Am I in scope of NIS2? The three-question test
Sector, size, exceptions: three questions decide whether NIS2 applies to your company. And what to do when the honest answer is no.
The question almost always arrives the same way: a client, an insurer or an auditor says the word "NIS2", and nobody in the company can say with any certainty whether the text applies. What you find online does not help much, because a good share of it has a commercial interest in you answering yes.
The directive itself is far narrower than the noise around it. It defines its own scope in a single article, and that article reads like a three-question test: the sector, the size, and then the cases where size does not matter. Answer no to all three and you are not a regulated entity under the text — and that deserves to be said plainly, because it is true. It does not mean the subject will never reach you, and the fourth section of this article explains why.
The reference text is Directive (EU) 2022/2555 of 14 December 2022 "on measures for a high common level of cybersecurity across the Union", known as the NIS 2 Directive. That is the only source cited here for what EU law says. Everything to do with national transposition — registration, deadlines, supervision — belongs to your own Member State's authority, and this article points you there rather than inventing dates.
Question 1: is your activity listed in Annex I or Annex II?#
This is the first filter, and the most decisive one. Article 2(1) of the directive applies only to "public or private entities of a type referred to in Annex I or II". Those two annexes are a closed list: a company whose activity is not in them is outside the scope, whatever its size, whatever its turnover, and however dependent its customers may be on it.
Annex I is titled "Sectors of high criticality". It contains eleven sectors, several of them further split into subsectors.
| Sector (Annex I) | What the line covers, in short |
|---|---|
| Energy | Electricity, district heating and cooling, oil, gas, hydrogen |
| Transport | Air, rail, water, road |
| Banking | Credit institutions |
| Financial market infrastructures | Operators of trading venues, central counterparties |
| Health | Healthcare providers, EU reference laboratories, R&D of medicinal products, manufacture of basic pharmaceutical products, certain critical medical devices |
| Drinking water | Suppliers and distributors of water intended for human consumption |
| Waste water | Undertakings collecting, disposing of or treating urban, domestic or industrial waste water |
| Digital infrastructure | Internet Exchange Points, DNS service providers, TLD name registries, cloud computing, data centres, content delivery networks, trust service providers, public electronic communications networks and services |
| ICT service management (business-to-business) | Managed service providers (MSPs) and managed security service providers (MSSPs) |
| Public administration | Central government entities and, as defined by the Member State, regional-level entities |
| Space | Operators of ground-based infrastructure supporting the provision of space-based services |
Annex II is titled "Other critical sectors". It is shorter, and it is the one manufacturing companies most often forget to read.
| Sector (Annex II) | What the line covers, in short |
|---|---|
| Postal and courier services | Postal service providers, including providers of courier services |
| Waste management | Undertakings whose principal economic activity is waste management |
| Manufacture, production and distribution of chemicals | Manufacture and distribution of substances and mixtures, production of articles from them |
| Production, processing and distribution of food | Food businesses engaged in wholesale distribution and industrial production and processing |
| Manufacturing | Medical devices and in vitro diagnostic medical devices; computer, electronic and optical products; electrical equipment; machinery and equipment n.e.c.; motor vehicles, trailers and semi-trailers; other transport equipment |
| Digital providers | Online marketplaces, online search engines, social networking services platforms |
| Research | Research organisations |
Two reading cautions, before concluding too quickly in either direction. First: the sector is not enough — what governs is the type of entity named in the annexes' third column. Many lines refer to a precise definition set out in another EU instrument: a "credit institution" within the meaning of Regulation (EU) No 575/2013, a "healthcare provider" within the meaning of Directive 2011/24/EU, and so on. Being "in health" in the everyday sense does not automatically make you an entity of the type listed under Annex I's health sector.
Second: IT service providers are not a blind spot in the text. Under business-to-business ICT service management, Annex I explicitly names managed service providers and managed security service providers. An MSP or MSSP therefore answers yes to question 1. That does not make it regulated yet — question 2 is still to come.
Question 2: does your company meet the size thresholds?#
The second filter is cumulative with the first: you must be in an annex and reach a certain size. Article 2(1) states this condition by cross-reference: the directive applies to entities "which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article".
