Does NIS2 Apply to a US SaaS Selling Into the EU?
Most US SaaS firms are not directly regulated by NIS2 - but EU buyers still ask. Here is how Article 21 supply-chain duty pulls you in, and what evidence unblocks reviews.
An EU enterprise prospect drops NIS2 into a security questionnaire. You are US-headquartered, have no Brussels office, and already hold SOC 2. The first reply that comes to mind - we are American; NIS2 does not apply - feels accurate. It also stalls the deal.
This post is for US (and other non-EU) SaaS founders, Heads of Sales or RevOps, and lone compliance owners selling into EU enterprises who suddenly see NIS2 language in questionnaires and contract addendums. The goal is to separate direct regulation from supply-chain pressure, then give you a practical evidence pack that unblocks procurement without inventing a NIS2 certificate you do not need.
The direct answer
Most US SaaS companies with no EU establishment are not directly regulated by NIS2. The directive regulates entities that provide covered services within the EU and meet its sector and size tests. If you have no establishment there and are not designated as a covered digital-infrastructure provider under the representative rules, NIS2 most likely does not name your company as a regulated entity.
That is the comforting half. The half that matters for revenue is different.
Covered EU customers must manage supplier cybersecurity under Article 21. Your European enterprise buyer is discharging their duty when they ask about your controls. In practice, a non-EU SaaS feels NIS2 as:
- A security questionnaire asking about NIS2 alignment or supplier cybersecurity
- A procurement request for attestation and live posture evidence
- A contract clause that obliges you to maintain and demonstrate certain controls
None of that depends on you becoming a regulated EU entity. It depends on your customer being regulated and wanting to keep buying from you. SaaSFort July 2026 framing of this pattern matches what we see in reviews: the directive does not send you a letter; it sends your customer a duty, and your customer passes that duty to you as a purchasing condition.
Three pathways: which one are you on?
Guidance that says if you sell into the EU, you are in scope oversimplifies. A clearer frame - reflected in the nis-2-templates.com non-EU companies guide (July 15, 2026) - is three pathways:
Pathway A - EU subsidiary that meets sector and size tests
If you have a legally established EU branch or subsidiary, that entity is evaluated like a domestic EU company. Article 2 scope plus Annex I/II sector and size caps (medium enterprise thresholds and above, with some entity types in scope regardless of size) can put that subsidiary in as an important or essential entity. Parent HQ location does not erase that test. Liability under Article 20 attaches to the management bodies of the in-scope entity - typically the subsidiary board or equivalent - though reputational and contractual fallout for the parent is a separate, real commercial exposure.
Pathway B - Narrow digital-infrastructure list with Article 26 representative duty
This is the genuinely extraterritorial route, and it is narrow. Article 26 reaches a specific list of digital-infrastructure provider types that offer services into the EU without an EU establishment - including DNS providers, TLD registries, domain registration services, cloud computing providers, data centre providers, CDNs, managed service providers, managed security service providers, and providers of online marketplaces, search engines, or social networking platforms (as summarized in the July 2026 non-EU companies guide). Those providers must designate an EU representative; without one, any member state where they provide services may take action.
Most Workstreet-shaped B2B SaaS products are not automatically Pathway B just because they sell software into Europe. If you do not recognize your business in that list, do not build a representative program on a false assumption - and do not ignore Pathway C.
Pathway C - Indirect supply-chain / contractual pressure
This is where most US SaaS companies live. Your EU customer is an essential or important entity. Article 21(2)(d) and national implementing rules push cybersecurity expectations into supplier questionnaires and contracts. IT Pro (published 24 September 2026) puts the same point in channel language: when your customer falls under NIS2, part of that compliance burden lands on suppliers through procurement, not through a direct regulator letter to you.
Pathway C is not you are a regulated NIS2 entity. It is you must answer as a supplier so the buyer can document their supply-chain duty.
Why we are US-based / NIS2 does not apply is a bad questionnaire answer
From the reviewer seat, that reply reads as either a misunderstanding of their Article 21 duty or an unwillingness to cooperate. Either way, the review stalls.
The reviewer is not asking you to become a regulated EU entity. They are asking you to show that your security posture meets the bar they are obliged to check. Jurisdiction theater does not close that request. Evidence does.
If you need a parallel story from EU financial ICT rules, see Workstreet DORA compliance post: same you are not in scope but the questionnaire arrived anyway shape, different law and buyer set.
