NIS2 Directive: What Indian Vendors of EU Companies Must Do

NIS2 Directive: What Indian Vendors Of EU Companies Must Do

The NIS2 Directive never mentions you by name. It binds your European client, and the client pushes the obligation down the contract, which is why most Indian vendors meet Directive (EU) 2022/2555 for the first time as a security annexe attached to a renewal rather than as a law they’ve got to register under. Certain Indian vendors can be caught directly where they fall within the NIS2 scope, including managed service providers and managed security service providers that qualify under the Directive and offer services in the Union. Where Article 26(3) applies, a provider not established in the Union must designate a representative in the Union. Everything else landing in your inbox, the questionnaire, the audit right, the notification clause written in hours, is Article 21 and Article 23 reaching you through somebody’s procurement team.

This article sets out what the NIS2 Directive requires from Indian vendors serving EU companies.

Check the timing before you argue about the clauses. Member States had until 17 October 2024 to write the directive into national law, most did, and on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for still not notifying full transposition. So the clause set can reach you before your client’s own national rules are settled, which is exactly when procurement drafts at its most defensive.

And the contract route doesn’t care how small you are. A four-person development shop signs the same annexe as a four-hundred-person one.



When the NIS2 Directive applies to you directly

The NIS2 Directive reaches you directly only if you’re one of its listed entity types providing services inside the Union. For most Indian vendors that test fails, which leaves the contract as the route the obligation actually takes. Work through it anyway, because the exception is wider than it looks.

Start with Article 2(1). The directive applies to entities of a type listed in Annex I or Annex II that qualify as medium-sized enterprises or exceed those ceilings, and that provide their services or carry out their activities within the Union. The size test comes from Recommendation 2003/361/EC, and the practical reality is simpler than the drafting: under the Commission’s SME definition, you stop being a small enterprise once you employ 50 people, or once turnover and balance sheet total both pass EUR 10 million.

Below that, you’re usually outside the directive’s own scope and fully inside your client’s contract.

Now check the entity types, because Annex I carries a category built for firms like yours. Sector 9 is ICT service management on a business-to-business basis, and it names managed service providers and managed security service providers. Article 6(39) defines a managed service provider as “an entity that provides services related to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or any other network and information systems, via assistance or active administration carried out either on customers’ premises or remotely”.

Read that last word again. Remote administration from Pune or Hyderabad sits inside the definition, not outside it.

So what do you owe if you land in that category? Article 26(3) is the operative provision: an entity of that type that isn’t established in the Union but offers services within it has to designate a representative in the Union, in one of the Member States where the services are offered. Jurisdiction then follows the representative. Skip the step and you lose your shelter, because absent a designated representative, any Member State in which you provide services may take legal action against you for infringement.

There’s a registration duty attached as well (easy to miss, since it sits in a different chapter). Article 27(2) required entities in this group to give competent authorities their name, entity type, the representative’s address, contact details, the Member States served and their IP ranges by 17 January 2025.

One more label to sort out, because your client will use it in the paperwork. Annex I entities above the medium-sized ceilings are essential entities under Article 3(1)(a), and everything else of a listed type is an important entity under Article 3(2). The two carry different supervisory regimes and different maximum fines, and that classification drives how hard your client pushes on you.

Do this before the next renewal call. Write a two-line scope statement and keep it at the top of your security annexe, something like: We are not an Annex I or Annex II entity under Directive (EU) 2022/2555 and hold no NIS2 registration. We accept the obligations in this annexe as contractual commitments supporting Customer’s compliance under Article 21(2)(d). If you do fall inside Annex I sector 9, the second line changes to name your EU representative and the Member State supervising you.

Getting that on paper early kills two failures worth naming: signing obligations meant for a regulated entity, and denying a status you actually hold. And the discipline being run on you here has a name of its own, worth understanding from the other side of the table if you’re the one answering third-party risk assessments every quarter.

What the NIS2 Directive puts in your contract

The NIS2 Directive reaches your contract through Article 21(2)(d), which requires essential and important entities to take measures covering supply chain security, “including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”. Article 21(3) then tells your client to take into account the vulnerabilities specific to each direct supplier and the overall quality of their cybersecurity practices, including their secure development procedures. You’re the direct supplier in that sentence.

Advertisement

The eight contract clauses

Stop guessing at what your client will ask for. For digital-sector entities it’s written down: point 5.1.4 of the Annex to Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 lists what their contracts with suppliers have to specify, where appropriate:

  • cybersecurity requirements for you, including requirements on the secure acquisition of ICT services and products
  • awareness, skills and training requirements for your employees, and certifications where appropriate
  • verification of the background of your employees
  • an obligation on you to notify your client, without undue delay, of incidents that present a risk to their network and information systems
  • the right to audit you, or to receive your audit reports
  • an obligation on you to handle vulnerabilities that present a risk to their systems
  • requirements on subcontracting, and cybersecurity requirements for your subcontractors where subcontracting is allowed
  • your obligations when the contract ends, such as retrieval and disposal of the information you held

Recognise the questionnaire in that list? Point 5.1.2 explains why it exists. Before contracting, your client has to apply selection criteria covering your cybersecurity practices and secure development procedures, your ability to meet the specifications they set, the overall quality and resilience of what you supply, and their own ability to diversify sources and limit vendor lock-in. But that last criterion isn’t about you at all (worth remembering when a scoring sheet comes back oddly).

