Cyber Resilience

Service Overview

Are your digital services reaching users in the EU or the UK from outside their borders?

Europe's cybersecurity rulebook has moved from voluntary standards to binding obligations — with statutory representation at the centre. If your organisation provides in-scope digital infrastructure or online services to users in the EU or the UK and is not established in either jurisdiction, you may be required to designate a local representative under the EU NIS2 Directive, the UK NIS Regulations, or — once enacted — the UK Cyber Security and Resilience Bill.

Cybersecurity authorities work to short timelines, expect to reach a named and accountable counterparty, and treat the representative as the operational interface for incident notifications, registration formalities and supervisory cooperation. We have built our service to meet that expectation.

Service Detail

What this service covers

What sets our service apart

Real establishments in Ireland and the UK

NIS2 mandates are held through our Dublin entity; UK NIS mandates through our Hampshire-based entity. Cybersecurity authorities deal with named representatives — not anonymous inboxes.

Built for the incident-notification cadence

NIS2 imposes a 24-hour early warning, a 72-hour incident notification, and a one-month final report. Our escalation procedures are calibrated to those clocks. UK NIS timelines are handled in parallel.

One relationship across overlapping mandates

Cloud, DNS, CDN, managed ICT and online platform providers often hold parallel obligations under GDPR, DSA and AI Act. Lionheart consolidates these under a coordinated escalation path — which matters most during a significant incident.

Frameworks we cover

Framework status and legal basis

EU NIS2 Representative

Operative: Article 26, NIS2 Directive (EU) 2022/2555. For non-EU providers of cloud computing, DNS, TLD registries, data centres, CDNs, managed ICT, online marketplaces, search engines and social networking services offering services in the Union.

UK NIS Representative

Operative: Regulation 14A, UK NIS Regulations 2018. For non-UK Relevant Digital Service Providers — online search engines, online marketplaces and cloud computing services — offering services to users in the United Kingdom.

UK CSR Representative

In preparation: UK Cyber Security and Resilience Bill (Royal Assent anticipated late 2026). Service offering will be finalised once scope, registration and notification mechanics are confirmed. Register your interest now.

Get started

Not sure if you are in scope?

Use the guided self-check tool to map which representative obligations may apply.