The NIS2 Directive came into force across EU member states between October 2024 and the first half of 2025. Most colocation buyers we now talk to know they are in scope. Almost none can answer the question we ask next: are you an essential entity, or an important entity?
The difference is not pedantic. It changes incident-reporting obligations, supervisory regime, fines, and — crucially for this audience — the kind of facility you can credibly host in.
This is a short read. The point is to be useful, not exhaustive.
The two categories, briefly
NIS2 splits in-scope organisations into two buckets, defined by sector + size. A simplified read:
- Essential entities — energy, transport, banking, financial-market infrastructure, healthcare, drinking water, wastewater, digital infrastructure (DNS, TLD registries, IXPs, datacenters), ICT service management, public administration, space.
- Important entities — postal and courier services, waste management, manufacture and distribution of chemicals, food, manufacturing of certain critical products, digital providers (online marketplaces, search engines, social networks), and most of the rest of the digital economy.
Size thresholds matter. Below specific employee and turnover floors, you are out. Above them, your sector decides which bucket you sit in.
If the answer is “I am not sure”, you are not unusual — and the right next move is a half-day scoping read against your sector classification, headcount, and revenue. Doing this before you go to market saves a procurement cycle.
Why it changes the shortlist
NIS2 imposes obligations on the entity you are. It also propagates through your supply chain, including your colocation provider.
Three practical consequences for a buyer in our network:
1. Incident-reporting timelines. Essential entities have stricter reporting obligations: an early warning within 24 hours, a more detailed notification within 72, and a final report inside one month. Your provider’s incident-response posture must support these timelines. Some smaller European operators do not. Filter for it before you take a meeting.
2. Concentration and supply-chain risk. NIS2 expects you to assess and manage risk from your direct and indirect ICT supply chain. A provider with one upstream substation, no carrier diversity, and a parent company in a third country is a higher-risk dependency. The legal team will want this written down. We do that work for you in the shortlist phase, not after the contract is signed.
3. Supervisory regime. Essential entities face proactive supervision (audits, on-site inspections, ad-hoc requests). Important entities face reactive supervision (post-incident or evidence-based). If you are essential, your provider will be asked questions you do not get to control. Choose facilities that have already lived through that — and have the documentation to prove it.
What we do with the answer in an RFQ
When a buyer flags NIS2 essential or important on our requirements wizard, we do three things differently:
- We exclude providers whose written incident-response and reporting playbooks do not match your timeline obligations. This typically removes one or two facilities from the European long-list.
- We require a written supply-chain attestation from each shortlisted provider, covering their upstream power, fiber, and managed-service dependencies. Some providers refuse. We tell you which ones and let you decide.
- We make sure the contract includes audit-cooperation, sub-contractor disclosure, and exit-assistance clauses that hold up if and when your supervisor calls. We are not a law firm, but we do not present a contract draft we know is going to be rejected by your legal team.
What we do not do
We do not interpret NIS2 for you. The directive is national-law in each member state, and the implementations differ in non-trivial ways. Where you need a formal scoping opinion — for the board, for the regulator, for an auditor — we point you at counsel. We have specific recommendations in NL, BE, DE, and FR.
We also do not certify providers under NIS2 ourselves. There is no provider certification under the directive. What there is, is provider posture — documented, attestable, and reviewed under contract. That is what we shortlist on.
If you are in scope and unsure
Most-common situation, and the cheapest one to resolve:
- Confirm scope with counsel. Sector + size, against the national transposition for your member state of incorporation.
- Bring the answer to us. Or, if you want, bring it to our requirements wizard — the questionnaire flags the same disqualifying combinations the law would.
- Submit an anonymized RFQ. We do the supply-chain review on the providers we put forward, before any introduction.
Most NIS2 procurement mistakes happen in step 1, where the organisation skips the scoping read and assumes its existing colocation provider is “fine because they were fine before”. Some are. Some are not. Cheaper to know.