Menu
← Guides

Who is in NIS2 scope: sectors, size and the national exceptions

How to work out whether a client is an essential entity, an important entity or outside NIS2 — the two annexes, the size-cap rule, the entities in scope regardless of size, and what member states add.

Updated 2026-09-22

Three questions decide it

Whether a client falls under NIS2 — Directive (EU) 2022/2555 — comes down to three questions, asked in this order:

  1. Is it active in a sector listed in Annex I or Annex II?
  2. Is it at least medium-sized under the size-cap rule?
  3. Does a member state where it operates add anything — its own thresholds, designations, or entities it brings into scope regardless of size?

The answers give one of three outcomes: an essential entity, an important entity, or outside the directive. Most of the work is in the detail of each question, and most of the mistakes come from skipping the third.

Question one: the sectors

Annex I — sectors of high criticality:

  • energy: electricity, district heating and cooling, oil, gas, hydrogen;
  • transport: air, rail, water, road;
  • banking;
  • financial market infrastructure;
  • health: health care providers, EU reference laboratories, research and manufacture of medicinal products, manufacture of certain medical devices;
  • drinking water;
  • waste water;
  • digital infrastructure: internet exchange points, DNS service providers, TLD name registries, cloud computing, data centres, content delivery networks, trust service providers, public electronic communications networks and services;
  • ICT service management (business-to-business): managed service providers and managed security service providers;
  • public administration;
  • space.

Annex II — other critical sectors:

  • postal and courier services;
  • waste management;
  • manufacture, production and distribution of chemicals;
  • production, processing and distribution of food;
  • manufacturing: medical devices and in vitro diagnostics, computer, electronic and optical products, electrical equipment, machinery, motor vehicles, other transport equipment;
  • digital providers: online marketplaces, online search engines, social networking platforms;
  • research organisations.

Read the sector descriptions in the annexes, not only the headings. "Health" does not cover every company that sells to hospitals; "digital providers" does not cover every website. A SaaS company is not in scope merely because it is a software company — but a company providing managed IT services to other businesses may well be, as an ICT service management provider.

A client can be in more than one sector. The class follows from the most critical one it is in.

Question two: size

The directive applies to entities that are at least medium-sized, as defined in Commission Recommendation 2003/361/EC:

  • Medium: 50 employees or more, or annual turnover and annual balance sheet both above EUR 10 million.
  • Large: 250 employees or more, or annual turnover above EUR 50 million and annual balance sheet above EUR 43 million.

Small and micro enterprises are outside the size-cap rule. Two details catch people out:

  • Linked and partner enterprises count. The Recommendation adds the figures of partner and linked enterprises. A 30-person subsidiary of a large group can be a large enterprise for this purpose.
  • Headcount is annual work units, not people on the payroll on one day.

Essential or important

Once a client is in scope, the class:

  • Essential entities: large entities in Annex I sectors; qualified trust service providers, top-level domain name registries and DNS service providers regardless of size; providers of public electronic communications networks or services that are medium-sized or larger; public administration entities of central government; and entities a member state designates as essential.
  • Important entities: every other entity in scope — medium entities in Annex I sectors, and medium or large entities in Annex II sectors — plus those designated as important.

The obligations are largely the same: cybersecurity risk-management measures (Art. 21), incident reporting (Art. 23), management body accountability and training (Art. 20), and registration. The difference is supervision. Essential entities are supervised proactively — inspections and audits without a triggering event. Important entities are supervised mainly after the fact, when there is evidence of non-compliance. The maximum fines differ as well.

In scope regardless of size

Article 2(2) brings in some entities whatever their size, including:

  • providers of public electronic communications networks or services;
  • trust service providers;
  • top-level domain name registries and DNS service providers;
  • entities that are the sole provider in a member state of a service essential for critical societal or economic activities;
  • entities whose disruption could have a significant impact on public safety, public security or public health, or induce significant systemic risk;
  • entities that are critical because of their specific importance nationally or regionally.

Several of these depend on a decision by the member state. A small client can therefore be in scope — and the only way to know is to check the national law and any designation made under it.

Question three: what member states add

The directive sets minimum rules. The national transposition laws differ, and the differences are practical:

  • The competent authority the client registers with and reports to.
  • Registration — whether it is required, by when, and through which portal.
  • Reporting deadlines — some are stricter than the directive's 24 hours, 72 hours and one month, or specify them differently.
  • Thresholds and designations — additional entities brought into scope.
  • Timing — not every member state had its law in force on the directive's deadline, and some still differ in when obligations apply.

Check the law of every member state where the client provides services or has an establishment, not only the one where it is incorporated. For some digital infrastructure and digital provider entities, jurisdiction follows the main establishment in the EU instead (Art. 26); for the rest, the client can be subject to more than one member state's rules.

Financial entities and DORA

Where a sector-specific Union legal act imposes cybersecurity risk-management or incident reporting requirements at least equivalent to NIS2's, those provisions of NIS2 do not apply to the entities covered (Art. 4). For most financial entities that act is the Digital Operational Resilience Act (DORA), which governs their ICT risk management, incident reporting and testing in place of NIS2's.

That does not make a financial client's NIS2 analysis irrelevant — its group may contain entities outside DORA — but it changes which rulebook the documentation has to follow.

A worked example

A client provides a payments platform. It employs 180 people (annual work units), with turnover of EUR 38 million and a balance sheet of EUR 30 million, and operates in Germany and the Netherlands.

  • Sector: depends on what it is. As a credit institution it would be in banking (Annex I) — and DORA would take precedence. As a B2B software and managed services provider to banks, it may be an ICT service management provider (Annex I).
  • Size: 180 employees is medium; the turnover and balance sheet do not reach the large thresholds. Medium.
  • Class: medium in an Annex I sector — an important entity.
  • National law: register with and report to the German and Dutch authorities under their national laws, with their deadlines.

The sector question did most of the work, and it was the one that needed a conversation with the client.

Edge cases that come up often

SaaS or cloud computing? Annex I lists cloud computing service providers under digital infrastructure. Whether a SaaS product is a "cloud computing service" in the directive's sense depends on the definition in the European Electronic Communications Code framework the directive refers to, and member states and authorities read it differently. Treat it as an open question for each client, record the reasoning, and check the national authority's guidance.

Group companies. Scope is assessed per legal entity, but size counts linked enterprises. The result can be that one subsidiary in a group is in scope and another is not — and that a small entity is large for NIS2 purposes.

Suppliers to entities in scope. A client outside NIS2 whose customers are in scope will still feel it: Article 21 requires those customers to address supply chain security, so they will send questionnaires and contract clauses. Being out of scope does not mean being untouched.

Public sector suppliers. Public administration entities are in scope as defined by each member state; their suppliers are not in scope for that reason alone.

Growth. A client that crosses 50 employees, or whose turnover and balance sheet both pass EUR 10 million, can move into scope at its next annual figures. Put a reminder against the client when it is close.

What to record

Whatever the outcome, write down the reasoning: the sectors considered and why, the size figures and their source, the member states checked, and who confirmed the conclusion. A client found to be outside NIS2 today can move into scope with one acquisition or one national designation, and the recorded reasoning is what lets you see that quickly.

Try it on a client

The free NIS2 scope check runs this reasoning on a client's sector, size and countries. It suggests the class with the reasons, and shows the authority and reporting deadlines for each country we hold a national profile for. It is a suggestion from sector and size; the designations and the sector detail are yours to confirm.

See what changed since your clients' policies were written

Enter up to ten client websites. Free, no sign-up, the first report in about a minute.