Through an EU entity
A subsidiary, branch or acquired company operating in a covered sector is an in-scope entity in its own right, with its own registration, reporting duties and board accountability.
The EU's NIS 2 Directive binds essential and important entities to register with a national authority, implement cybersecurity measures and report incidents against fixed deadlines. For a US business it arrives through an EU subsidiary, services delivered into the EU, or — most often — an EU customer passing the obligation down the supply chain. We handle the EU side so your team does not have to learn it.
Directive (EU) 2022/2555 · transposed by each EU member state
Three questions, thirty seconds. Tap every statement that is true for your company.
This result is indicative and does not constitute legal advice. The official classification is made by the entity itself, on its own responsibility, through the relevant national authority.
The difference between "essential" and "important" changes the fine ceiling, the supervisory regime and the consequences for the board of your EU entity. Getting it wrong costs in both directions: penalties for obligations you missed, or money spent on measures you never needed.
NIS 2 does not regulate American companies as such. It regulates entities operating in the European Union — and then makes those entities answerable for the security of everyone who supplies them.
A subsidiary, branch or acquired company operating in a covered sector is an in-scope entity in its own right, with its own registration, reporting duties and board accountability.
Certain digital providers — cloud, data centers, managed services, marketplaces, search, social platforms — fall under the directive based on where the service is offered, not where the company is incorporated.
The route that catches the most US companies. In-scope entities must manage supply chain security, so the requirement arrives as a contract clause, a questionnaire or an audit right — with the renewal at stake.
This is not a list of good practice but a set of obligations with deadlines. Two of them start a clock you cannot stop: registration and incident reporting.
Enroll the entity on the national platform of the member state, with contact details and sector.
Assess security risks and self-assess maturity against the national methodology.
Policies, access control and multi-factor authentication, encryption, backup, business continuity and supply chain security.
Early warning, full notification and final report to the authority, for every significant incident.
Periodic security audits and mandatory management training, with the documentation that evidences both.
Take the services separately or the whole path, run by one team. The difference from pure consulting: the measures we recommend, we also implement — and then monitor.
We map which of your entities are in scope, in which member state, and prepare the entity file.
We map what you already run under SOC 2 or NIST onto what the directive requires, and price the delta.
The controls required by Article 21, actually put into operation — not merely written into procedures.
An external security officer for the EU entity, in the same time zone as the authority it reports to.
We detect, contain and prepare the notification file within the legal deadlines.
Periodic verification of compliance and the mandatory training for the management body.
You need a partner on the European side of this — one who understands both the directive and the infrastructure it lands on, and who is awake when the authority is.
A thirty-minute conversation and a free initial assessment show you which of your entities are in scope, where you stand against the NIS 2 requirements and what reaching compliance would involve.
We reply within 15 minutes. We do not send unsolicited offers.
The information on this page is general and indicative. It does not constitute legal advice and does not replace the legislation in force in any member state or official guidance from a competent authority.