Key takeaway: registration is an administrative act, not a security control, but it is the act that makes you visible to a supervisor. Getting it wrong in either direction is expensive. Registering under the wrong classification invites supervision you are not ready for. Not registering at all leaves you in scope anyway, with an added finding that is trivial for an authority to prove.
Most NIS2 programmes start with the security measures in Article 21, because that is where the work is. Registration gets treated as paperwork and slips to the end of the plan. That order is backwards. Registration is what puts your entity on the national list, and the national list is what determines whether a supervisor knows you exist, which regime applies to you, and which authority sends the first letter.
This article covers the mechanics. What the two registration duties are and how they differ. What data each one asks for. How jurisdiction is decided when you operate in more than one Member State. What the ongoing change notification obligation means in practice. And the classification work you need to finish before you fill in a single field.
There are two registration duties, not one
The confusion in most boardrooms comes from treating NIS2 registration as a single act. It is not. The directive creates two distinct obligations, and some organisations are caught by both.
1. National registration under Article 3(4)
This applies to every in-scope essential and important entity, in every sector of Annex I and Annex II. Member States must require entities to submit identification and contact information so a national list of essential and important entities can be established and maintained. The data goes to whichever body the Member State designated for the purpose, usually the competent authority for your sector or the national single point of contact.
2. The Article 27 registry, forwarded to ENISA
This applies to a defined list of digital and ICT service providers only. Their data is collected nationally and forwarded to ENISA, which maintains a Union-level registry. The purpose is different: these entity types are typically cross-border by nature, so a single register avoids the situation where a cloud provider serving eleven Member States appears in none of their lists.
The Article 27 list is specific. It names DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines, and social networking services platforms. If your business model is not on that list, Article 27 does not apply to you, and national registration is your only registration duty.
The practical consequence: a Dutch managed service provider with 90 staff has both duties. It registers nationally as an important entity in the ICT service management sector, and its data feeds the ENISA registry because managed service providers are named in Article 27. A Dutch hospital of the same size has only the first.
What data you actually submit
The directive sets a minimum data set. Member States can and do ask for more through their national portals, but every implementation includes at least the following.
- Entity name. The registered legal name, not the trading name. Where a group has several legal entities in scope, each one registers separately. This is the field that most often diverges from what the chamber of commerce holds.
- Address. For the Article 27 entity types this is the address of the main establishment and, where relevant, of other legal establishments in the Union or of the designated Union representative.
- Up-to-date contact details. Email addresses and telephone numbers. Use a monitored functional mailbox, not a named individual. A supervisory letter that lands in the mailbox of someone who left two years ago still counts as delivered.
- Sector and subsector. The Annex I or Annex II entry that applies, plus the type of entity. This single field decides which competent authority supervises you and, in most Member States, which sectoral guidance you are expected to follow.
- Member States of operation. Where applicable, the list of Member States in which you provide services falling within the scope of the directive. This drives cross-border supervisory cooperation.
- IP ranges. Part of the contact data set, and required for the Article 27 registry as well. This exists so that CSIRTs can attribute observed activity to a known entity and warn it, which is genuinely useful and worth keeping accurate.
- Type of entity. An additional field in the Article 27 data set, distinguishing for example a cloud computing service provider from a data centre service provider.
Which Member State, and the main establishment rule
Article 26 answers the jurisdiction question. The default is straightforward: an entity falls under the jurisdiction of the Member State where it is established. If you are a manufacturer with one plant in the Netherlands, you register with the Dutch authority and there is nothing more to think about.
For the Article 27 entity types the rule changes to main establishment. The main establishment is normally the place where decisions on cybersecurity risk-management measures are predominantly taken. If that cannot be determined, the fallback is the establishment where cybersecurity operations are carried out, and failing that the establishment with the highest number of employees in the Union. The point of this cascade is to give a cross-border cloud or managed service provider exactly one lead supervisor rather than twenty-seven.
Two edge cases deserve attention. Providers of public electronic communications networks and publicly available electronic communications services fall under the jurisdiction of each Member State where they provide their services, which is a broader test than main establishment. And entities that are not established in the Union but offer in-scope services within it must designate a representative in the Union, established in one of the Member States where the services are offered. That representative is the point of contact for supervision, and the entity falls under the jurisdiction of that Member State.
Classify before you register
Registration asks you to declare your sector and, in most national portals, your classification as essential or important. Answer that question properly before you open the form, because the answer determines your supervisory regime.
Essential entities are subject to ex ante supervision under Article 32. That means on-site inspections, off-site supervision including random checks, regular and targeted security audits, ad hoc audits, security scans, and requests for information and evidence, whether or not anything has gone wrong. Important entities are supervised ex post under Article 33: the authority acts when it has evidence or an indication of non-compliance. The maximum administrative fines differ too, at least ten million euro or two percent of total worldwide annual turnover for essential entities, and at least seven million euro or 1.4 percent for important entities, in each case whichever is higher.
The general pattern is that large entities in Annex I sectors are essential, medium-sized Annex I entities and Annex II entities are important, and a set of specific cases in Article 3(1) are essential regardless of size. Trust service providers, TLD name registries, DNS service providers and certain public administration entities sit in that last group. Size is measured with the criteria in the annex to Commission Recommendation 2003/361/EC, which counts headcount alongside turnover and balance sheet total, and includes linked and partner enterprises. That last part is what pulls a 30-person subsidiary of a large group into scope.