Concede most of the eight early and negotiate the two that carry real cost. Audit rights come first, and since the regulation gives your client the right to audit you or to receive your audit reports, offer the report and cap the on-site alternative. Here’s what that actually looks like: Supplier will provide its current ISO/IEC 27001 certificate and Statement of Applicability, and its most recent independent audit report, within ten business days of request. Customer may conduct one on-site audit per contract year on thirty days’ notice, and further audits following a significant incident affecting Customer data.

Subcontracting is the second, and the flow-down is what catches Indian firms: Supplier will not subcontract any part of the Services without prior written approval, and will impose on each approved subcontractor security obligations no less protective than those in this annexe. Sign that with three freelance developers already on the work and you’ve created a breach on day one. The mistake we see most often isn’t refusing the clause. It’s signing it and never mentioning the people already inside the delivery.

Incident notification timelines

Your notification clause exists because your client is running a clock they can’t pause. Article 23(4) gives them an early warning to their national CSIRT within 24 hours of becoming aware of a significant incident, a fuller notification with an initial severity and impact assessment within 72 hours, an intermediate report on request, and a final report no later than one month after that notification.

And whatever hours they have, you get a fraction of them.

Know what counts as significant, because that’s the trigger sitting behind your clause. Article 3(1) of the implementing regulation treats an incident as significant where it causes or could cause direct financial loss above EUR 500 000 or 5 per cent of annual turnover, whichever is lower, the exfiltration of trade secrets, death or considerable damage to a person’s health, or where a successful and suspectedly malicious unauthorised access occurs that’s capable of causing severe operational disruption. Article 10 adds thresholds built specifically for managed service and managed security service providers: complete unavailability for more than 30 minutes, limited availability for more than an hour affecting 5 per cent of Union users or a million users (whichever number is smaller), and any compromise of integrity, confidentiality or authenticity caused by suspectedly malicious action.

Write your notification duty in hours, never in business days. A clause that works on both sides reads roughly: Supplier will notify Customer’s security contact within four hours of becoming aware of any incident affecting Customer data or systems, using the agreed contact address, with the information available at that time. Supplier will provide an updated assessment within twenty-four hours and will not delay the initial notification pending confirmation of scope.

Fight for that last phrase. This is where most vendors go wrong: they wait for certainty, the client misses its 24-hour early warning, and the relationship doesn’t recover. Behind the clause you need a real procedure, so if you’ve never built one, start from a data breach response plan and set its trigger to your contractual hours rather than the regulator’s.

How a NIS2 duty reaches an Indian vendor

Directive (EU) 2022/2555
1 Your EU
client
The directive binds the client, not you
Article 2(1), Annex I or II, medium size and above
Scope starts at 50 employees, or where turnover and balance sheet total both pass EUR 10 million. For infringements covered by Article 34, essential entities may face administrative fines of at least EUR 10 million or 2 per cent of total worldwide annual turnover in the preceding financial year, whichever is higher; important entities may face at least EUR 7 million or 1.4 per cent of total worldwide annual turnover, whichever is higher. Article 20 makes the management body approve the measures and capable of being held liable.
Directive (EU) 2022/2555, Articles 2, 3, 20 and 34
2 Your
contract
Eight things the contract has to specify
Article 21(2)(d), supply chain security
acybersecurity requirements
btraining and certifications
cemployee background checks
dincident notice without undue delay
eright to audit or receive audit reports
fvulnerability handling
gsubcontractor flow-down
hreturn and disposal at termination
Implementing Regulation (EU) 2024/2690, Annex point 5.1.4
3 Your
clock
Three deadlines, one detection process
Build to the tightest of the three
6 hours
Your CERT-In report, from noticing the incident
24 hours
Client’s early warning to its national CSIRT
72 hours
Client’s fuller notification with an impact assessment
Directive Article 23(4); CERT-In Cyber Security Directions, 28 April 2022, direction (ii)
The one case where NIS2 reaches you directly Managed service providers and managed security service providers that are not established in the Union but offer services in it have to designate a representative in the Union. Without one, any Member State where the services are provided may take legal action for infringement. Article 26(3).
SkillArbitrage

Evidence and controls to prepare before the audit

Prepare your evidence against a standard your client already recognises and the questionnaire stops being a research project. Recital 25 of the implementing regulation says its technical and methodological requirements are based on European and international standards “such as ISO/IEC 27001, ISO/IEC 27002 and ETSI EN 319401”, and technical specifications such as CEN/TS 18026:2024. So an ISO 27001 information security management system isn’t a lucky match for what your client wants. It’s the frame the rules were drawn on.

