NIS2 for Cloud Providers and SaaS: The "Cloud Computing" Sector

Practitioner note: This is not legal advice. For specific situations, consult a qualified attorney or compliance officer.

TL;DR

  • Annex I, "digital infrastructure" classifies cloud computing providers as essential entities
  • Threshold: 50+ employees and EUR 10M turnover; smaller providers can still qualify if "critical"
  • Pure SaaS is not always cloud computing under NIS2; IaaS and PaaS clearly are
  • Heightened duties: stricter SLAs, EU data boundary, supply-chain liability for sub-providers
  • Recommended standards: ISO 27017, ISO 27018, BSI C5, CSA STAR

1. Sector classification

NIS2 Annex I classifies cloud computing services as an essential entity sector. The default thresholds are 50+ employees and at least EUR 10M turnover. Providers below the size threshold can still be brought into scope when they are designated "critical" (e.g., CDN services for public administration).

2. Is your SaaS a cloud provider?

Not all SaaS qualifies as cloud computing under NIS2. The definition (Annex I) refers to "scalable, elastic IT resources." Pure SaaS is often outside scope; IaaS and PaaS are clearly inside. A pure email-marketing SaaS rarely qualifies; a PaaS that allocates compute on demand always does.

3. Heightened duties

4. Sub-providers and supply chain

The cloud provider remains accountable for sub-providers. Section 30 BSIG supply-chain clauses apply strictly: due diligence, contractual security commitments, audit rights, and exit plans must be documented per sub-provider.

5. Customer notification on incidents

On a significant incident, the provider must notify customers (typically within 24 hours), so that customers can fulfill their own NIS2 and GDPR Art. 33 obligations downstream.

6. Recommended standards

Summary

Cloud and IaaS/PaaS providers operating in Germany sit in the highest NIS2 tier. Implementing ISO 27017 + BSI C5 typically covers the bulk of obligations and provides defensible evidence for customer audits.

View NIS2 Kit →

Frequently Asked Questions

Hyperscalers vs. mid-market cloud?
AWS/Azure/GCP often have global compliance programs. EU mid-market clouds (Stack-IT, IONOS) are DACH-focused.
CSA STAR or ISO 27017?
Both are good. CSA STAR is more affordable, ISO 27017 is more widely recognized.

Sources

Tools & self-assessments

NIS2 Readiness Check Assess your NIS2 readiness in 10 minutes. Fining Calculator Estimate the potential fine exposure for your organisation. NIS2 Self-Test Am I in scope? Check thresholds and sector criteria. NIS2 Mandatory Measures Audit 10 mandatory measures from Section 30 BSIG with maturity rating.