Service Overview

The NIS2 Directive — Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union — entered into force on 16 January 2023, with national transposition by 17 October 2024. It introduces enhanced cybersecurity, governance and incident-reporting obligations for organisations providing digital infrastructure and online platform services within the European Union. Article 26(3) of the Directive requires certain entities not established in the Union but providing in-scope services within it to designate, in writing, a representative established in one of the Member States where the services are offered. Where services are provided across multiple Member States, a single representative may be appointed for the Union as a whole.

Are you providing in-scope digital services to users across the European Union from outside the Union?

Lionheart provides Article 26 representation through Lionheart Squared (Europe) Limited, our Dublin-based EU entity. The mandate is structured as a formal compliance interface — receiving correspondence from competent authorities, supporting incident-notification cadence, and acting as the named point of contact for NIS2 supervision.

Article 26(3) makes the representative's location material: the Member State in which the representative is established becomes the Member State whose competent authority supervises the entity for NIS2 purposes. We have chosen Ireland deliberately. Ireland operates a federated NIS2 regulatory regime, with the National Cyber Security Centre (NCSC-IE) acting as lead competent authority and serving as Ireland's Single Point of Contact for cross-border cooperation with other Member States, the European Commission and ENISA. Significant incidents are reported to CSIRT-IE, which is encompassed within the NCSC.

As your representative, we accept that we may be addressed in addition to or instead of you by competent authorities on NIS2-related matters. Our duties under the mandate are concrete: promptly inform you of correspondence received from competent authorities, cooperate with those authorities by providing copies of the mandate, the underlying agreement and related materials concerning your compliance with NIS2, and permit you to disclose our appointment and approved contact details for publication. Within the operational structure of NIS2, the representative is the addressable counterparty — not the substantive compliance owner. That responsibility remains with you.

Service Detail

What this service covers

Our focus

Established in Ireland for genuine EU-facing representation

Article 26(3) makes the representative's location material: the Member State in which the representative is established becomes the Member State whose competent authority supervises the entity for NIS2 purposes. We have chosen Ireland deliberately. Ireland operates a federated NIS2 regulatory regime, with the National Cyber Security Centre (NCSC-IE) acting as lead competent authority and serving as Ireland's Single Point of Contact for cross-border cooperation with other Member States, the European Commission and ENISA. Significant incidents are reported to CSIRT-IE, which is encompassed within the NCSC.

Built around the duties Article 26 actually imposes

As your representative, we accept that we may be addressed in addition to or instead of you by competent authorities on NIS2-related matters. Our duties under the mandate are concrete: promptly inform you of correspondence received from competent authorities, cooperate with those authorities by providing copies of the mandate, the underlying agreement and related materials concerning your compliance with NIS2, and permit you to disclose our appointment and approved contact details for publication. Within the operational structure of NIS2, the representative is the addressable counterparty — not the substantive compliance owner. That responsibility remains with you.

Aligned with the NIS2 incident-notification cadence

NIS2 imposes a layered notification timeline for significant incidents: an early warning to the CSIRT or competent authority within 24 hours of becoming aware of the incident, an incident notification within 72 hours, and a final report within one month. You retain responsibility for determining whether an incident is significant and for filing those notifications. The representative's function on these clocks is to relay inbound authority correspondence and route enquiries to the right person at your organisation. The specific service levels — including the target turnaround for forwarding authority correspondence and the named escalation contacts — are agreed in writing with each customer at contract signature and tested as part of onboarding, so that both parties begin the engagement with a shared, documented understanding of how the channel will work in a live incident.

Our services include

Formal designation

Acting as your EU NIS2 representative under Article 26(3) of the Directive, by written mandate, with clearly documented scope and procedures.

Ireland-based contact details

A dedicated representative email address and Lionheart's Dublin postal address, available for inclusion in your public-facing materials and any required disclosures to competent authorities.

Authority liaison

Acting as the formal contact point for Ireland's National Cyber Security Centre (NCSC-IE) — Ireland's lead competent authority and Single Point of Contact for NIS2 — and for cross-border cooperation with other Member States' authorities, the European Commission and ENISA where relevant.

Authority correspondence handling

Prompt receipt, logging and forwarding of regulatory correspondence; provision of mandate and agreement copies to competent authorities on request, in cooperation with you.

Incident-notification escalation

Defined escalation paths and service levels aligned with NIS2's 24-hour early warning, 72-hour incident notification and one-month final report cadence, supporting the responsibility you retain for filing those notifications.

Registration support

Practical support with the contact-information disclosures required when your appointment is communicated to authorities and reflected in your public materials.

Coordinated mandates

Single-relationship handling where NIS2 obligations overlap other Lionheart EU representative services — GDPR, DSA, AI Act, TCOR and e-Evidence — under one engagement and one escalation path.

Legal basis: Article 26, EU NIS2 Directive (Directive (EU) 2022/2555). Single Point of Contact and CSIRT functions in Ireland are vested in the National Cyber Security Centre (NCSC-IE).

NIS2 covered categories (high level)

Cloud computing services, DNS service providers, TLD name registries, data centre service providers, content delivery networks, managed service providers and managed security service providers, online marketplaces, online search engines, and social networking platforms — among others. The Directive's full scope is set out in Annexes I and II of Directive (EU) 2022/2555.

Size-based exemption

Micro and small enterprises are generally outside scope, with limited exceptions — including providers of DNS services, TLD name registries and certain managed ICT services on a B2B basis, where the size-based exemption does not apply. Whether your organisation falls within or outside scope is a question worth taking advice on; Lionheart can provide a preliminary assessment.

Note on terminology

The NIS2 term 'legal representative' (in the substantive cybersecurity-governance sense) refers to your senior management — not to your appointed Article 26 representative. The two concepts are distinct.

Get started

Not sure if you are in scope?

Use the guided self-check tool to map which representative obligations may apply.