Pre-registration checklist
- A written scope determination per legal entity, with the Annex I or II entry cited and the size calculation shown, including linked and partner enterprises.
- A classification decision, essential or important, signed off by the management body rather than assumed by the security team.
- A monitored functional mailbox and phone number that will still work in three years, with a named owner and a deputy.
- The list of Member States where in-scope services are provided, agreed with sales and legal rather than estimated by IT.
- The current IP ranges, exported from the source of truth, with an owner responsible for keeping them current.
- A main establishment analysis if you operate across borders, documenting where cybersecurity risk-management decisions are predominantly taken.
- A change trigger list wired into legal, HR and network operations, so the two-week notification clock actually starts when something changes.
The two-week change rule
Registration is not a one-off. Entities must notify changes to the submitted data without delay, and in any event within two weeks of the change taking effect. Most organisations register once, file the confirmation, and never think about it again. Two years later the address is a former office, the contact is a former employee, and the sector code no longer matches what the business does.
The fix is unglamorous and takes an afternoon. Write down the events that change registration data, and attach the notification step to the process that already handles each event. A registered office move is a legal and facilities process. A change of security contact is an HR leaver process. A new Member State of operation is a sales or contracting milestone. A new IP block is a network change record. None of these need a new process, they need one extra line in an existing one.
Common registration mistakes
- Registering the group, not the entity. Scope applies per legal entity. A holding company registration does not cover the operating subsidiaries, and a supervisor will read the register at entity level.
- Guessing the sector code. Several businesses genuinely sit across two Annex entries. Pick deliberately, document the reasoning, and be ready to defend it. An arbitrary choice becomes a credibility problem the moment a supervisor asks why.
- Declaring important when the size test says essential. This looks like a small saving and reads, later, like an attempt to avoid ex ante supervision. Recalculate the headcount and turnover figures with linked and partner enterprises included before you decide.
- Using a personal mailbox as the contact. Regulatory correspondence, CSIRT warnings and incident follow-ups all arrive at the registered address. A personal mailbox turns an urgent warning into an out-of-office reply.
- Treating registration as evidence of compliance. It is evidence of existence. Being on the list with no Article 21 measures in place simply means the authority now knows exactly where to look.
- Forgetting the Union representative. Non-EU entities offering in-scope services in the Union need one, and the designation has to be real rather than a name on a form.
What happens after you register
Registration puts you into the supervisory workflow. Expect three things over time. First, correspondence: sector guidance, questionnaires, and in some Member States a self-assessment request in the first year. Second, CSIRT contact: warnings about vulnerabilities and observed activity relevant to your sector or your registered IP ranges. Third, the possibility of a supervisory action, which for essential entities does not require any prior indication of a problem.
The organisations that handle this well treat the registration record as the front page of their compliance file. The register says what you are. The evidence file has to say the same thing, in the same words, with the same entity names, the same sector, and the same services. Where those two documents disagree, the disagreement is the first question you will be asked.
Frequently asked questions
Does NIS2 require me to register my organisation?
Yes, if you are an in-scope essential or important entity. Article 3(4) of the directive requires Member States to make in-scope entities submit identification and contact data so the national list of essential and important entities can be built. Registration is a separate obligation from implementing the Article 21 security measures, and it is usually the first thing a supervisor checks.
What is the difference between national registration and the ENISA registry?
National registration under Article 3(4) applies to all in-scope entities and goes to the competent authority or single point of contact in your Member State. The Article 27 registry is narrower: it covers a specific list of digital and ICT service provider types, and their data is forwarded to ENISA so a Union-level registry exists. Entities in that list can face both duties.
Which entity types must submit data for the ENISA registry?
Article 27 names DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines and social networking services platforms.
What data does NIS2 registration require?
At minimum: the entity name, address and up-to-date contact details including email addresses, IP ranges and telephone numbers, the relevant sector and subsector from Annex I or II, and, where applicable, the list of Member States where the entity provides in-scope services. The Article 27 registry adds the type of entity and the address of the main establishment or of the Union representative.
Which Member State do I register in if I operate across the EU?
The default rule in Article 26 is that an entity falls under the jurisdiction of the Member State where it is established. For the digital and ICT provider types listed in Article 27, jurisdiction follows the main establishment, which is normally where decisions on cybersecurity risk-management measures are predominantly taken. Entities outside the Union that offer in-scope services inside it must designate a representative in the Union.
How quickly must I report a change to my registration data?
The directive requires entities to notify changes without delay and in any event within two weeks of the change taking effect. In practice this catches address changes, mergers, a new security contact, a new Member State of operation, and changes to your IP ranges.
What happens if I do not register?
Failing to register does not put you out of scope. Scope follows the sector and size criteria in Article 2, not the register. An unregistered in-scope entity is a non-compliant entity, and because registration data is cheap to cross-check against company registers, it is one of the easiest findings for a supervisor to make.
Not sure which registration duties apply to you?
We run scope and classification determinations that hold up in front of a supervisor: the entity list, the size calculation, the Annex mapping, the jurisdiction analysis, and the registration data set ready to submit.
Book a scope and registration review