NIS2

Who Must Comply With NIS2?

NIS2 scope is decided by a two-criteria test: the sector your organisation operates in, and its size. If you carry out an activity listed in Annex I or Annex II of the directive and you are at least a medium-sized enterprise, you are in scope by default — no letter from an authority is needed, and the obligation to register falls on you.

The two-criteria test

The sector criterion comes first. Annex I of Directive (EU) 2022/2555 lists eleven "sectors of high criticality" — energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration and space. Annex II adds seven "other critical sectors": postal and courier services, waste management, chemicals, food production and distribution, manufacturing of certain products, digital providers and research organisations. Eighteen sectors in total. What matters is the activity you actually perform, not the industry code on your registration certificate.

The size criterion uses the EU's standard enterprise definition (Recommendation 2003/361/EC). An organisation is in scope if it is at least medium-sized, meaning it employs 50 or more people, or has both an annual turnover and a balance sheet total above €10 million. Head-count and financial data of linked and partner enterprises count towards these thresholds, so a small subsidiary of a large group is usually treated as part of the group.

Meeting both criteria makes you an essential or important entity depending on the annex, your sector and your size. Meeting only one of them normally leaves you out of scope — with the exceptions described further down.

Essential vs important entities

Essential entitiesImportant entities
Sectors coveredAnnex I (11 sectors of high criticality), and Annex I medium-sized entities in some member statesAnnex II (7 other critical sectors), plus medium-sized Annex I entities
Typical sizeLarge enterprises: 250+ employees, or turnover above €50M and balance sheet above €43MMedium-sized enterprises: 50-249 employees, or turnover and balance sheet above €10M
SupervisionProactive (ex ante): authorities may run on-site inspections, regular and targeted security audits and request evidence without any incident having occurredReactive (ex post): authorities normally act on evidence or an indication of non-compliance, such as after an incident or a complaint
Maximum administrative fineAt least €10,000,000 or 2% of total worldwide annual turnover, whichever is higherAt least €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher

The security obligations under Article 21 and the reporting obligations under Article 23 are the same for both categories. The difference lies in how closely you are supervised and how hard you can be fined.

Size thresholds at a glance

Based on the EU enterprise definition in Recommendation 2003/361/EC. Staff head-count is decisive; a company must also stay under one of the two financial ceilings to remain in a category.
Enterprise sizeHeadcountTurnover / balance sheetNIS2 status
MicroFewer than 10≤ €2M turnover and ≤ €2M balance sheetOut of scope, unless an exception applies
Small10-49≤ €10M turnover and ≤ €10M balance sheetOut of scope, unless an exception applies
Medium50-249≤ €50M turnover and ≤ €43M balance sheetIn scope — usually as an important entity
Large250 or more> €50M turnover or > €43M balance sheetIn scope — as an essential entity in Annex I sectors

Always in scope regardless of size

Article 2 removes the size filter for a set of entities whose failure would have cross-border effects out of proportion to their head-count. Regardless of how few people they employ, the following are in scope:

  • DNS service providers, excluding operators of root name servers.
  • Top-level domain (TLD) name registries.
  • Qualified trust service providers, such as qualified e-signature issuers.
  • Providers of public electronic communications networks and publicly available electronic communications services.
  • Sole providers of a service that is essential for societal or economic activity in a member state, and entities whose disruption could have a significant impact on public safety, security or health — including public administration entities and organisations individually designated by national authorities.

Self-assessment in five steps

  1. List what you actually do. Write down every service and activity your legal entity delivers, then check each one against Annex I and Annex II. One matching activity is enough.
  2. Calculate your size correctly. Take head-count, turnover and balance sheet total for the last closed financial year, and add the relevant share of any partner and linked enterprises.
  3. Check the size-independent exceptions. If you are a DNS provider, TLD registry, qualified trust service provider or public telecoms provider, you are in scope even as a micro enterprise.
  4. Determine your category. Annex I plus large size normally means essential; Annex II, or Annex I at medium size, normally means important. Where activities span sectors, the stricter category wins.
  5. Register and document. Submit your entity details to the competent national authority in each member state where you operate, and keep a dated record of the assessment itself — supervisors ask for the reasoning, not just the conclusion.

National variation

NIS2 is a directive, so each member state transposes it into national law and may extend scope further, add sectors or set its own registration deadlines. Always confirm your conclusion against the national implementing act in every country where you provide services.

Related reading

Frequently asked questions

Not sure where your organisation stands?

Work through our free NIS2 Readiness Checklist. It walks you through scope, the Article 21 measures and the documentation supervisors expect to see — no payment required.

Get the free NIS2 Readiness Checklist