Does NIS2 Apply to My Company?

Last updated: 15 July 2026

Whether NIS2 applies to your company comes down to a two-part test. You are in scope if you operate in one of eighteen listed sectors and you count as at least a medium-sized enterprise. Fail either half and the directive normally leaves you out.

Normally. A third layer ignores size entirely and pulls in certain services regardless of how few people they employ. Most companies working through this try to rule themselves out on headcount, which is exactly the move Directive (EU) 2022/2555 blocks for those services.

Our NIS2 Applicability Checker runs the full test in a couple of minutes. This piece explains what each part is asking, so when the answer lands you know why.

Who Does NIS2 Apply To?

NIS2 applies to public and private entities that operate in a sector listed in Annex I or Annex II of the directive and that qualify as at least medium-sized enterprises. Both conditions have to be met at the same time.

Article 2(1) ties the two halves together with an “and”. You have to be an entity of a type referred to in Annex I or II and qualify as medium-sized or larger. A national retail chain with two thousand staff sits outside NIS2 because retail is not a listed sector. A regional water utility with ninety staff sits inside it because water is. In our assessment the sector half is where most self-assessments go wrong, because people reach for the size number first and never check whether their activity is even on the list.

Does NIS2 Apply to Small Businesses?

As a rule, no. NIS2 uses the EU definition of a medium-sized enterprise as its floor, so micro and small enterprises fall outside the directive unless a size-blind exemption applies.

The floor comes from Recommendation 2003/361/EC, which Article 2(1) of NIS2 imports directly. A micro enterprise has fewer than 10 staff and turnover or balance sheet total no higher than €2 million. A small enterprise has fewer than 50 staff and turnover or balance sheet total no higher than €10 million. A medium enterprise has fewer than 250 staff and turnover no higher than €50 million or a balance sheet total no higher than €43 million.

Headcount is the main criterion and has to be met. The two financial figures work as an either or, so a company stays in its band as long as one of them sits under the ceiling. A firm with fewer than 50 staff only climbs out of the small band, and into NIS2 range, when it either crosses 50 staff or exceeds both €10 million turnover and €10 million balance sheet total. A 30-person company with €40 million turnover but an €8 million balance sheet is still small on its own numbers, because the balance sheet keeps it under. And a single year over the line does not flip you, since a change of status takes effect only after two consecutive accounting periods, per Article 4 of the Annex.

Those thresholds apply to your own figures only if you are autonomous. Under Article 6 of the Annex, a company with linked or partner enterprises has to count the group’s headcount and financials too, in full for linked enterprises and pro rata for partners. So a small subsidiary of a large group can clear the medium threshold on the group’s numbers even when its own payroll would keep it under. “We are too small” is the most common wrong answer we see, and group structure is usually why it is wrong.

What Sectors Are Covered by NIS2?

NIS2 covers eighteen sectors, split across two annexes. Annex I lists eleven sectors of high criticality and Annex II lists seven other critical sectors.

The split is not cosmetic. Annex I is the backbone the economy stops without, so it carries the heavier classification. It runs from energy, transport, banking and financial market infrastructure through to health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II is the tier of important but survivable services: postal and courier, waste management, chemicals, food production and distribution, certain manufacturing, digital providers such as online marketplaces, search engines and social networking platforms, and research organisations.

The Commission’s own overview confirms the jump from the seven sectors of the original directive to today’s eighteen. In our assessment that jump is the single biggest reason a company that was clear before is now caught. Waste water, public administration, space, postal services, food, chemicals and manufacturing of critical products were all pulled in. Widely cited estimates put the number brought into scope at roughly 160,000, up from about 15,000 under the original directive, though those are projections rather than a legal count. If your answer to “were we ever in scope” was no, check the date you last looked.

Essential or Important, and Why the Label Decides Your Exposure

Your classification follows from your sector, your size, and in several cases your activity type. As a baseline, large entities in Annex I are essential, medium entities in Annex I are important, and Annex II entities are important whether they are medium or large. Article 3 then makes several categories essential regardless of size band.

Per Article 3(1), qualified trust service providers, top-level domain registries and DNS providers are essential no matter how small they are, medium-sized providers of public electronic communications are essential rather than important, central government public administration entities are essential, and so are CER critical entities and any entity a member state specifically designates. So a medium-sized telecoms operator that assumed it was merely important has read the table wrong. The label is the switch that sets how hard the regime lands. Essential entities face proactive supervision and the full enforcement toolkit. Important entities are supervised mainly after something goes wrong. We keep the full breakdown in a separate piece on essential versus important entities.

One consequence belongs here rather than there. Under Article 20(1), the management body has to approve the cyber risk measures and can be held liable for the entity’s failures. For essential entities only, Article 32(5)(b) lets a competent authority ask a court to bar a chief executive or legal representative from management functions until the gaps are fixed. The fines sit on top, up to €10 million or 2% of global annual turnover, whichever is higher, for essential entities, and up to €7 million or 1.4% of global annual turnover, whichever is higher, for important ones, under Article 34. Those are minimum ceilings for the national maximum, so national law can set them higher. That is the sentence to forward to your board before the budget conversation, not after. Our breakdown of NIS2 obligations covers what the measures actually are.

The Entities NIS2 Covers Regardless of Size

Some entities are in scope no matter how small they are. Article 2(2) to 2(4) of NIS2 overrides the size floor for specific services and situations.

This is the layer that surprises people. Per Article 2(2), size stops mattering for providers of public electronic communications networks and services, trust service providers, and top-level domain registries and DNS providers. It also stops mattering when an entity is the sole provider in a member state of a service essential to critical activity, where an outage would hit public safety, security or health, where it would carry significant systemic and cross-border risk, or where the entity is critical because of its specific importance at national or regional level under Article 2(2)(e). Article 2(2)(f) pulls in central government public administration entities regardless of size, with regional bodies covered on a risk assessment. Article 2(3) pulls in any entity identified as a critical entity under the CER Directive (EU) 2022/2557. Article 2(4) covers domain name registration services.