What reviewers actually want
Strip the NIS2 branding and EU buyers usually want the same evidence pack a serious domestic enterprise would, framed against supply-chain language:
1. Current attestation - SOC 2 Type 2 or ISO 27001 where you have them. SOC 2 is widely accepted in the EU as supporting evidence. It is not a NIS2 certificate and does not replace live posture or data-handling answers (SaaSFort, July 2026).
2. Clear data-handling and residency answers - where EU customer data lives, who accesses it, how it is encrypted, and how transfers are handled. These often sit next to the NIS2 questions even when they are GDPR or commercial requirements rather than NIS2 itself.
3. Incident and BCP language - how you detect, escalate, notify, and recover; what customers can expect on timing and cooperation.
4. Live external-posture evidence - TLS, security headers, exposed admin surfaces, email authentication, and similar checks that a snapshot attestation does not show. SaaSFort notes this third item as the one that trips vendors because it is about the live state of your domain, not a policy PDF.
For packaging questionnaire answers at scale, see SOC 2 vs security questionnaires and SIG questionnaire. A Trust Center that makes attestation and policies easy to share still helps; see building trust with a company trust page.
NIS2 vs DORA (short contrast)
| NIS2 | DORA | |
|---|---|---|
| Focus | Broader essential / important entities + supply-chain cybersecurity | EU financial ICT resilience |
| Typical buyer | Hospitals, energy, manufacturing, government, large enterprises across Annex sectors | Banks, insurers, investment firms, and other financial entities |
| How US SaaS feels it | Article 21 supplier questionnaires and contract clauses (Pathway C for most) | ICT third-party risk questionnaires and contractual ICT clauses |
| Sibling reading | This post | DORA compliance |
Same procurement pattern, different statute. Do not answer a NIS2 question with a DORA narrative, or the reverse. For another EU extraterritorial / questionnaire pattern in the AI space, see EU AI Act compliance.
National enforcement: date-stamp what is live
NIS2 is a directive. It takes effect in each country when written into national law, and member states have moved at different speeds.
As of sources fetched for this draft:
- Germany - NIS2 Implementation Act binding since 6 December 2025, with registration expectations shortly after (IT Pro, 24 September 2026; nis-2-templates.com mid-2026 snapshot citing DLA Piper reporting on BSI registration).
- Greece - in force since November 2024 (IT Pro, 24 September 2026).
- France - folded into a broader resilience law; timing still evolving in public channel reporting (IT Pro, 24 September 2026).
- Ireland - national legislation and registration portals have lagged relative to the October 2024 transposition deadline in Commission tracking summarized by nis-2-templates.com (mid-2026); NCSC Ireland has published FAQ-style guidance while the statute catches up.
Treat these as snapshots from named sources, not a permanent enforcement map. If you are on Pathway A or B, sequence registration and audit-readiness around countries where the law is already live. If you are on Pathway C, watch which of your buyers member states are enforcing first - that is often where questionnaires harden first.
Penalty ranges in the Directive apply to directly in-scope essential and important entities (for example, essential-entity maxima described in Directive Article 34 materials as at least EUR 10 million or 2% of worldwide annual turnover, whichever is higher; important-entity maxima at least EUR 7 million or 1.4%, as summarized in the July 2026 non-EU companies guide). Those figures are about regulated entities, not a fine ticket automatically issued to a US SaaS on Pathway C. Do not invent reader-specific fine exposure.
A practical answer pack for Pathway C deals
When the questionnaire arrives, aim for a one-sitting reply kit:
1. Scope statement in plain language - We are not an EU-established NIS2 essential/important entity. We support your Article 21 supplier diligence with the evidence below.
2. Attestation package - current SOC 2 / ISO report, pen-test summary if you share one, and subprocessor list.
3. Data map answers - regions, encryption, access, retention, and transfer mechanism.
4. Incident / BCP excerpt - customer-facing notification expectations and contacts.
5. Live posture artifact - dated external scan or equivalent evidence of the current domain state.
6. Contract-ready control language - what you can commit to without overclaiming a NIS2 certification.
Hand that pack early. Reviewers move faster when you answer the duty they actually have.
Soft next step
If NIS2 (or DORA, or EU AI Act) language is showing up in late-stage deals and your team is answering from scratch each time, Workstreet can help package questionnaire responses, keep a Trust Center-ready evidence set current, and support managed compliance or vCISO ownership as EU deals scale - including security questionnaire automation. That is packaging and program help, not a claim that Workstreet issues a NIS2 certificate or that every US SaaS is a regulated entity.

