NIS2 Applicability Checker

Whether NIS2 applies to your company comes down to two questions, your sector and your size, with a layer of exceptions where size does not count. Which EU member state you operate in then shapes how and when the obligations bite. The checker below works through the scope criteria in Article 2 of the NIS2 Directive (EU 2022/2555) and the sectors listed in Annexes I and II.

It takes about two minutes. Answer the questions and you get a clear in-scope or out-of-scope result, the entity classification that applies to you (essential or important), and the penalty ceiling that comes with it.

Built for compliance officers, risk managers and COOs at EU-based companies who need a documented starting point for a NIS2 assessment. This is not legal advice. For complex group structures or cross-border operations, verify the output with qualified legal counsel before relying on it for formal reporting.

How This Tool Works

The checker applies the scope criteria in Article 2 of NIS2, the sector definitions in Annex I and Annex II, and the size floor drawn from Recommendation 2003/361/EC, which sets the medium-enterprise threshold at 50 staff or the financial ceilings for turnover and balance sheet total. It also applies the size-independent categories in Article 2(2) to 2(4), which bring certain entities into scope regardless of headcount or revenue. Those include qualified trust service providers, top-level domain registries and DNS providers, sole providers of a service essential to a member state, entities whose disruption would carry significant cross-border risk, and critical entities designated under the CER Directive (EU) 2022/2557.

Two limits are worth stating plainly. The checker settles the sector and size question. It does not work out the jurisdiction and registration specifics that apply to DNS providers, TLD registries, cloud providers, data centres, CDNs and managed service providers under Articles 26 and 27, and where your organisation falls into one of those categories the result screen flags it and points you to the provision. Group structure is the other limit. Where linked or partner enterprises push a small company over the threshold on combined figures, confirm the calculation against the full scope explainer before treating an out-of-scope result as final.

A proposal to amend NIS2 is moving through the legislative process, published by the Commission on 20 January 2026 as COM(2026) 13 final. This tool reflects the directive as it stands. The proposed changes are covered in the FAQ below, and none of them are law yet.

Frequently Asked Questions

Does NIS2 apply to companies outside the EU?

Yes, in some cases. NIS2 reaches entities that provide covered services within the EU regardless of where they are established. For the digital categories named in Article 26(1)(b), such as DNS providers, cloud providers and online marketplaces, a company based outside the Union that offers those services inside it has to designate a representative in a member state where it operates, under Article 26. Simply selling goods into the Union is usually not enough on its own, because that is not one of the listed services. The market, not the head office, decides.

What is the difference between an essential entity and an important entity under NIS2?

The category follows from sector, size and in several cases activity type, not from sector alone. Large entities in Annex I sectors are essential. Medium entities in Annex I are important. Entities in Annex II are important whether they are medium or large. On top of that, Article 3(1) makes some entities essential regardless of size, including qualified trust service providers, TLD registries and DNS providers, medium-sized providers of public electronic communications, central government public administration entities, and CER critical entities. The substantive obligations under Article 21 are the same for both categories. The difference is supervision. Essential entities face proactive oversight and can be inspected without a prior incident. Important entities are supervised reactively, after an incident or complaint.

My company has fewer than 50 employees. Are we exempt?

Usually yes, but not always. The medium-enterprise floor in Article 2(1) leaves micro and small companies out as a rule. Two things override that. First, Article 2(2) to 2(4) lists categories in scope regardless of size, including sole providers of a service critical to a member state, entities whose disruption would carry significant cross-border effects, DNS providers, TLD registries and qualified trust service providers. Second, size is measured across the group. Under the Annex to Recommendation 2003/361/EC, linked and partner enterprises are aggregated, in full for linked enterprises and pro rata for partners, so a small subsidiary of a large group can clear the threshold on the group’s numbers even when its own payroll would keep it under.

Which sectors does NIS2 cover?

Annex I lists eleven high-criticality sectors: energy (electricity, oil, gas, hydrogen, district heating), transport (air, rail, water, road), banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure (internet exchange points, DNS providers, TLD registries, cloud providers, data centres, CDNs, trust service providers, public electronic communications networks), ICT service management (managed service providers, managed security service providers), public administration, and space.

Annex II lists seven other critical sectors: postal and courier services, waste management, manufacture and distribution of chemicals, food production and distribution, manufacturing (medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment), digital providers (online marketplaces, online search engines, social networking platforms), and research organisations.

What are the penalties if NIS2 applies and we are not compliant?

Essential entities face fines up to €10 million or 2% of global annual turnover, whichever is higher. Important entities face fines up to €7 million or 1.4% of global annual turnover, whichever is higher. Those figures in Article 34 are floors for the national maximum, so a member state can set higher ceilings when it transposes.

Personal liability is the part most boards miss. Under Article 20(1), the management body has to approve the cybersecurity risk measures and can be held liable for the entity’s failures. For essential entities, Article 32(5)(b) lets a competent authority ask a court to bar a chief executive or legal representative from management functions until the gaps are fixed. Several member states have added their own management liability provisions in transposition, so check the figure that applies in your jurisdiction.

When did NIS2 become law, and where does enforcement stand in 2026?

NIS2 entered into force on 16 January 2023, and the transposition deadline for member states was 17 October 2024. By mid-2026, 22 of the 27 member states had enacted national implementing legislation. France, Ireland, Luxembourg, the Netherlands and Spain were still completing the process, and on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for incomplete transposition, asking for a lump sum and daily penalties (we track the case in our note on the NIS2 court referral). The correct posture is to treat NIS2 as live and enforced rather than as something still being phased in. Our NIS2 transposition status for all 27 member states tracks the date each national law entered into force and how many days late each state was.

What is the January 2026 Commission proposal, and does it change my NIS2 status?

Not yet. On 20 January 2026 the Commission published COM(2026) 13 final, a targeted amendment to NIS2 within a wider cybersecurity package, aimed at clearer scope and simpler compliance. The Commission estimates it would ease compliance for 28,700 companies, including 6,200 micro and small enterprises.

The changes that touch scope are the ones to watch. The proposal would remove micro and small DNS providers through a size cap, remove chemical distributors while keeping chemical manufacturers in, add operators of submarine data cable infrastructure and European Digital Identity Wallet providers regardless of size, and create a lighter-touch “small mid-cap” category treated as important rather than essential. It also adds ransomware reporting detail under Article 23 and would require post-quantum cryptography migration in national strategies. The proposal is still in the legislative process, with adoption expected in late 2026 or 2027 and a transposition period to follow. Until then the current directive applies, which is what this checker reflects.

Does NIS2 replace GDPR for cybersecurity incidents?

No. The two run in parallel and cover different obligations. GDPR governs personal data and requires breach notification to the data protection authority within 72 hours. NIS2 governs network and information system security and requires, under Article 23, an early warning to the national CSIRT within 24 hours, an incident notification within 72 hours, and a final report within one month. Where an incident involves personal data, both sets of obligations apply at once.

We operate across several EU member states. Which authority do we report to?

As a rule, the authority in the member state where you are established. For DNS providers, TLD registries, cloud providers, data centres, CDNs, managed service providers, online marketplaces, search engines and social networking platforms, Article 26 sets the jurisdiction by main establishment, usually where the decisions on cyber risk measures are mainly taken.

A Confirmed Result Points Straight to Article 21

If the checker puts you in scope, the work starts with mapping your current security measures against the ten risk-management requirements in Article 21 of NIS2. Incident handling, supply chain risk and access control are where most mid-market organisations have the widest gaps. Where your member state has set a compliance or audit deadline, document what you have done and when, because supervisory authorities are moving from preparatory conversations to formal inspections. For the reasoning behind each question in the checker, read our full explainer on whether NIS2 applies to your company.

Making EU compliance almost enjoyable. Almost. EU regulatory updates in your inbox every two weeks. Free. Get the next briefing.

This tool provides general guidance based on NIS2 Directive (EU 2022/2555), Article 2 and Annexes I and II. It is not legal advice. Consult qualified legal counsel for your specific situation. Last verified: July 2026.

Not sure where your organisation stands on EU compliance more broadly? Take the free RegDossier AI Act Readiness Assessment to identify your highest-priority gaps across multiple regulations at once.

This tool provides general guidance based on NIS2 Directive (EU 2022/2555), Article 2 and Annexes I and II. It is not legal advice. Consult qualified legal counsel for your specific situation. Last verified: May 2026.