Get Demo
↑

Does NIS2 Apply to Non-EU Companies? (UK, US, GCC, Pakistan Vendors)

Non-EU companies can face NIS2 duties through EU establishments, in-scope services, customer flow-down.

Published: September 2026 Compliance · NIS2 8–12 min read

Headquarters outside the EU does not create a free pass. Directive (EU) 2022/2555 obligations attach through EU entities, services offered into covered sectors, and contractual flow-down from essential/important customers.

Related: NIS2 hub · Scope · Transposition tracker.

Practical triggers: EU subsidiary or branch in a covered sector; providing MSP/cloud/digital services that land you on national lists; or enterprise customers requiring Article 21(2)(d) supplier assurances.

Regional Notes (editorial)

What Non-EU Vendors Should Do

  1. Inventory EU legal entities and customer sectors
  2. Map services to Annex I/II themes
  3. Stand up Article 21-aligned controls and 24/72/one-month incident playbooks for EU impact
  4. Confirm national law wherever you have establishment or designation risk

How CyberSilo Helps

Align Exporter Controls to EU Customer NIS2 Duties

CSA and ThreatHawk help non-EU teams produce evidence EU buyers recognise.

Frequently Asked Questions

If we only sell into the EU with no office, are we safe?

Not necessarily — digital/ICT service themes and customer flow-down can still create obligations or commercial mandates. Assess facts and confirm national law.

Does GDPR Article 3 logic apply one-for-one?

No. NIS2 uses sector/entity classification and national transposition, not GDPR’s Article 3 territorial test.

What do procurement teams usually ask?

Article 21 control summaries, MFA/crypto posture, supplier risk process, and incident notification SLAs.

NIS2 hub · Supply chain · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!