NIS2 Eligibility Checker

Does NIS2 Apply to Your Company?

Answer a few quick questions to find out whether your organization falls under the scope of the NIS2 Directive.

Your Progress Step 1 of 9

This tool provides a preliminary assessment only and does not constitute legal advice. For a full eligibility assessment, consult a qualified NIS2 compliance expert.

Who Does NIS2 Apply To?

The NIS2 Directive (EU) 2022/2555 replaced the original NIS Directive and widened the net dramatically — from roughly 20,000 organisations across the EU to an estimated 160,000 or more. If you ran the checker above, you already have a preliminary answer. This section explains the reasoning behind it, so you can sanity-check the result and explain it to your board.

Whether NIS2 applies to your organisation comes down to three tests, applied in order: which sector you operate in, how big you are, and where you provide services. You need to pass all three to fall within scope — with a set of exceptions where size stops mattering entirely.

The Three Tests That Decide If NIS2 Applies to You

1

Sector

Your primary activity must fall within one of the 18 sectors listed in Annex I or Annex II of the Directive. Annex I covers 11 “sectors of high criticality”; Annex II covers 7 “other critical sectors”.

2

Size

NIS2 uses the standard EU size-cap rule. Medium-sized enterprises (50 or more employees, or annual turnover and balance sheet total above €10 million) and large enterprises (250 or more employees, or turnover above €50 million and balance sheet above €43 million) fall in scope. Micro and small enterprises are generally out — unless an exception applies.

3

Territory

NIS2 applies to entities providing services within the EU, including organisations established outside the Union. A UK, Swiss or US company serving EU customers in a covered sector can be in scope, and may be required to designate an EU representative.

The 18 Sectors Covered by NIS2

NIS2 splits covered activities across two annexes. Which annex you sit in matters: together with your headcount and turnover, it determines whether you are classified as an essential or an important entity.

Annex I — Sectors of High Criticality (11)Annex II — Other Critical Sectors (7)
Energy — electricity, district heating and cooling, oil, gas, hydrogenPostal and courier services
Transport — air, rail, water, roadWaste management
BankingManufacture, production and distribution of chemicals
Financial market infrastructuresProduction, processing and distribution of food
Health — providers, EU reference laboratories, pharmaceuticalsManufacturing — medical devices, computer, electronic and optical products, electrical equipment, machinery, motor vehicles, other transport equipment
Drinking waterDigital providers — online marketplaces, search engines, social networking platforms
Waste waterResearch organisations
Digital infrastructure — DNS, TLD registries, cloud, data centres, CDNs, trust services, electronic communications
ICT service management (business-to-business) — managed service providers, managed security service providers
Public administration entities
Space

Essential vs. Important Entities: What’s the Difference?

Both categories carry the same obligations under Article 21 (risk-management measures) and Article 23 (incident reporting). The difference is how aggressively regulators check your compliance, and how hard they can fine you when you fall short.

Essential entitiesImportant entities
Who qualifiesLarge enterprises in Annex I sectorsMedium enterprises in Annex I; medium and large enterprises in Annex II
SupervisionEx-ante — proactive audits, on-site inspections and routine checks, whether or not anything has gone wrongEx-post — regulators act only after evidence of non-compliance surfaces
Maximum fine€10 million or 2% of total worldwide annual turnover, whichever is higher€7 million or 1.4% of total worldwide annual turnover, whichever is higher
Core obligationsIdentical — Article 21 risk-management measures and Article 23 reporting duties apply equally to both

When NIS2 Applies Regardless of Your Size

The size-cap rule has exceptions. Under Article 2(2), you can fall in scope even as a small or micro enterprise if you are:

  • The sole provider in a Member State of a service that is essential to societal or economic activity
  • An organisation where disruption could have a significant impact on public safety, public security or public health
  • An organisation where disruption could induce significant systemic risk, particularly across borders
  • Critical because of your specific importance at national or regional level for a given sector or service
  • A provider of public electronic communications networks or services
  • A trust service provider
  • A TLD name registry or DNS service provider
  • A public administration entity, as defined by your Member State

This is where most “we’re too small for NIS2” assumptions fall apart — particularly for managed service providers, DNS and hosting businesses, and specialist suppliers to critical sectors.

NIS2 Scope Checklist

Work through these eight points to confirm your position and evidence it for your management body.

  • Confirmed your primary activity against the Annex I and Annex II sector lists
  • Calculated headcount, turnover and balance sheet total against the EU size-cap thresholds
  • Checked whether any Article 2(2) exception overrides the size cap in your case
  • Identified whether you would be classified as an essential or an important entity
  • Mapped every EU Member State in which you provide services
  • Checked each country’s national transposition law, since scope and deadlines vary
  • Confirmed your registration obligation with the relevant national competent authority
  • Briefed your management body — Article 20 makes them personally accountable for approving cybersecurity measures

Country rules differ across the EU. See our country-by-country NIS2 guides for national transposition status, competent authorities and registration deadlines — or talk to our team for a formal scope assessment.

Frequently Asked Questions

Does NIS2 apply to my company?

NIS2 applies if your organisation operates in one of the 18 sectors listed in Annex I or Annex II, meets the medium or large enterprise size thresholds, and provides services in the EU. Small and micro enterprises are generally excluded, unless one of the Article 2(2) exceptions applies. The checker at the top of this page walks you through all three tests in about two minutes.

Who does NIS2 apply to?

NIS2 applies to medium and large organisations across 18 sectors, ranging from energy, transport, banking and health to waste management, food production, manufacturing and digital providers. It also captures certain organisations regardless of size, including DNS service providers, TLD registries, trust service providers, providers of public electronic communications, and public administration entities.

Is NIS2 mandatory?

Yes. NIS2 is binding EU law for organisations in scope. Because it is a directive rather than a regulation, it takes effect through each Member State’s national transposition law, so the precise obligations, registration process and deadlines vary by country. In-scope entities must register with their national competent authority, implement the Article 21 risk-management measures and meet the Article 23 reporting timelines.

What happens if my company is out of scope?

Being out of scope does not mean NIS2 will not affect you. Article 21(2)(d) requires in-scope entities to manage supply chain security, so their NIS2 obligations get passed down to suppliers through contracts, questionnaires and audit clauses. Many organisations that are formally out of scope still need to demonstrate equivalent security controls in order to keep working with customers who are in scope.

When did NIS2 come into force?

NIS2 entered into force on 16 January 2023, and Member States were required to transpose it into national law by 17 October 2024. Transposition has moved at very different speeds across the EU, so your actual obligations and deadlines depend on the country or countries in which you operate.

What is the difference between NIS and NIS2?

NIS2 significantly expands the original 2016 NIS Directive. It widens sector coverage, replaces the old case-by-case national identification of operators with a clear size-cap rule, introduces the essential and important entity classification, tightens incident reporting to a 24-hour early warning and 72-hour notification, adds supply chain security requirements, and makes management bodies personally accountable. See our detailed NIS vs NIS2 comparison.