Glossary · NIS2
Annex II
The list of 7 sectors under NIS2 considered important but generally lower-risk than Annex I.
Explained in depth: Which sectors NIS2 covers
Annex II lists the "other critical sectors": postal and courier services, waste management, chemicals, food production and distribution, manufacturing (including medical devices, electronics, machinery, and motor vehicles), digital providers (online marketplaces, search engines, social networks), and research organisations. Organisations in Annex II sectors that meet the medium-enterprise threshold are classified as important entities. They must implement the same ten Article 21 security measures and follow the same Article 23 reporting timeline as essential entities. The difference lies in supervision and penalties, not in the security requirements themselves.
Why it matters
A common misconception is that Annex II means lighter security obligations. It does not. The cybersecurity measures are identical; only the supervisory regime (reactive rather than proactive) and the maximum fine (EUR 7 million or 1.4% of turnover) differ.
