If you operate a datacenter, sell colocation, or run managed hosting in the EU, NIS2 is probably the most consequential regulation to land on this industry in a decade — and a lot of providers still believe it is somebody else's problem.
It is not. Data centre services and cloud computing services sit in Annex I of the directive, in the Digital Infrastructure sector, which means qualifying providers are classified as essential entities and face the strictest tier of obligations the directive defines.
Not legal advice. NIS2 is an EU directive, which means it is implemented in national law and the details — registration mechanics, deadlines, supervisory authority and penalties — differ by member state and are still landing in some. This post describes the shape of the obligations and the operational consequences. Get your specific position confirmed by a qualified adviser in the countries you operate in.
Are you in scope?
Two tests, and you need both.
Sector. Digital Infrastructure in Annex I covers data centre services and cloud computing services, and the practical reading pulls in datacenter operators offering colocation, IaaS, PaaS and SaaS providers above the thresholds, managed hosting providers, and CDN operators.
Size. The default thresholds are 50 or more employees, or annual turnover of at least €10 million. Below both, you are generally out of the default scope — but member states can designate smaller entities where the service is critical, so "we are small" is a position to confirm rather than assume.
The distinction that matters most: entities in Annex I sectors are essential, not merely important. Essential entities face proactive supervision rather than supervision that begins after something goes wrong.
What it actually requires
Risk management measures. A documented risk analysis and an information security policy, incident handling, business continuity and backup management, supply chain security, security in acquisition and development, policies to assess effectiveness, basic cyber hygiene and training, cryptography policy, human resources and access control, and multi-factor authentication. Commission Implementing Regulation (EU) 2024/2690 sets out the technical and methodological detail for digital infrastructure entities, along with the criteria for what counts as a significant incident.
Incident reporting on a hard clock. This is the requirement that changes operations. A significant incident triggers an early warning within 24 hours, a fuller notification within 72 hours, and a final report within a month. Twenty-four hours is not long enough to work out who is supposed to send it — that has to be decided in advance, written down, and rehearsed.
Management accountability. Governing bodies approve the risk measures, oversee implementation, and can be held personally liable. NIS2 deliberately moves this off the CTO's desk and onto the board's.
Supply chain security. You are responsible for assessing the security of your suppliers and service providers. If you resell someone else's capacity, or depend on a remote-hands contractor, or run your business on third-party software, that is in scope.
Penalties. For essential entities, up to €10 million or 2% of total worldwide annual turnover, whichever is higher.
The part hosting providers underestimate
Supply chain security cuts both ways, and the second direction is the commercial one.
Your customers who are themselves in scope now have an obligation to assess you. That means security questionnaires, evidence requests, contractual security terms and audit clauses arriving from customers who never asked before. Providers who can answer quickly will win business from providers who cannot, and this is already visible in enterprise procurement.
The practical consequence is that NIS2 readiness is a sales asset, not only a compliance cost. The documentation you build to satisfy your own obligation is the same documentation your customers will ask you for.
Where your billing platform sits in this
It is easy to file NIS2 under "infrastructure security" and forget that the billing system is one of the most sensitive systems you run. It holds customer identities, contact details, payment references, contracts, and — in an integrated platform — the map of which customer is on which physical machine in which rack. That last one is an asset inventory, and asset inventory is a NIS2 requirement rather than a nice-to-have.
Concretely, these are the places the billing layer touches the obligations:
- Access control and MFA. Multi-factor authentication on administrative access is explicitly named. If your staff log into the billing platform with a password alone, that is a finding.
- Audit trails. You need to be able to say who changed what and when — for incident investigation and for the final report. See audit trails for billing systems.
- Backup and continuity. Backup management is named. A billing database you cannot restore is a continuity failure with a regulatory dimension now. See backups and disaster recovery.
- Asset inventory. Knowing which hardware exists, where it is, and who is on it. This is exactly the record a combined billing and DCIM system holds, and exactly the record that drifts when the two live in separate systems — see closing the reconciliation gap.
- Supplier assessment. Your billing vendor is a supplier. Expect to have to evidence that assessment, and expect your customers to ask you the same question.
A sequence that is not overwhelming
- Establish whether you are in scope, per member state, in writing. Do not guess on size thresholds.
- Find out your national registration obligation and deadline — these differ, and several have already passed in some states.
- Write the incident reporting runbook first. It is the one with a 24-hour clock and it is cheap to prepare and expensive to improvise.
- Inventory your assets and your suppliers. Most providers discover both lists are incomplete.
- Close the obvious technical gaps: MFA on admin access, tested backups, logging you can actually search.
- Get the governing body to formally approve the measures, and minute it. Accountability sits there by design.
How FluxBilling fits
Nothing here is a compliance product and we would not sell it as one — NIS2 compliance is an organisational programme, not a feature. What a billing platform can do is not be the weak point.
FluxBilling supports two-factor authentication on administrative access, keeps audit trails of administrative actions, and holds hardware inventory, rack position and IP allocation in the same records as the customer and the invoice — so the asset inventory question has one answer rather than two systems that disagree. Self-hosting on the Business tier (€44.95/month plus a €500 one-time fee) is available where you need the data to sit on infrastructure you control.
Being clear about the limits: we do not publish a SOC 2 or ISO 27001 certification, and you should not represent us as one in your own supplier assessment. If your customers require certified suppliers, ask us directly what we can evidence rather than assuming.
See security and the compliance roundup.
Closing thoughts
The 24-hour early warning is the requirement that will catch people. It does not require a full analysis — it requires that somebody, identified in advance, notices a significant incident and reports it within a day. Write that runbook this month, name the person, and test it once. It is the cheapest item on the list and the one most likely to be missing when it matters.
Sources
- Directive (EU) 2022/2555 (NIS2), Annex I Digital Infrastructure
- Commission Implementing Regulation (EU) 2024/2690 — technical and methodological requirements for digital infrastructure entities, and significant-incident criteria
National implementations differ; confirm your position with a qualified adviser in each member state where you operate.