NIS2 · Sector deep-dive

NIS2 for Public Administration

Public administration is an Annex I sector, and it behaves differently from every other one. Central government entities are in scope as their member state defines them, without the usual size threshold; regional bodies are in scope where the state identifies them; and activities in national security, defence and law enforcement are excluded outright. The result is that scope is decided almost entirely by national transposition rather than by reading the directive.

Scope is set nationally, in three steps

First, central government. Annex I refers to public administration entities of central government "as defined by a member state in accordance with national law". Each state therefore publishes its own list or definition, and the boundary between a ministry, an agency and a state-owned company is drawn differently across Europe.

Second, regional and local level. Regional entities are in scope where the member state identifies them as providing services whose disruption could significantly affect critical societal or economic activities. Municipalities are covered only if the state chose to include them — a genuine national policy decision, taken differently in different countries and sometimes limited to named functions such as social care systems or municipal emergency services.

Third, the exclusions. Activities in national security, public security, defence and law enforcement fall outside the directive, and member states may exempt further entities carrying out such activities. Because the carve-out follows activities rather than organisations, most authorities that touch this area need a written scoping decision showing which systems are in and which are out.

Where public authorities typically have the biggest gaps

  • Shared service centres. IT is delivered by a central or inter-municipal provider, so the entity that carries the legal obligation is not the entity that operates the systems, and the contract rarely says who detects, escalates and reports.
  • Procurement-shaped supplier risk. Long framework agreements signed before NIS2, with no security requirements, no right to audit and no vulnerability notification duty.
  • Management accountability sits with elected officials. Article 20 requires the management body to approve the risk management measures and to receive training. In a public body it must be clear whether that is the director general, the board, or the political committee — and the approval must be minuted.
  • Legacy case-handling systems. Registry, benefits and permit systems maintained for decades, holding large volumes of personal data, with authentication and logging built to an older standard.
  • Two overlapping notification duties. A single incident can require a NIS2 early warning within 24 hours and a GDPR personal data breach notification within 72 hours, to different authorities, on different clocks.

What this means for the Article 21 measures

  • Risk analysis and system security policy — Article 21(2)(a). The policy has to state the scoping decision explicitly: which functions are in scope, which are excluded as national security or law enforcement activities, and on what basis.
  • Supply chain security — Article 21(2)(d). Security requirements written into procurement templates and into the shared service agreement, covering detection, escalation timelines and reporting support.
  • Incident handling — Article 21(2)(b). One runbook that starts both clocks — NIS2 to the CSIRT or competent authority, GDPR to the data protection authority — and names the person authorised to file each. See the reporting timeline.
  • Business continuity and crisis management — Article 21(2)(c). Continuity for statutory services citizens cannot obtain elsewhere, with tested restore procedures rather than a plan that assumes the shared service centre will cope.
  • Basic cyber hygiene and training — Article 21(2)(g). Broad, distributed workforces make MFA, patching discipline and role-based training the measures that move risk the most per euro spent.

The full measure list is on the Article 21 requirements page. Because scope depends on national transposition, confirm your status against your own country's implementing law before concluding you are out of scope.

Documentation

The NIS2 Starter Kit gives a public authority the risk assessment, asset register, policy set and incident procedure needed to evidence Article 21 without a consulting engagement.

View the NIS2 Starter Kit

Related reading

Frequently asked questions