of 2024

    Authority: SZTFH · Source

  • SlovakiaIn force
    • In force since January 1, 2025
    • Act: Act No 366/2024 Coll.
    • Registration within 60 days

    Authority: NBÚ · Source

  • RomaniaIn force
    • In force since December 31, 2024
    • Act: GEO 155/2024 (Law 124/2025)
    • Registration within 30 days

    Authority: DNSC · Source

  • GreeceIn force
    • In force since November 27, 2024
    • Act: Law 5160/2024 (Gazette A' 195)

    Authority: National Cybersecurity Authority · Source

  • BelgiumIn force
    • In force since October 18, 2024
    • Registration due March 18, 2025

    Authority: CCB · Source

  • LithuaniaIn force
    • In force since October 18, 2024
    • Act: Law No XIV-2902

    Authority: NCSC (MoND) · Source

  • ItalyIn force
    • In force since October 16, 2024
    • Act: D.Lgs. 138/2024
    • Baseline measures due by October 2026 (entities listed in 2025)

    Authority: ACN · Source

  • LatviaIn force
    • In force since September 1, 2024
    • Act: National Cybersecurity Law

    Authority: National Cybersecurity Centre · Source

  • CroatiaIn force
    • In force since February 15, 2024
    • Act: Cybersecurity Act (OG 14/2024)

    Authority: NCSC (SOA) · Source

  • FranceNot yet transposed
    • Senate adopted the law on March 12, 2025
    • Regulator published its framework on March 17, 2026
    • Referred to the Court of Justice on July 8, 2026
    • Pre-registration open

    Authority: ANSSI · Source

  • SpainNot yet transposed
    • Draft bill approved on January 14, 2025
    • Referred to the Court of Justice on July 8, 2026
    • The NIS1 regime still applies

    Authority: CCN / INCIBE · Source

  • IrelandNot yet transposed
    • Referred to the Court of Justice on July 8, 2026
    • Bill not yet enacted

    Authority: NCSC Ireland · Source

Status as of September 28, 2026. Other member states: see the country-by-country timeline.

What to check this month

For each platform client, work through five questions. Does the service meet one of the three Article 6 definitions? Does the client pass the size test? Where are cybersecurity decisions predominantly taken, so which regulator applies? Is the client in the national register and the Article 27 data current, including IP ranges? And has anyone checked the user counts against the 5% and 1 million triggers?

Most clients can answer the first two in an afternoon. The last three expose the real gaps. If you want a structured starting point, run a free NIS2 readiness scan and use the output as the baseline for the client conversation.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.