The practical read is simple. If you provide DNS, run a TLD registry, issue trust services or carry public electronic communications, headcount is not a defence. A ten-person trust service provider is as in scope as a bank. Size is a filter for ordinary sectors, not a safe harbour for the ones the directive treats as load-bearing.

What NIS2 Does Not Cover

NIS2 explicitly leaves some entities out even when they sit in a listed sector. National security, defence and law enforcement functions are excluded outright, financial entities largely follow DORA instead for the obligations DORA governs, and micro and small enterprises without a size-blind trigger fall away on size.

Per Article 2(7), the directive does not apply to public administration entities carrying out activities in national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences. Financial sector entities are largely handled elsewhere. Under Article 4, the Digital Operational Resilience Act (Regulation (EU) 2022/2554) is lex specialis for banks, insurers and investment firms, so for the areas DORA governs they follow DORA, not NIS2. Banking and financial market infrastructure remain listed NIS2 sectors, so the point is displacement of specific obligations, not blanket exclusion. The judiciary, parliaments and central banks fall outside as well, because the directive’s own definition of a public administration entity in Article 6(35) excludes them, so they never enter scope as public administration in the first place.

Two labels cause more confusion than the exclusions themselves. Critical entities are a CER concept, not a NIS2 one, and a CER critical entity is automatically an essential entity under NIS2 rather than something separate. NIST is a US standards agency, and its voluntary Cybersecurity Framework is not the binding EU directive that happens to sound like it.

NIS2 Reaches Non-EU Digital Providers That Serve the EU Market

Being established outside the EU does not put a covered digital provider out of scope. For the digital categories listed in Article 26(1)(b), offering services within the Union brings the entity within NIS2 through Article 26.

The mechanism mirrors GDPR, and it is narrower than it first looks. It applies to the digital services named in Article 26(1)(b): DNS providers, TLD registries, domain name registration services, cloud providers, data centres, content delivery networks, managed service and managed security service providers, online marketplaces, search engines and social networking platforms. Per Article 26(3), such an entity based outside the Union that offers services inside it has to designate a representative in a member state where it operates, and it then falls under that state’s jurisdiction. Skip the appointment and any member state where you provide those services can pursue you directly. For an ordinary-sector business with no EU establishment, simply selling goods into the Union is usually not enough to be caught, because that is not providing one of these services. The market, not the head office, decides, but only for the listed digital categories.

There is a matching registration duty. Entities such as cloud providers, data centres, content delivery networks, managed service providers, online marketplaces and search engines had to submit their details to competent authorities by 17 January 2025 under Article 27, feeding an ENISA-held register. If that date passed without you noticing and you run one of those services into the EU, the obligation did not wait for you to notice.

The Directive Can Apply Before Your Country Has Finished Transposing It

Whether NIS2 applies to you is set by the directive, but how and when its obligations bite depends on your member state’s national law. Transposition timelines and some thresholds vary across the Union, and our NIS2 transposition status for all 27 member states lists where each stands and which authority enforces it.

NIS2 is a directive, so it lives through national statutes rather than applying directly. Member states had until 17 October 2024 to transpose it, and several missed. On 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for incomplete transposition and asked for a lump sum and daily penalty payments (press release IP/26/1499). So four governments are now being taken to court for missing the deadline to enact the rules that decide who else has to follow rules, with daily fines running until they finish. We track the case in our note on the NIS2 court referral.

The transposition gap has a practical edge that is easy to get wrong. In a state that has not finished transposing, your entity can already fall within the directive’s scope while the domestic machinery, the competent authority, the registration portal, the exact thresholds, is not yet in force to be complied with. That is not the same as saying NIS2 does not apply there. France is the clearest case in this group, where ANSSI is preparing the regime but the transposing law was still pending when the Commission referred the country, which is why France is on the list. Where transposition is complete the picture is concrete, as in Slovenia, which transposed through the Information Security Act (ZInfV-1), in force since 19 June 2025, with URSIV as competent authority and self-registration due by 19 December 2025. Read your own country’s implementing act for the thresholds and deadlines that actually bind you, not the directive alone.

Germany completed its transposition on 6 December 2025 with no transition period, and the German law adds a third entity tier plus a BSI registration duty on top of the EU test, which we cover in our guide to NIS2 in Germany.

Once You Are in Scope, the Registration Clock Is Already Running

If the two-part test puts you in scope, the next step is registration under your national regime, and the deadlines are already set. Confirming scope is the work that does not wait for anything else.

Run your own activity against the two halves first. Are you in an Annex I or II sector, and are you medium-sized or larger once linked and partner enterprises are counted. If both are yes, or if you fall into the size-blind category under Article 2(2) to 2(4), you are in scope and the question shifts from whether to when. Member states had to compile their lists of essential and important entities by 17 April 2025 under Article 3(3), and national self-registration windows have their own dates. Slovenia’s initial window for entities already in scope closed on 19 December 2025, and entities that meet the criteria later have 30 days from that point, so missing the date does not make the duty lapse. Yours will be in your implementing act.

If the test puts you in scope and the Article 21 workload is more than your team can absorb internally, our directory of vetted NIS2 compliance providers lists specialist firms across the EU, filterable by country, service type and company size.

The fastest way to settle the sector and size question without reading the annexes line by line is our NIS2 Applicability Checker. It walks the same test this piece describes and tells you which side of it you land on.

RegDossier

Making EU compliance almost enjoyable. Almost.

EU regulatory updates in your inbox every two weeks. Free.

Get the next briefing

Similar Posts