- Operated by
- National cybersecurity authorities
- Purpose
- NIS2 registration and incident notifications
- Access
- Defined by each Member State
- Relevance to NIS2
- Registration and reporting interface
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is a NIS2 registration portal?
The Registration portals are the national online platforms through which organisations meet their NIS2 duties. Whereas the terms National cybersecurity authorities and competent authority describe the institution and the legal role, a registration portal is the concrete technical tool: the online platform through which entities in scope deal with their authority. This is where entities register and file their incident notifications – the portal is the practical point of contact between an organisation and its supervisor.
What you use it for
- Registration as an entity in scope
- Multi-stage notifications for security incidents (24-hour early warning, 72-hour notification, final report after one month)
- Managing the contact and master data of the Entity
How access works
Access usually runs through an existing national business identity – the same kind of electronic identification that organisations already use for tax filings or other dealings with public authorities. Which scheme applies is decided by the Member State that operates the portal. The advantage is the same everywhere: the login is bound to the identity your organisation already has, so no additional sign-in system has to be built.
The portal in the NIS2 process
The portal is the interface to the competent authority of the Member State in which your organisation is established. NIS2 has applied since 18 October 2024; from the date on which your Member State transposed it, the national portal is the binding route for meeting registration and reporting duties. The deadlines themselves are set in national law and differ from country to country.
A scenario from hospital operations
The IT security officer of a hospital operator sets up the company account early and files two contact points. When an encryption attack is detected during the night, the on-call team can send the 24-hour early warning through the national portal straight away, without first having to apply for credentials. The team then follows up within 72 hours with the fuller notification and an initial assessment of cause and impact, and later adds the final report. Having that access ready in advance decides, in an emergency, whether the tight 24-hour deadline and the further statutory reporting deadlines are met.
Further reading: European Commission – NIS2 Directive
Frequently asked questions
What is a NIS2 registration portal?
A registration portal is the online platform that a Member State operates so that entities in scope of NIS2 can register, maintain their master data and report significant incidents. It is the practical point of contact between an organisation and its supervisor. NIS2 does not create a Union-wide portal: each Member State builds or designates its own, so the address, the login procedure and the data requested differ from country to country.
How do you sign in to a registration portal?
Access is usually tied to an electronic identity that the organisation already holds, such as a national business or tax identity, so that the login is bound to an established identity and no separate sign-in system has to be created. The scheme differs by Member State, and so do the roles and permissions that can be granted. Whatever the arrangement, it is advisable to register more than one contact point.
When should you set up portal access?
As early as possible. In a real incident NIS2 leaves only 24 hours for the early warning, followed by an incident notification within 72 hours and a final report within one month. Anyone who applies for access only after an incident risks missing those statutory deadlines. The registration deadlines themselves are set in national law and differ from country to country, so check the date that applies where your organisation is established.