Directive (EU) 2022/2555, known as NIS2, is not aimed only at large infrastructure. It requires thousands of companies to manage their supply chain risk, and your hosting provider is part of it. It also imposes notification deadlines so short that they are unworkable without that provider's cooperation. This guide sets out what changes concretely for anyone renting a cabinet, and lists the evidence to obtain before signing.
Estimate my cost →The NIS2 directive distinguishes essential entities from important ones. The first belong to the highly critical sectors of its Annex I and are supervised ex ante: the authority may inspect without waiting for an incident. The second are supervised ex post, on report or after an event. The difference also shows in penalties, set by Article 34: up to 10 million euros or 2 % of total worldwide annual turnover for an essential entity, whichever is higher; up to 7 million or 1.4 % for an important one. The directive itself is the authority.
Data centre service providers, internet exchange points, cloud computing service providers and public electronic communications networks all sit among the highly critical sectors. Your data center is therefore not only a supplier to watch: it may itself be in scope, with its own risk management and notification duties. That is good news for you, because a provider in scope has built, or must build, exactly what you need.
Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, a substantive notification with a severity and impact assessment within 72 hours, an intermediate report if the authority asks, then a final report within one month of the notification. These deadlines run from AWARENESS, not from resolution. That is what turns this from a legal topic into an operational one: if your provider takes eight hours to tell you what happened, you have already spent a third of your first deadline.
NIS2 requires risk management measures that explicitly cover supply chain security, including relationships with direct suppliers. An availability commitment is no longer enough: you need to know how your provider manages its own risks, how it warns you, and what it records. A contract silent on all this leaves you carrying alone an obligation you cannot meet.
French transposition runs through a resilience bill not adopted at this date, and the European Commission referred France to the Court of Justice of the European Union in July 2026 over the delay, as it did for other Member States. In practice the national timetable is still moving, but two things do not depend on it: the obligations flowing from the directive are known, and the evidence listed above can be requested today, in a live negotiation or at renewal. ANSSI publishes the state of play and the registration arrangements.
The comparator shows certifications declared site by site, with their validity date, and refuses to attribute to a whole group what covers only one building. That is one item of the file, not the file. A provider's NIS2 status, its escalation channels and its first-information deadlines are published by nobody today: they are asked for, in writing, and written into the contract. No comparator can invent them.
NIS2 is not settled with a tick box. It turns a commercial relationship into a chain of responsibility, with deadlines counted in hours. The useful question is not « is my provider compliant », which means nothing, but « what does it send me, to whom, how fast, and what is written down ». Ask the eight questions before signing: they cost an email, and they decide whether you can meet your own obligations.
Data centre service providers and internet exchange points appear in the highly critical sectors of Annex I. Whether a given provider is actually in scope then depends on size and on national transposition. The right move is to ask in writing rather than assume.
An early warning within 24 hours of becoming aware, a substantive notification within 72 hours, an intermediate report on request, then a final report within one month of the notification. The clock starts at awareness, not at resolution.
Article 34 sets minimum maximums that Member States must provide: up to 10 million euros or 2 % of total worldwide annual turnover for an essential entity, whichever is higher; up to 7 million or 1.4 % for an important one.
No. A certification is one useful piece of evidence among others, and it covers only the scope for which it was issued. Always check it names the SITE you rent, not the group, and that it is in date.
That is information in itself. Without a written deadline your 24 hours are not workable and you carry the risk alone. The subject is negotiated at renewal, where your position is strongest.
Written on 6 September 2026.
Estimate my cost → Compare data centers