Compare & price
HomeGuidesNIS2 et hébergement

NIS2: what you must demand from your data center

Directive (EU) 2022/2555, known as NIS2, is not aimed only at large infrastructure. It requires thousands of companies to manage their supply chain risk, and your hosting provider is part of it. It also imposes notification deadlines so short that they are unworkable without that provider's cooperation. This guide sets out what changes concretely for anyone renting a cabinet, and lists the evidence to obtain before signing.

Estimate my cost →

Two categories, two supervision regimes #

The NIS2 directive distinguishes essential entities from important ones. The first belong to the highly critical sectors of its Annex I and are supervised ex ante: the authority may inspect without waiting for an incident. The second are supervised ex post, on report or after an event. The difference also shows in penalties, set by Article 34: up to 10 million euros or 2 % of total worldwide annual turnover for an essential entity, whichever is higher; up to 7 million or 1.4 % for an important one. The directive itself is the authority.

Digital infrastructure is in Annex I, and so is your provider #

Data centre service providers, internet exchange points, cloud computing service providers and public electronic communications networks all sit among the highly critical sectors. Your data center is therefore not only a supplier to watch: it may itself be in scope, with its own risk management and notification duties. That is good news for you, because a provider in scope has built, or must build, exactly what you need.

Three deadlines, counted from when you become aware #

Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, a substantive notification with a severity and impact assessment within 72 hours, an intermediate report if the authority asks, then a final report within one month of the notification. These deadlines run from AWARENESS, not from resolution. That is what turns this from a legal topic into an operational one: if your provider takes eight hours to tell you what happened, you have already spent a third of your first deadline.

The three notification deadlines for a significant incidentThree deadlines, counted from the moment you become aware of the incidentAwareness24 hEarly warning72 hSubstantive notification1 monthFinal reportThe clock starts at AWARENESS of the incident, not at its resolution.Article 23 of Directive (EU) 2022/2555. An intermediate report may be requested between the last two milestones.
The three Article 23 deadlines. The clock starts when you become aware, not when the incident ends.

The supply chain becomes your responsibility #

NIS2 requires risk management measures that explicitly cover supply chain security, including relationships with direct suppliers. An availability commitment is no longer enough: you need to know how your provider manages its own risks, how it warns you, and what it records. A contract silent on all this leaves you carrying alone an obligation you cannot meet.

The eight pieces of evidence to ask for before signing #

Where France stands, as of 6 September 2026 #

French transposition runs through a resilience bill not adopted at this date, and the European Commission referred France to the Court of Justice of the European Union in July 2026 over the delay, as it did for other Member States. In practice the national timetable is still moving, but two things do not depend on it: the obligations flowing from the directive are known, and the evidence listed above can be requested today, in a live negotiation or at renewal. ANSSI publishes the state of play and the registration arrangements.

What DataColoc can check, and what it does not know #

The comparator shows certifications declared site by site, with their validity date, and refuses to attribute to a whole group what covers only one building. That is one item of the file, not the file. A provider's NIS2 status, its escalation channels and its first-information deadlines are published by nobody today: they are asked for, in writing, and written into the contract. No comparator can invent them.

What to remember #

NIS2 is not settled with a tick box. It turns a commercial relationship into a chain of responsibility, with deadlines counted in hours. The useful question is not « is my provider compliant », which means nothing, but « what does it send me, to whom, how fast, and what is written down ». Ask the eight questions before signing: they cost an email, and they decide whether you can meet your own obligations.

FAQ #

Is my data center in scope for NIS2?

Data centre service providers and internet exchange points appear in the highly critical sectors of Annex I. Whether a given provider is actually in scope then depends on size and on national transposition. The right move is to ask in writing rather than assume.

What are the notification deadlines?

An early warning within 24 hours of becoming aware, a substantive notification within 72 hours, an intermediate report on request, then a final report within one month of the notification. The clock starts at awareness, not at resolution.

What penalties are provided for?

Article 34 sets minimum maximums that Member States must provide: up to 10 million euros or 2 % of total worldwide annual turnover for an essential entity, whichever is higher; up to 7 million or 1.4 % for an important one.

Is ISO 27001 certification enough to be compliant?

No. A certification is one useful piece of evidence among others, and it covers only the scope for which it was issued. Always check it names the SITE you rent, not the group, and that it is in date.

What if my provider refuses to commit to a first-information deadline?

That is information in itself. Without a written deadline your 24 hours are not workable and you carry the risk alone. The subject is negotiated at renewal, where your position is strongest.

Written on 6 September 2026.

From reading to comparing: relevant data centers

Telehouse - Paris 2 (Voltaire - Léon Frot)
Paris · 356 networks on site · certified ISO 27001, PCI DSS
See the exact price →
Equinix PA2 - Paris, Saint-Denis
Paris · 146 networks on site · certified HDS, ISO 22301
View the listing →
Equinix PA3 - Paris, Saint-Denis
Paris · 122 networks on site · certified HDS, ISO 22301
View the listing →
UltraEdge Lyon-Venissieux
Vénissieux · 83 networks on site · certified ISO 27001, ISO 50001
View the listing →

Estimate my cost →   Compare data centers

Other guides

Guides · Expert answers →

Advertisement