NIS2 for Cloud Providers and SaaS: The "Cloud Computing" Sector
TL;DR
- Annex I, "digital infrastructure" classifies cloud computing providers as essential entities
- Threshold: 50+ employees and EUR 10M turnover; smaller providers can still qualify if "critical"
- Pure SaaS is not always cloud computing under NIS2; IaaS and PaaS clearly are
- Heightened duties: stricter SLAs, EU data boundary, supply-chain liability for sub-providers
- Recommended standards: ISO 27017, ISO 27018, BSI C5, CSA STAR
1. Sector classification
NIS2 Annex I classifies cloud computing services as an essential entity sector. The default thresholds are 50+ employees and at least EUR 10M turnover. Providers below the size threshold can still be brought into scope when they are designated "critical" (e.g., CDN services for public administration).
2. Is your SaaS a cloud provider?
Not all SaaS qualifies as cloud computing under NIS2. The definition (Annex I) refers to "scalable, elastic IT resources." Pure SaaS is often outside scope; IaaS and PaaS are clearly inside. A pure email-marketing SaaS rarely qualifies; a PaaS that allocates compute on demand always does.
3. Heightened duties
- Stricter service-level agreements with customers
- Higher availability and resilience standards
- Alignment with the ENISA Cloud Security benchmark
- EU data boundary considerations
4. Sub-providers and supply chain
The cloud provider remains accountable for sub-providers. Section 30 BSIG supply-chain clauses apply strictly: due diligence, contractual security commitments, audit rights, and exit plans must be documented per sub-provider.
5. Customer notification on incidents
On a significant incident, the provider must notify customers (typically within 24 hours), so that customers can fulfill their own NIS2 and GDPR Art. 33 obligations downstream.
6. Recommended standards
- ISO 27017 - cloud security controls
- ISO 27018 - cloud privacy / personal data
- BSI C5 - cloud-computing compliance criteria (German federal benchmark)
- CSA STAR - lighter-weight, vendor-friendly attestation
Summary
Cloud and IaaS/PaaS providers operating in Germany sit in the highest NIS2 tier. Implementing ISO 27017 + BSI C5 typically covers the bulk of obligations and provides defensible evidence for customer audits.
Frequently Asked Questions
Hyperscalers vs. mid-market cloud?
CSA STAR or ISO 27017?
Sources
- Directive (EU) 2022/2555 — NIS2 (Annex I digital infrastructure) (As of: 2026-05-02)
- BSIG 2025 (consolidated after NIS2UmsuCG) (As of: 2026-05-02)
- Regulation (EU) 2022/2554 — DORA (cloud-services interplay) (As of: 2026-05-02)