NIS2 scope

Does NIS2 apply to my company?

NIS2 applies to your company if two things are true. It works in one of the 18 sectors listed in Annexes I and II of Directive (EU) 2022/2555. And it is at least medium-sized: 50 or more staff, or both annual turnover and balance sheet above €10 million. Some entities are covered whatever their size (Article 2).

Aptiness editorial team · built from the official texts cited belowUpdated 23 September 2026Assessment methodology

Quick check in three questions

  1. Is your sector in Annex I or II? If not, NIS2 does not apply to you directly. Your customers may still ask about it as their supplier.
  2. Is your service one covered regardless of size? Electronic communications, trust services, DNS, TLD registries and domain registration are. If yes, NIS2 applies.
  3. Do you have 50+ staff, or turnover and balance sheet both above €10 million? If yes, NIS2 applies. If no, it generally does not, unless your country names you.

Is your sector covered by NIS2?

The Directive lists 18 sectors in two annexes. Annex I holds the sectors of high criticality, Annex II the other critical sectors. Only the listed types of entity count, not the whole industry.

Annex I — sectors of high criticality

  1. 1.

    Energy. Electricity, district heating and cooling, oil, gas and hydrogen — including suppliers, producers, grid operators and operators of EV recharging points.

  2. 2.

    Transport. Air carriers and airports, rail, water transport and ports, road authorities and operators of intelligent transport systems.

  3. 3.

    Banking. Credit institutions.

  4. 4.

    Financial market infrastructures. Trading venues and central counterparties.

  5. 5.

    Health. Healthcare providers, EU reference laboratories, medicinal product R&D, pharmaceutical manufacturing and manufacturers of critical medical devices.

  6. 6.

    Drinking water. Suppliers and distributors of water for human consumption.

  7. 7.

    Waste water. Undertakings collecting, disposing of or treating urban, domestic or industrial waste water.

  8. 8.

    Digital infrastructure. Internet exchange points, DNS and TLD registries, cloud computing, data centres, content delivery networks, trust services and electronic communications.

  9. 9.

    ICT service management (B2B). Managed service providers and managed security service providers.

  10. 10.

    Public administration. Central and regional government entities, as defined by each Member State.

  11. 11.

    Space. Operators of ground-based infrastructure supporting space-based services.

Annex II — other critical sectors

  1. 12.

    Postal and courier services. Postal service providers, including courier services.

  2. 13.

    Waste management. Undertakings whose principal economic activity is waste management.

  3. 14.

    Chemicals. Manufacture of substances and distribution of substances or mixtures.

  4. 15.

    Food. Food businesses in wholesale distribution and industrial production and processing.

  5. 16.

    Manufacturing. Medical and in vitro diagnostic devices; computer, electronic and optical products; electrical equipment; machinery; motor vehicles; other transport equipment (NACE divisions 26–30).

  6. 17.

    Digital providers. Online marketplaces, online search engines and social networking platforms.

  7. 18.

    Research. Research organisations.

In practice, check your company's main activity and its NACE code against the full annex text. Waste management counts only as a principal activity, food only in wholesale and industrial production.

Is your company big enough for NIS2?

NIS2 uses the EU definition of small and medium-sized enterprises (Recommendation 2003/361/EC). A company in a listed sector is covered once it is no longer small.

SizeStaffTurnover or balance sheet
Small — not coveredfewer than 50turnover or balance sheet up to €10 million
Medium — coveredfewer than 250turnover up to €50 million or balance sheet up to €43 million
Large — covered250 or moreor turnover above €50 million and balance sheet above €43 million

Staff and financial figures include partner and linked enterprises, so a small subsidiary of a large group is usually not small (Article 6 of the Recommendation's Annex). The rule that public ownership disqualifies a company from being an SME does not apply under NIS2 (Article 2(1)).

Which companies does NIS2 cover regardless of size?

Articles 2(2) to 2(4) bring in some entities of any size:

  • providers of public electronic communications networks or publicly available electronic communications services;
  • trust service providers;
  • top-level domain name registries and DNS service providers;
  • entities providing domain name registration services;
  • entities identified as critical under Directive (EU) 2022/2557;
  • central government entities, and regional ones after a risk-based assessment;
  • entities a Member State names because they are the sole provider of an essential service, or their disruption would have a significant impact.

Essential or important entity: what is the difference?

Every covered company is either essential or important (Article 3). The obligations are the same; supervision and fines differ.

  • Essential: Annex I entities above the medium-sized ceilings, plus qualified trust service providers, TLD registries, DNS providers and some others. They face supervision in advance and afterwards (Article 32). Fines reach at least €10 million or 2 % of worldwide turnover, whichever is higher (Article 34(4)).
  • Important: every other covered entity, typically medium-sized companies and companies in Annex II. They are supervised after the fact, on evidence of non-compliance (Article 33). Fines reach at least €7 million or 1.4 % of worldwide turnover (Article 34(5)).

Does NIS2 affect suppliers?

Yes, indirectly. Covered companies must manage supply chain security, including their relationships with direct suppliers and service providers (Article 21(2)(d)). They must also consider each supplier's security practices (Article 21(3)).

In practice, a small supplier outside the scope gets the requirements through contracts and questionnaires. The questions are the same as for a covered company.

What does NIS2 require once it applies?

  • Management is responsible. It approves the security measures, oversees them, can be held liable and must be trained (Article 20).
  • At least ten measures. Risk analysis, incident handling, backups and continuity, supplier security, secure development, checking that measures work, training, encryption, access control and multi-factor authentication (Article 21(2)).
  • Incident reporting. An early warning within 24 hours, a notification within 72 hours and a final report within one month (Article 23(4)).
  • Registration. Member States keep a list of covered entities; entities give their name, contacts, sector and countries of service (Article 3(3) and 3(4)).

NIS2 applies to you, or your customers ask about it?

The free NIS2 readiness assessment checks your company against Articles 20, 21 and 23 in fifteen questions. No sign-up, result straight away.

Start the NIS2 assessment

Which national law applies?

NIS2 is a directive, so each Member State puts it into national law. The deadline was 17 October 2024, with the rules applying from 18 October 2024 (Article 41).

National laws may go further than the Directive (Article 5). They may also extend it to local government and education institutions (Article 2(5)). This page describes the EU minimum; your national authority decides the details.

Sources

This page paraphrases the official texts. It is not legal advice and does not check your national law.