Last updated: 6 October 2026
Quick answer: NIS2 registration means giving your national competent authority the information it needs to list you as an essential or important entity. Article 3 sets the general rule, with changes reported within two weeks. Article 27 adds a separate registry for digital providers such as cloud, DNS and managed service providers, with changes reported within three months.
Registration is often the first NIS2 obligation an organisation actually has to act on. It is also the one most likely to be missed, because it is set out in national law and delivered through national portals that differ from country to country.
Getting it right matters. Registration is how supervisors know you exist, which sector you belong to and how to contact you when an incident or inspection arises.
This guide explains the NIS2 registration requirements in Articles 3 and 27, the information you need to prepare, the deadlines and update rules, and how registration works in practice in several Member States.
What is NIS2 registration?
NIS2 registration is the process by which in-scope entities submit identifying and contact information to their national authority so that the Member State can build and maintain its list of essential and important entities.
The NIS2 Directive (EU) 2022/2555 contains two registration regimes:
- Article 3: a national list of essential and important entities, plus entities providing domain name registration services. Member States had to establish it by 17 April 2025 and must review and, where appropriate, update it regularly and at least every two years.
- Article 27: a registry of certain digital infrastructure and digital service providers, maintained by ENISA on the basis of information forwarded by national single points of contact.
Both regimes rely on the entity to provide the information. Authorities do not always know who is in scope, which is why NIS2 puts the duty on you.
Who must complete NIS2 registration?
Every essential and important entity must provide registration information under Article 3, and a defined group of digital providers must also provide information under Article 27.
| Regime | Who | Initial deadline in the directive | Changes reported within |
|---|---|---|---|
| Article 3 | Essential and important entities; entities providing domain name registration services | List established by 17 April 2025 | Two weeks |
| Article 27 | DNS service providers, TLD name registries, domain name registration services, cloud computing, data centre and content delivery network providers, managed service providers, managed security service providers, online marketplaces, online search engines and social networking platforms | Information submitted by 17 January 2025 | Three months |
Article 27 entities are usually also essential or important entities, so in many countries they register once through a single national process that captures both sets of data.
In practice: the directive dates are the EU baseline. Your actual deadline is whatever your national law sets. Where transposition happened late, the national deadline is later, and some Member States set different dates for different entity types.
What information do you need to submit?
Under Article 3(4) you provide your name, contact details, IP ranges, sector and the Member States you serve; Article 27(2) asks for a similar but more detailed set, including the address of your main establishment and any EU representative.
| Data item | Article 3(4) | Article 27(2) |
|---|---|---|
| Name of the entity | Yes | Yes |
| Address and up-to-date contact details, including email and telephone | Yes | Yes, including of any EU representative |
| IP ranges | Yes | Yes |
| Sector, subsector and entity type (Annex I or II) | Where applicable | Where applicable, including type of entity |
| Member States where services are provided | Where applicable | Yes |
| Main establishment and other legal establishments in the EU | Not listed | Yes |
Under Article 27(4), the national single point of contact forwards the Article 27 information to ENISA, except the IP ranges, which stay at national level.
National forms often ask for more than the directive minimum. Germany’s Federal Office for Information Security (BSI), for example, lists legal form, contact persons, supervisory authorities and company size data among the information it asks entities to provide.
Which Member State do you register in?
Most entities register where they are established; certain digital providers register where they have their main establishment in the EU, and non-EU providers must appoint an EU representative.
Article 26 sets the rules. As a general principle, entities fall under the jurisdiction of the Member State in which they are established. For DNS providers, TLD registries, domain name registration services, cloud, data centre and CDN providers, MSPs, MSSPs and the listed online platforms, jurisdiction lies with the Member State of their main establishment. That is where cybersecurity risk-management decisions are predominantly taken, or, failing that, where cybersecurity operations are carried out or where the entity has the most employees in the EU.
If such a provider is not established in the EU but offers services there, it must designate a representative in one of the Member States where it provides services.
Common mistake: assuming one registration covers a group. Each legal entity that meets the criteria usually needs to register in the Member State with jurisdiction over it. A group with subsidiaries in several countries may face several registrations, on different portals, with different deadlines.
How does NIS2 registration work in practice?
Article 3(4) lets Member States set up national mechanisms for entities to register themselves, so in practice you register through a national online portal run by the competent authority or cybersecurity agency.
Belgium
Belgium’s NIS2 law of 26 April 2024 entered into force on 18 October 2024. According to the Centre for Cybersecurity Belgium, entities register on the Safeonweb@Work platform. Essential, important and domain name entities had five months, until 18 March 2025, while digital sector entities had two months, until 18 December 2024. The portal pulls some data automatically from the Crossroads Bank for Enterprises.
