NIS2
Who Must Comply With NIS2?
NIS2 scope is decided by a two-criteria test: the sector your organisation operates in, and its size. If you carry out an activity listed in Annex I or Annex II of the directive and you are at least a medium-sized enterprise, you are in scope by default — no letter from an authority is needed, and the obligation to register falls on you.
The two-criteria test
The sector criterion comes first. Annex I of Directive (EU) 2022/2555 lists eleven "sectors of high criticality" — energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration and space. Annex II adds seven "other critical sectors": postal and courier services, waste management, chemicals, food production and distribution, manufacturing of certain products, digital providers and research organisations. Eighteen sectors in total. What matters is the activity you actually perform, not the industry code on your registration certificate.
The size criterion uses the EU's standard enterprise definition (Recommendation 2003/361/EC). An organisation is in scope if it is at least medium-sized, meaning it employs 50 or more people, or has both an annual turnover and a balance sheet total above €10 million. Head-count and financial data of linked and partner enterprises count towards these thresholds, so a small subsidiary of a large group is usually treated as part of the group.
Meeting both criteria makes you an essential or important entity depending on the annex, your sector and your size. Meeting only one of them normally leaves you out of scope — with the exceptions described further down.
Essential vs important entities
| Essential entities | Important entities | |
|---|---|---|
| Sectors covered | Annex I (11 sectors of high criticality), and Annex I medium-sized entities in some member states | Annex II (7 other critical sectors), plus medium-sized Annex I entities |
| Typical size | Large enterprises: 250+ employees, or turnover above €50M and balance sheet above €43M | Medium-sized enterprises: 50-249 employees, or turnover and balance sheet above €10M |
| Supervision | Proactive (ex ante): authorities may run on-site inspections, regular and targeted security audits and request evidence without any incident having occurred | Reactive (ex post): authorities normally act on evidence or an indication of non-compliance, such as after an incident or a complaint |
| Maximum administrative fine | At least €10,000,000 or 2% of total worldwide annual turnover, whichever is higher | At least €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher |
The security obligations under Article 21 and the reporting obligations under Article 23 are the same for both categories. The difference lies in how closely you are supervised and how hard you can be fined.
Size thresholds at a glance
| Enterprise size | Headcount | Turnover / balance sheet | NIS2 status |
|---|---|---|---|
| Micro | Fewer than 10 | ≤ €2M turnover and ≤ €2M balance sheet | Out of scope, unless an exception applies |
| Small | 10-49 | ≤ €10M turnover and ≤ €10M balance sheet | Out of scope, unless an exception applies |
| Medium | 50-249 | ≤ €50M turnover and ≤ €43M balance sheet | In scope — usually as an important entity |
| Large | 250 or more | > €50M turnover or > €43M balance sheet | In scope — as an essential entity in Annex I sectors |
Always in scope regardless of size
Article 2 removes the size filter for a set of entities whose failure would have cross-border effects out of proportion to their head-count. Regardless of how few people they employ, the following are in scope:
- DNS service providers, excluding operators of root name servers.
- Top-level domain (TLD) name registries.
- Qualified trust service providers, such as qualified e-signature issuers.
- Providers of public electronic communications networks and publicly available electronic communications services.
- Sole providers of a service that is essential for societal or economic activity in a member state, and entities whose disruption could have a significant impact on public safety, security or health — including public administration entities and organisations individually designated by national authorities.
Self-assessment in five steps
- List what you actually do. Write down every service and activity your legal entity delivers, then check each one against Annex I and Annex II. One matching activity is enough.
- Calculate your size correctly. Take head-count, turnover and balance sheet total for the last closed financial year, and add the relevant share of any partner and linked enterprises.
- Check the size-independent exceptions. If you are a DNS provider, TLD registry, qualified trust service provider or public telecoms provider, you are in scope even as a micro enterprise.
- Determine your category. Annex I plus large size normally means essential; Annex II, or Annex I at medium size, normally means important. Where activities span sectors, the stricter category wins.
- Register and document. Submit your entity details to the competent national authority in each member state where you operate, and keep a dated record of the assessment itself — supervisors ask for the reasoning, not just the conclusion.
National variation
NIS2 is a directive, so each member state transposes it into national law and may extend scope further, add sectors or set its own registration deadlines. Always confirm your conclusion against the national implementing act in every country where you provide services.
Related reading
Frequently asked questions
Not sure where your organisation stands?
Work through our free NIS2 Readiness Checklist. It walks you through scope, the Article 21 measures and the documentation supervisors expect to see — no payment required.
Get the free NIS2 Readiness Checklist