To fulfil your cybersecurity obligations in the EU – even without your own establishment
The NIS-2 Directive (EU) 2022/2555 requires certain organisations providing critical or important digital services to implement comprehensive measures in the areas of cybersecurity and incident management. For organisations not established in the EU but which nevertheless provide services within the EU and fall within the scope of NIS-2, the following also applies:
- The company is not established in the EU,
- but offers services within the EU, and
- belongs to the categories covered by NIS-2 (e.g. cloud computing providers, DNS service providers, data centre service providers, managed service providers, managed security service providers, online marketplaces, search engines or social media platforms).
In such cases, pursuant to Article 26(3) of NIS-2, a representative must be appointed in an EU Member State where the services are provided. This representative acts as the official point of contact for the competent authorities and CSIRTs and serves as the central channel for communication and enforcement regarding NIS-2 matters.
Our role as your external EU representative under NIS-2
Our cybersecurity and compliance specialists will act as your external EU representative under NIS-2 and ensure that enquiries and requirements from the EU are coordinated, dealt with in a timely manner and in your best interests.
Among other things, we offer you:
- Acting as the official point of contact in the EU for competent supervisory authorities and CSIRTs under NIS-2 through our subsidiary, Swiss Infosec (Deutschland) GmbH, based in Berlin, Germany
- Receipt, coordination and forwarding of official correspondence, orders and requests for information
- Support with the organisation and adherence to reporting deadlines for significant security incidents
- Pragmatic recommendations for action regarding NIS-2 obligations (risk management, technical and organisational measures, reporting processes) based on proven best practices
- Support in aligning NIS 2 requirements with existing information security management systems (e.g. ISO 27001)
- A reliable point of contact who understands your business model and digital service landscape and speaks your language
This allows you to focus on your core business and your growth in the EU market. We take care of the operational implementation of the representative role and ongoing communication with the authorities.
Why choose Swiss Infosec as your NIS-2 representative in the EU?
- Combined expertise in cybersecurity and regulation: many years of experience in information security, data protection and regulatory requirements in the EU
- Practical, risk-based advice rather than purely formal compliance checklists
- Understanding of cloud services, managed services, platform and online business models typically affected by NIS-2
- Clear lines of responsibility and short communication channels in the event of incidents, audits or enquiries from authorities
Our goal: to design NIS-2 compliance in such a way that you are legally compliant without unnecessarily slowing down your business.
Next steps
Contact us for a no-obligation initial consultation. Together, we will clarify:
- Whether your company falls within the scope of NIS-2, and
- how we can efficiently integrate the role of the NIS-2 representative into your existing processes.
Let us take care of the role of the EU representative under NIS-2, so that you can provide your digital services in the EU market securely, in full compliance with the law and with a view to the future.