Germany
Germany’s NIS2 implementation act entered into force on 6 December 2025. The BSI says entities must register within three months of first becoming subject to NIS2, so the first deadline fell in early March 2026. On 6 January 2026 the BSI announced its new portal, estimating about 29,500 companies and federal institutions in scope. Registration takes two steps: first an account with the “Mein Unternehmenskonto” service, then registration in the BSI portal. The BSI later gave businesses until 31 July 2026 to catch up on overdue registrations. That grace period has ended, so any entity still unregistered should register without delay.
Italy
Italy’s national cybersecurity agency, ACN, ran a registration window on its portal for NIS entities with a deadline of 28 February 2025.
These examples show how much the process varies. Transposition is also still uneven: in May 2025 the Commission sent reasoned opinions to 19 Member States for not fully transposing NIS2, and on 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice. Our NIS2 transposition tracker summarises the status by Member State. Check the current status in each country where you operate before assuming a deadline has passed or not yet started.
If you track NIS2 alongside other frameworks, you can start your 14-day free trial and keep registration records, deadlines and evidence for each entity in one place.
How do you prepare for NIS2 registration?
Confirm scope and jurisdiction first, then gather the data, register through the right portal and set up a process to keep the record current.
- Confirm scope. Check whether each legal entity is essential, important or out of scope, based on sector, size and any national designation. A structured compliance assessment helps document the reasoning.
- Identify jurisdiction. Apply Article 26 to decide which Member State has jurisdiction, especially for digital providers with a main establishment rule.
- Gather the data. Collect names, addresses, contact details, IP ranges, sector and subsector, and the list of Member States where you provide services.
- Name owners. Decide who is the registered contact and who keeps IP ranges and contact details up to date. Use shared mailboxes rather than personal ones.
- Register. Use the national portal and keep a copy of the submission and any confirmation or reference number.
- Set change triggers. Link registration updates to events such as office moves, new IP ranges, new countries or changes in sector, so you meet the two-week or three-month update deadline.
- Connect to incident reporting. Registration contacts often double as incident reporting contacts. Make sure your incident management process uses the same, current details.
In practice: IP ranges are the item most often out of date. Pull them from your network or cloud inventory and review them on a fixed schedule rather than relying on memory.
What happens if you do not register?
Consequences are set by national law, because Article 36 requires Member States to lay down effective, proportionate and dissuasive penalties for infringements of national NIS2 measures.
Failing to register also creates practical risk. Authorities may identify you anyway, and an unregistered entity that suffers a significant incident still has to meet the 24-hour early warning duty under Article 23. Being on the list with correct contacts makes that first report far smoother.
Registration is also the start, not the end. The same entity must implement the Article 21 risk-management measures and have its management body approve them. Mapping NIS2 to existing controls in a cross-framework compliance tool avoids duplicating work you have already done for ISO 27001 or other standards.
Key takeaways
- NIS2 has two registration regimes: Article 3 for essential and important entities and Article 27 for certain digital providers.
- Article 3 changes must be reported within two weeks; Article 27 changes within three months.
- You need name, addresses, contact details, IP ranges, sector and the Member States you serve.
- Registration happens through national portals, and deadlines depend on national law.
- Assign owners and change triggers so the registration stays current.
Frequently asked questions
Is NIS2 registration mandatory?
Yes, for entities in scope. NIS2 requires Member States to make essential and important entities submit registration information, and certain digital providers must submit additional information under Article 27. The exact procedure, portal and deadline are set in national law, so check the transposition law in each Member State where you are established or provide services.
Where do I register for NIS2?
You register with the competent authority in the Member State that has jurisdiction over you, usually through a national online portal. Examples include Safeonweb@Work in Belgium and the BSI portal in Germany. For certain digital providers, jurisdiction lies with the Member State of their main establishment in the EU.
What is the difference between Article 3 and Article 27 registration?
Article 3 covers all essential and important entities and feeds the national list, with changes reported within two weeks. Article 27 covers a defined group of digital providers, such as cloud, DNS and managed service providers, and feeds an ENISA registry, with changes reported within three months and more detailed establishment data.
Do I need to register in every EU country where I operate?
Not always. Most entities fall under the Member State where they are established, so a legal entity established in one country usually registers there. Groups with legal entities in several countries may need several registrations. Digital providers covered by the main establishment rule generally register only in the Member State of their main establishment.
How often must NIS2 registration information be updated?
Whenever it changes. Under Article 3, entities must notify changes without delay and within two weeks. Under Article 27, digital providers must notify changes without delay and within three months. National law may add periodic confirmation requirements, so keep an owner and a review schedule for the record.
Keeping your NIS2 registration current
NIS2 registration is short to complete but easy to get wrong across several entities and countries. Confirm scope and jurisdiction, gather accurate data, use the correct national portal and keep the record up to date as your organisation changes. The frameworks and regulations covered by Enactia’s AI-powered GRC platform include NIS2 alongside ISO 27001, DORA and GDPR.
For help organising your NIS2 programme, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
