

Service Overview
Are your digital services reaching users in the EU or the UK from outside their borders?
Europe's cybersecurity rulebook has moved from voluntary standards to binding obligations — with statutory representation at the centre. If your organisation provides in-scope digital infrastructure or online services to users in the EU or the UK and is not established in either jurisdiction, you may be required to designate a local representative under the EU NIS2 Directive, the UK NIS Regulations, or — once enacted — the UK Cyber Security and Resilience Bill.
Cybersecurity authorities work to short timelines, expect to reach a named and accountable counterparty, and treat the representative as the operational interface for incident notifications, registration formalities and supervisory cooperation. We have built our service to meet that expectation.
Service Detail
What this service covers
What sets our service apart
Real establishments in Ireland and the UK
NIS2 mandates are held through our Dublin entity; UK NIS mandates through our Hampshire-based entity. Cybersecurity authorities deal with named representatives — not anonymous inboxes.
Built for the incident-notification cadence
NIS2 imposes a 24-hour early warning, a 72-hour incident notification, and a one-month final report. Our escalation procedures are calibrated to those clocks. UK NIS timelines are handled in parallel.
One relationship across overlapping mandates
Cloud, DNS, CDN, managed ICT and online platform providers often hold parallel obligations under GDPR, DSA and AI Act. Lionheart consolidates these under a coordinated escalation path — which matters most during a significant incident.
Frameworks we cover
Framework status and legal basis
EU NIS2 Representative
Operative: Article 26, NIS2 Directive (EU) 2022/2555. For non-EU providers of cloud computing, DNS, TLD registries, data centres, CDNs, managed ICT, online marketplaces, search engines and social networking services offering services in the Union.
UK NIS Representative
Operative: Regulation 14A, UK NIS Regulations 2018. For non-UK Relevant Digital Service Providers — online search engines, online marketplaces and cloud computing services — offering services to users in the United Kingdom.
UK CSR Representative
In preparation: UK Cyber Security and Resilience Bill (Royal Assent anticipated late 2026). Service offering will be finalised once scope, registration and notification mechanics are confirmed. Register your interest now.
Notes and next steps
- NIS2 exemptions: micro and small enterprises are generally outside scope, with limited exceptions — including certain DNS, TLD and managed ICT providers. Whether your organisation is in scope is worth taking advice on; Lionheart can provide a preliminary assessment.
Explore the Cyber Resilience services in detail:
Related Services
Services in this area

EU NIS2 Representative (Article 26)
The NIS2 Directive — Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union — entered into force on 16 January 2023, with...

UK Cyber Security and Resilience Representative
The UK Cyber Security and Resilience Bill is currently progressing through Parliament. It is expected to broaden the existing UK cybersecurity framework —...

UK NIS Representative (Regulation 14A)
Lionheart Squared Limited · Fordingbridge, Hampshire, England The Network and Information Systems Regulations 2018 (SI 2018/506) — in force since 10 May 2018 —...
Get started
Not sure if you are in scope?
Use the guided self-check tool to map which representative obligations may apply.
