Cyber Resilience
NIS 2 representative under Article 26. Unlimited incident filings. We never charge you during your worst 72 hours.
$0
at 1 entities in scope · 1 included
Incident notifications in the format each authority wants, on the deadlines NIS 2 sets, and a named Article 26 representative registered with ENISA. For digital providers serving the EU from outside it.
Early warning in 24 hours, notification in 72, final report in a month. The deadlines are started by the incident, not by whoever remembers, and the drafts are waiting when you get there.
Which CSIRT and which competent authority, in which member states, for an incident with this footprint — decided from your registration rather than searched for at three in the morning.
A named Article 26 representative, registered with ENISA under Article 27. The part of this you cannot do yourself from outside the EU.
Detection time, not reporting time, is what the deadlines run from — so the first thing recorded is when you knew, and every deadline is derived from that.
Within 24 hours: whether it is suspected to be unlawful or malicious, and whether it could have cross-border impact. Short on purpose, because at that point nobody knows much.
Within 72 hours: severity, impact, indicators of compromise, and an update on the early warning. Drafted against what you have logged rather than from a blank page.
Within a month: the description, the type of threat, the mitigations applied, and the cross-border effect. Filed to every authority that was told about the incident in the first place.
// Incident · NIS 2 Art. 23 Detected 14 Feb 02:11 CET Early 14 Feb 02:41 (+30 min) Notified 15 Feb 18:20 (+40 h) Final 09 Mar (+23 d) Authorities 3 engaged HR CSIRT · lead DE BSI · cross-border IE NCSC · cross-border Users ~14,200 affected Status Closed · no enforcement
The ten measures Article 21(2) names — policies, incident handling, business continuity, supply-chain security, disclosure, cryptography and the rest — held as a framework you can show rather than assert.
The governing body approves the measures and can be held personally liable for failing to. That approval, and the training behind it, is recorded.
The register of the suppliers and service providers whose security is now part of yours, with the assessment behind each relationship.
Your entity registered in the member state where the representative sits, and the ENISA registry entry that digital providers specifically must keep current.
DNS providers, cloud and data-centre services, CDNs, managed service providers and online marketplaces that offer services in the Union without being established there must designate a representative in one of the member states where they operate. We become yours, and we register you where Article 27 requires.
Incident filings are never metered. We will not charge you by the notification during the week you can least afford it.
Learn more about the Article 26 mandate →NIS 2 representative under Article 26. Unlimited incident filings. We never charge you during your worst 72 hours.
$0
at 1 entities in scope · 1 included
In the fee
This is on top of your platform plan, which starts at $0. See every price →
An incident involving personal data is also a 72-hour GDPR notification. Same clock, different authority.
If users post or trade on your service — the Article 13 representative and the notice endpoint.
The public side: your security contact and the vulnerability disclosure policy Article 21 expects.
The representative is part of it. Cyber Resilience is the product: the incident clocks, the notifications, the risk-management framework and the Article 26 mandate together. If all you need is the mandate itself, that is the piece described on the NIS 2 Representative page — but it is bought as Cyber Resilience either way.
NIS 2 catches more than people expect: cloud computing, data centres, CDNs, DNS, managed services, online marketplaces, search engines and social platforms are all named, and the thresholds are lower than the old directive's. If you sell any of those into the EU without an entity there, assume yes and check.
We file, from what you give us, against the deadline. You keep the facts and the decisions; what you do not keep is the question of which authority, in which format, in which language, by when.
One legal entity in scope. One is included; each additional entity is priced on top. Incident filings are never counted, however many there are.
The mandate ends on 30 days' notice, and the authority and the ENISA registry are updated. Until it does you stay covered: a designated representative that quietly lapses leaves you in breach.
Thirty minutes to work out which authorities you answer to and what your 24 hours would look like. A named representative on record the moment you sign.