Skip to main content
NIS2 SCOPE

Does NIS2 apply to your organization?

Two tests decide most of the answer: what sector you operate in, and how big you are. A third list — the exceptions — pulls some organizations into scope regardless of size. And the final answer is always national: each of the 27 member states transposed NIS2 into its own law, and the thresholds, registration duties and deadlines that bind you are the national ones, not the directive headline.

Test one — your sector

NIS2 names the sectors it covers in two annexes. Annex I lists sectors of high criticality; Annex II lists other critical sectors. If your main activity is on either list, move to test two. If it is not, NIS2 probably does not apply to you directly — but read the supply-chain note below before you close the tab.

NIS2 sector annexes — Directive (EU) 2022/2555
AnnexSectors covered
Annex I — high criticalityEnergy, transport, banking, financial-market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, space
Annex II — other criticalPostal and courier services, waste management, chemicals, food production and distribution, manufacturing, digital providers (online marketplaces, search engines, social networks), research

Test two — your size

As a rule, NIS2 covers medium-sized and larger organizations in those sectors: 50 or more employees, or more than EUR 10 million in annual turnover. Small and micro organizations in Annex sectors are generally out of scope — unless an exception applies.

The combination of the two tests also sets your tier. Large enterprises in Annex I sectors are usually essential entities, supervised proactively. Medium enterprises in Annex I, and medium and large ones in Annex II, are usually important entities, supervised reactively — after an incident or a complaint. The duties are largely the same; the supervision and the fine ceilings are not.

The exceptions — in scope regardless of size

Some organizations are covered no matter how small they are: providers of public electronic communications networks or services, trust service providers, top-level-domain name registries, and DNS service providers. Member states may also pull in smaller entities whose failure would have outsized consequences — a regional water utility with thirty employees is the classic example. The national lists differ, which is one reason the country pages below exist.

Below the threshold? Your customers may bring NIS2 to you

Article 21(2)(d) obliges in-scope entities to manage the security of their supply chain — and in practice that obligation flows downhill. If an essential or important entity buys from you, expect security requirements, evidence requests and audit rights in your contracts whether or not NIS2 names you directly. Suppliers who can answer those requests from a running control system close those deals faster than suppliers who answer from a spreadsheet.

The binding answer is national

The directive sets the frame; the 27 national transpositions set the thresholds, the registration portals, the competent authorities and the deadlines that actually bind you. Germany's NIS2UmsuCG is not Belgium's NIS2 Act of 26 April 2024. Start with your country:

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 applies by sector and size: organizations in its Annex I or II sectors with 50+ employees or over EUR 10 million turnover are in scope, and trust service providers, TLD registries, DNS and telecom providers are in scope regardless of size. The binding thresholds are set by each member state's national transposition, not the EU headline.