Service Overview

Are you providing online search, marketplace or cloud computing services to users in the United Kingdom from outside the UK?

The Network and Information Systems Regulations 2018 (SI 2018/506) — in force since 10 May 2018 — impose cybersecurity obligations on Relevant Digital Service Providers, alongside Operators of Essential Services in defined sectors including energy, transport, health, water and digital infrastructure. Regulation 14A requires Relevant Digital Service Providers — providers of online search engines, online marketplaces and cloud computing services — that have their head office outside the United Kingdom but offer digital services within the UK to nominate, in writing, a representative established in the UK.

Lionheart provides Regulation 14A representation through Lionheart Squared Limited, our England-and-Wales registered entity.

Service Detail

What this service covers

Our focus

Genuine UK establishment, not a post-Brexit address of convenience

Lionheart Squared Limited has been operating in England since 2017. Our UK presence predates the most recent expansion of UK digital and cybersecurity rules and is supported by an established UK team handling GDPR, NIS and product safety mandates day-to-day. You are appointing a firm with a real UK compliance footprint.

A 3-month registration window — and a template to make it manageable

You must notify the Information Commission of the name and contact details of your appointed representative no later than three months from first making your product or service available on the UK market. The notification must be on your own corporate stationery, signed by a person with sufficient authority. Lionheart provides a template registration letter (the same template used in the master representative services agreement) that captures every required field, leaving only the customer-specific particulars to complete. Final responsibility for the registration content rests with you, but the template eliminates the most common drafting friction.

Built around the duties Regulation 14A actually imposes

As your representative, we accept that we may be addressed in addition to or instead of you by the competent authorities for the purposes of ensuring compliance with the UK NIS Regulations. Our duties under the mandate are: promptly inform you of correspondence received from competent authorities, cooperate with those authorities — including by providing copies of the mandate, the underlying agreement and related materials concerning your compliance — and permit you to disclose our appointment and approved contact details for publication.

Aligned with the UK competent-authority structure

For Relevant Digital Service Providers, the Information Commission is the designated competent authority under the UK NIS Regulations. The Government Communications Headquarters (GCHQ), through the National Cyber Security Centre, performs the technical cybersecurity-authority function. Lionheart acts as the formal contact point between your organisation and these authorities, with all logging, escalation and forwarding handled through documented procedures.

Our services include

Formal designation

Acting as your UK NIS representative under Regulation 14A of the UK NIS Regulations 2018, by written mandate, with clearly documented scope and procedures.

UK-based contact details

A dedicated representative email address and Lionheart's Hampshire postal address, available for inclusion in your public-facing materials and registration disclosures.

Authority liaison

Acting as the formal contact point for the Information Commission (the designated competent authority for Relevant Digital Service Providers) and for the National Cyber Security Centre / GCHQ on the technical cybersecurity side.

Registration support

Provision of a template Regulation 14A representative-appointment notification ready to be transposed onto your corporate stationery, and practical support with the 3-month registration window.

Authority correspondence handling

Prompt receipt, logging and forwarding of regulatory correspondence; provision of mandate and agreement copies to competent authorities on request, in cooperation with you.

Incident-notification escalation

Defined escalation paths and service levels aligned with UK NIS notification timelines for significant incidents, supporting the responsibility you retain for filing those notifications.

Coordinated mandates

Single-relationship handling where UK NIS obligations sit alongside other Lionheart representative services — UK GDPR, EU NIS2, EU GDPR, DSA or AI Act — under one engagement and one escalation path.

Legal basis: Regulation 14A, The Network and Information Systems Regulations 2018 (SI 2018/506).

Scope reminder:

Regulation 14A applies to Relevant Digital Service Providers — providers of online search engines, online marketplaces and cloud computing services — that have their head office outside the United Kingdom. Operators of Essential Services in regulated sectors (energy, transport, health, water, digital infrastructure) are subject to a separate framework under the same Regulations and are typically established locally; the Regulation 14A representative obligation is not the relevant compliance pathway for those entities.

Size-based exemption:

Small and micro enterprises, as defined under the UK NIS framework, are not required to appoint a Regulation 14A representative.

Get started

Not sure if you are in scope?

Use the guided self-check tool to map which representative obligations may apply.