Use the free guidance rather than paying someone to summarise it for you. ENISA published its NIS2 Technical Implementation Guidance on 26 June 2025, covering the digital infrastructure, ICT service management and digital provider sectors, and it does three things worth an afternoon of your time: it explains the concepts in the legal text, it gives examples of the evidence that shows a requirement has been met, and it maps each requirement to European and international standards and national frameworks.

Build your evidence index from those examples, one line per control, naming the artefact and where it lives. Something as plain as: 5.1.4(d) supplier incident notification: clause 9.2 of the MSA, four-hour trigger, tested in the tabletop exercise of 12 August 2026, ticket INC-2026-0031. An index like that answers in one page what a questionnaire otherwise drags out of you over three weeks (and this is the part most vendor checklists skip). Keep your GDPR record of processing activities filed next to it, since the same questionnaire almost always asks for both.

Resolve your two reporting clocks now, before an incident makes you choose under pressure. India’s CERT-In directions of 28 April 2022 require any service provider, intermediary, data centre, body corporate or government organisation to “mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents”. Your EU client needs its early warning inside 24. A smarter strategy is to build one detection and escalation process to the six-hour standard, so both duties come out of the same run of the same procedure.

Understand why your client negotiates this hard, because it isn’t personal. Article 34(4) sets maximum administrative fines for essential entities at least EUR 10 million or 2 per cent of total worldwide annual turnover, whichever is higher, and Article 34(5) sets EUR 7 million or 1.4 per cent for important entities. But the sharper provision is Article 20, which makes management bodies approve the risk-management measures, oversee implementation, and be capable of being held liable for infringements. The person across the table from you is personally exposed to your controls, which explains the tone.

Two things to keep on a calendar. Transposition is still moving, so a clause set drafted in Germany and one drafted in Ireland can differ on detail while the Commission tracks national implementation. And on 20 January 2026 the Commission proposed targeted amendments to the NIS2 Directive as part of a cybersecurity package, aimed at clarifying scope and definitions and simplifying jurisdictional rules (a proposal, not law, so don’t rewrite anything on the strength of it yet).

So what does this mean for you commercially? A decent position, if you move first. EU buyers already read SOC 2 reports from Indian service providers, and a vendor who can produce a certificate, a mapped evidence index and a tested four-hour notification path wins renewals against one who can’t. Whether you build the audit skill in-house through an ISO 27001 lead auditor track or buy it in is a budget question; having it isn’t.

Frequently asked questions

Does the NIS2 Directive apply to a small Indian software company with one EU client?

Article 2(1) generally limits the directive to Annex I and Annex II entity types that are at least medium-sized and provide services or carry out activities in the Union. A small Indian firm therefore generally sits outside the Directive’s scope unless a specific NIS2 provision brings it within scope. The obligations still reach you through your client’s contract under Article 21(2)(d).

Do you need to appoint an EU representative?

Article 26(3) requires one from managed service and managed security service providers, cloud, data centre and CDN providers, DNS and TLD operators, marketplaces and search engines that offer services in the Union without being established there. Without one, any Member State served may sue you.

Is ISO 27001 certification enough for an EU client’s NIS2 clauses?

Recital 25 of Implementing Regulation (EU) 2024/2690 confirms the requirements are based on standards including ISO/IEC 27001 and 27002, so certification covers most of the ground. It won’t cover the contract duties, particularly the notification timing and the subcontractor flow-down.

Can an Indian vendor be fined directly under the NIS2 Directive?

The fines in Article 34 apply to essential and important entities, so a vendor outside those categories faces contractual liability rather than a regulatory penalty. An Indian entity inside Annex I that skips the Article 26(3) representative can face legal action in any Member State it serves.

References

Official guidance and regulations

  1. Directive (EU) 2022/2555 (NIS2 Directive). Official Journal of the European Union, 14 December 2022
  2. Commission Implementing Regulation (EU) 2024/2690. European Commission, 17 October 2024
  3. NIS2 Directive: securing network and information systems. European Commission
  4. NIS2 Directive transposition in EU countries. European Commission
  5. Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice. European Commission, 8 July 2026
  6. SME definition (Recommendation 2003/361/EC). European Commission
  7. Cyber Security Directions under section 70B(6) of the Information Technology Act, 2000. CERT-In, 28 April 2022

Guidance and standards

  1. NIS2 Technical Implementation Guidance. ENISA, 26 June 2025
  2. ISO/IEC 27001, Information security management systems. International Organization for Standardization

This article is for informational and educational purposes only and does not constitute professional, legal or compliance advice. Obligations under the NIS2 Directive depend on national transposition and on the terms of your own contracts. Consult a qualified professional before acting on any compliance or contractual decision.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *