NIS2
Does NIS2 apply to my company? A five-minute check
Updated September 26, 2026
The NIS2 Directive (EU) 2022/2555 widened EU cybersecurity law from a few hundred operators per country to thousands of ordinary companies. Whether it applies to yours comes down to three questions.
1. Is your main activity in a listed sector?
Annex I lists sectors of high criticality; Annex II lists other critical sectors.
- Annex I: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure (cloud, data centres, CDNs, DNS, IXPs, telecoms, trust services), managed IT and managed security services for businesses, public administration and space.
- Annex II: postal and courier services, waste management, chemicals, food production and distribution, manufacturing of medical devices, electronics, electrical equipment, machinery and vehicles, online marketplaces, search engines and social networks, and research organisations.
2. Are you at least a medium-sized enterprise?
The Directive covers entities in those sectors that are medium-sized or larger under the EU definition: 50 or more staff, or annual turnover and balance sheet total both above €10 million (Art. 2(1)). Small and micro enterprises are generally out of scope.
3. Are you one of the exceptions that apply regardless of size?
- Providers of public electronic communications networks or services.
- Trust service providers, TLD registries, DNS service providers and domain registrars.
- The sole provider in a member state of a service essential to society or the economy, or an entity the authority designates as critical.
- Public administration bodies, depending on national rules.
Essential or important?
Large entities in Annex I sectors, and some size-independent ones such as qualified trust service providers and DNS providers, are essential entities (Art. 3(1)). Most others in scope are important entities (Art. 3(2)).
The difference matters for supervision and fines: essential entities can be audited proactively and face maximum fines of at least €10 million or 2% of worldwide turnover; important entities are supervised after the fact and face maximum fines of at least €7 million or 1.4% (Arts. 32-34).
Out of scope does not mean off the hook
Organisations in scope must manage the security of their direct suppliers (Art. 21(2)(d)). If you sell IT, software or services to a company in scope, expect security questionnaires and contract clauses even if the law does not name you.
Our free NIS2 assessment starts with this scope check, then scores your readiness against each of the ten minimum measures.
Where does your company stand on NIS2?
Free assessment, about 10 minutes, score for every area of the law.
Start the free assessmentThis guide is general information, not legal advice.