Whether a company falls under NIS2 is decided by three questions: is it of a type listed in the directive's annexes, is it large enough, and which Member State has jurisdiction over it? A fourth question — essential or important entity — decides how it is supervised and how high the fines can be. This guide takes the questions in that order, with the article of Directive (EU) 2022/2555 for each rule.
The guide is general information, not legal advice. The national transposition law of the country concerned decides the final position.
1. The sector test: Annexes I and II
Annex I — sectors of high criticality: energy (electricity, district heating and cooling, oil, gas, hydrogen); transport (air, rail, water, road); banking; financial market infrastructures; health; drinking water; waste water; digital infrastructure (internet exchange points, DNS service providers, top-level domain name registries, cloud computing, data centres, content delivery networks, trust service providers, public electronic communications networks and services); ICT service management business-to-business (managed service providers and managed security service providers); public administration; and space.
Annex II — other critical sectors: postal and courier services; waste management; manufacture, production and distribution of chemicals; production, processing and distribution of food; manufacturing of medical devices, computer, electronic and optical products, electrical equipment, machinery, motor vehicles and other transport equipment; digital providers (online marketplaces, online search engines and social networking platforms); and research organisations.
The annexes describe types of entity by activity, often by reference to other EU acts. A company that carries on a listed activity only as a side business may still be in scope; the analysis follows what the company actually does, not its name or its main registered activity code.
2. The size-cap rule
Under Article 2(1), NIS2 applies to entities of the listed types that qualify as medium-sized enterprises under Article 2 of the Annex to Commission Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises. Small and micro enterprises are, as a rule, outside the scope. In practice an entity is at least medium-sized if it has 50 or more employees, or if its annual turnover and its balance sheet total both exceed EUR 10 million. It exceeds the medium-sized ceilings — relevant for essential entities — with 250 or more employees, or with an annual turnover above EUR 50 million and a balance sheet total above EUR 43 million.
The Recommendation counts the figures of partner and linked enterprises as well (Articles 3 and 6 of its Annex). A company with 20 employees that belongs to a larger group can therefore be in scope. The directive's recitals allow the degree of independence of the entity's network and information systems from the rest of the group to be taken into account; how far this is used depends on the national authority.
3. Entities covered regardless of size
Article 2(2) to (4) covers some entities whatever their size, including:
- providers of public electronic communications networks or publicly available electronic communications services;
- trust service providers;
- top-level domain name registries and DNS service providers;
- the sole provider in a Member State of a service essential for critical societal or economic activities;
- entities whose disruption could significantly affect public safety, public security or public health, or induce a significant systemic risk;
- public administration entities of central government, and regional ones where the Member State so decides;
- entities identified as critical entities under Directive (EU) 2022/2557 (CER Directive);
- entities providing domain name registration services (for the purposes of Article 28).
4. Essential or important entity
Article 3(1) lists the essential entities, in particular: Annex I entities that exceed the ceilings for medium-sized enterprises; qualified trust service providers, top-level domain name registries and DNS service providers regardless of size; providers of public electronic communications networks or services that are medium-sized; central government public administration entities; critical entities under the CER Directive; and entities that a Member State identifies as essential. Every other Annex I or Annex II entity in scope is an important entity (Article 3(2)).
The obligations of Articles 20, 21 and 23 are the same for both categories. The difference is in supervision — proactive for essential entities (Article 32), reactive for important entities (Article 33) — and in the maximum fines (Article 34): at least EUR 10 million or 2% of worldwide annual turnover for essential entities, at least EUR 7 million or 1.4% for important entities. Typical example: a large Annex I energy company is essential; a medium-sized food producer (Annex II) is important.
5. Which Member State has jurisdiction
As a rule, an entity falls under the jurisdiction of the Member State in which it is established (Article 26(1)). There are exceptions: providers of public electronic communications networks or services fall under each Member State where they provide their services; DNS service providers, top-level domain registries, domain registration services, cloud, data centre and content delivery network providers, managed and managed security service providers and certain online platforms fall under the Member State of their main establishment in the Union. A company with subsidiaries in several countries usually deals with several national laws, one per subsidiary.
6. Registration and self-assessment
Member States had to draw up a list of essential and important entities by 17 April 2025 (Article 3(3)), largely from the entities' own registrations: name, address, contact details, IP ranges, sector and the Member States where they operate (Article 3(4)). NIS2 therefore expects companies to assess themselves: an authority will not necessarily tell a company that it is in scope, and failing to register does not take it out of scope.
Not in scope? Check your customers
A company below the threshold or outside the annexes can still be drawn into NIS2 by its customers, which must manage the security of their suppliers. See NIS2 supply chain requirements for suppliers.
nis2europe.eu, operated by AIPOS OÜ, offers a country-by-country route for companies in scope: each of its 24 country pages is in the local language and built on that country's transposition law — for example Poland, Netherlands, Latvia, Lithuania, Czechia, Romania and Denmark. All countries are listed on the page NIS2 compliance documentation.
Ready to start? Once you know your category, see what NIS2 requires and where the documentation is ordered. NIS2 compliance documentation.
Frequently asked questions
What is the size threshold of NIS2?
NIS2 applies to entities of the types listed in Annexes I and II that are at least medium-sized under Commission Recommendation 2003/361/EC: 50 or more employees, or an annual turnover and a balance sheet total each above EUR 10 million (Article 2(1)).
What is the difference between essential and important entities?
Essential entities (Article 3(1)) are mainly large entities in Annex I sectors and some entities regardless of size; they are supervised proactively (Article 32). Other covered entities are important entities (Article 3(2)), supervised after the fact (Article 33). The obligations are the same; supervision and maximum fines differ.
Which country's NIS2 law applies to my company?
As a rule, that of the Member State where the entity is established (Article 26(1)). Some digital providers fall under the Member State of their main establishment in the Union, and telecom providers under each Member State where they provide services.
Related guides
- What is NIS2? The EU cybersecurity directive explained
- NIS2 supply chain requirements for suppliers
- What happens without NIS2 compliance
More on this topic: NIS2 compliance documentation.