Skip to content
rPResiliencePilot
All resources
NIS27 min read·31 July 2026

Is your organisation in scope for NIS2? A plain-English scope test

A practical NIS2 scope test: the two questions that decide whether you're in, the Annex I and II sectors, the size thresholds, and whether you're an essential or important entity.

A wide view of an illuminated motorway interchange at night, forming a network of light trails

NIS2 widened the net so far that the first question on most people's minds isn't how do we comply but does this even apply to us? The old NIS directive covered a few thousand operators of essential services. NIS2 pulls in an estimated 100,000-plus organisations across the EU, and a lot of them don't think of themselves as critical infrastructure.

The good news is that working out whether you're in scope is mechanical. It comes down to two questions: what sector are you in, and how big are you. Answer both and your status, including whether you're an essential or an important entity, falls out.

Part 1: are you in a covered sector?

NIS2 lists 18 sectors, split across two annexes.

Annex I, "sectors of high criticality" (11):

  • Energy (electricity, district heating and cooling, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking
  • Financial market infrastructure
  • Health (providers, laboratories, R&D, pharmaceuticals, critical medical devices)
  • Drinking water
  • Waste water
  • Digital infrastructure (internet exchange points, DNS, top-level domain registries, cloud providers, data centres, content delivery networks, trust service providers, electronic communications)
  • ICT service management, business-to-business (managed service providers and managed security service providers)
  • Public administration
  • Space

Annex II, "other critical sectors" (7):

  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing (medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment)
  • Digital providers (online marketplaces, search engines, social networking platforms)
  • Research organisations

Two of these catch people out. ICT service management means that if you're an MSP or an MSSP, you're in a high-criticality sector in your own right, regardless of who your customers are. And digital infrastructure and digital providers sweep in a lot of technology and SaaS companies that never considered themselves regulated.

If nothing on the list describes what you do, you're very likely out of scope, and the rest of this article is reassurance rather than homework.

Part 2: are you big enough?

Being in a listed sector isn't enough on its own. NIS2 uses the EU definition of a medium-sized enterprise as its floor. Broadly, you're in scope on size if you have at least 50 employees, or an annual turnover or balance sheet total above €10 million. Micro and small organisations sit below that line and are generally left out.

There's one nuance worth pausing on, because it's where self-assessments go wrong. The size test counts linked and partner enterprises, not just your own headcount. A twenty-person subsidiary of a large group is usually assessed as part of that group, which can pull a business that feels small firmly into scope.

In regardless of size

A short list of entity types are in scope whatever their size, because the service they provide is too critical to exempt on a headcount:

  • DNS service providers
  • Top-level domain name registries
  • Qualified and non-qualified trust service providers
  • Providers of public electronic communications networks or services
  • An entity that is the sole provider of an essential service in a Member State
  • Entities a Member State designates because a disruption would have significant systemic or cross-border impact

Essential or important?

If both questions land you in scope, NIS2 sorts you into one of two categories. The distinction isn't about how hard you have to work on security; both categories have to meet the same risk-management measures (Article 21) and the same incident-reporting duties (Article 23). What differs is how you're supervised and how large the fines can be.

Your situationCategory
Large entity in an Annex I sectorEssential
Medium entity in an Annex I or Annex II sectorImportant
Large entity in an Annex II sectorImportant

Essential entities face proactive, ex-ante supervision and a fine ceiling of up to €10 million or 2% of global annual turnover, whichever is higher. Important entities are supervised reactively, ex-post, with a ceiling of €7 million or 1.4%. In both cases, senior management can be held personally accountable for failures in the risk-management measures.

The catches teams miss

  • It's national law now, not one directive. NIS2 is a directive, which means each Member State writes it into its own law. The transposition deadline was 17 October 2024, and several countries ran late, so your precise obligations, and sometimes the exact scope, come from your national legislation rather than the directive itself. Always confirm against the law in the country where you operate.
  • Supply chain reaches the out-of-scope. Even if you're below the line, your in-scope customers must manage the security of their supply chain. You'll feel NIS2 second-hand, through contract clauses and security questionnaires, long before any regulator writes to you directly.
  • Assess per entity and per country. Scope is decided for each legal entity in each Member State, so a group can have some companies in and others out.

If you're in scope, what happens next

Two obligations do most of the work. Article 21 sets out the risk-management measures you must have in place, from risk analysis and incident handling to supply-chain security, encryption and basic cyber hygiene. Article 23 sets the reporting clock: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. We walk through those deadlines in detail in NIS2 incident reporting timelines.

Many organisations already run a large part of this through an ISO 22301 business continuity system, and map the evidence to NIS2 rather than starting from a blank page.

Still not certain?

Scope questions rarely have a one-line answer, especially where national transposition adds its own detail, so treat this as a structured first pass rather than legal advice. If you want a quick read on where you'd stand, our NIS2 readiness assessment walks through the obligations clause by clause, or you can see how ResiliencePilot supports NIS2 end to end. When you're ready to talk specifics, book a demo.

See ResiliencePilot in action

See it on your own data and frameworks, with your security and data-residency questions answered.