In other words: the entry threshold for NIS2 is not a figure written in the directive, it is the boundary between a small enterprise and a medium-sized one under the European SME definition. In practice that comes down to at least 50 employees, or more than EUR 10 million in both turnover and annual balance sheet total. Below that, the entity stays outside the direct scope — apart from the exceptions, which are the subject of question 3.
| Category (Recommendation 2003/361/EC) | Headcount | Position under NIS2 |
|---|---|---|
| Microenterprise | Fewer than 10 persons | Out of scope, unless an Article 2 exception applies |
| Small enterprise | Fewer than 50 persons | Out of scope, unless an Article 2 exception applies |
| Medium-sized enterprise | Fewer than 250 persons | In scope if the sector matches |
| Large enterprise | 250 persons or more | In scope if the sector matches |
Headcount alone does not settle it: an enterprise with fewer than 50 persons is still medium-sized, and therefore in scope, if its turnover and its balance sheet total both exceed EUR 10 million.
Three things happen in the detail of the calculation, and they are what tips the borderline cases.
First, the calculation does not necessarily cover only the legal entity you have in mind. The Recommendation provides that the data of an enterprise having partner or linked enterprises are determined on the basis of consolidated accounts, or by adding the data of the enterprises situated immediately upstream or downstream. A 30-person subsidiary inside a 400-person group does not count as a 30-person enterprise.
Second, the directive expressly disapplies one rule of the Recommendation: Article 2(1) states that Article 3(4) of the Annex to Recommendation 2003/361/EC does not apply for the purposes of NIS2. That rule is the one which normally prevents an enterprise from being treated as an SME where 25 % or more of its capital or voting rights are controlled by public bodies. The consequence is technical but real: a publicly-owned entity is not mechanically treated as a large enterprise for the NIS2 size test.
Third, the directive sets a floor, not a ceiling. Article 5 states that it "shall not preclude Member States from adopting or maintaining provisions ensuring a higher level of cybersecurity", and Article 2(5) explicitly allows a Member State to extend the directive to local public administration entities and to education institutions. The European calculation gives you a solid answer; it does not give you the final one. That belongs to national law, and to the authority applying it.
Am I an "essential entity" or an "important entity"?#
This is the question that follows immediately from a yes to the first two, and it is dealt with in Article 3, not Article 2. The distinction does not change the risk-management measures to be implemented — they are the same — but it changes the supervisory regime the entity is subject to.
| Category | Who is in it, in broad terms |
|---|---|
| Essential entity | Entities of a type referred to in Annex I which exceed the medium-sized enterprise ceilings; qualified trust service providers, TLD name registries and DNS service providers regardless of size; certain providers of public electronic communications networks and services; central government entities; entities identified as critical entities under Directive (EU) 2022/2557; entities a Member State designates as essential under the Article 2 exceptions |
| Important entity | Entities of a type referred to in Annex I or II which are not essential — including those a Member State designates as important under the same exceptions |
The useful reading of that table fits in one sentence: "important entity" is not a second-tier category that can be dealt with later. It is the default category for everything that enters the scope without being essential, and it is far more populated than the other one.
One point is worth noting in passing, because it bears directly on IT service providers: an MSP with at least 250 people falls under Annex I and exceeds the medium-sized ceilings, which makes it an essential entity. An 80-person MSP is in scope too, but as an important entity. The line between the two is not drawn on the perceived criticality of the service delivered — it is drawn on size.
Question 3: do you fall under one of the size exceptions?#
Article 2(2) opens a series of cases where the directive applies "regardless of their size". These cases do not create new sectors: they apply to entities already listed in Annex I or II which would otherwise have dropped out on the thresholds alone. This is the filter very small organisations forget to check, when it is precisely the one aimed at them.
| Case provided for by the directive | What it covers |
|---|---|
| Article 2(2)(a) | Providers of public electronic communications networks or of publicly available electronic communications services; trust service providers; TLD name registries and DNS service providers |
| Article 2(2)(b) | The entity is the sole provider in a Member State of a service essential for the maintenance of critical societal or economic activities |
| Article 2(2)(c) | Disruption of the service could have a significant impact on public safety, public security or public health |
| Article 2(2)(d) | Disruption of the service could induce a significant systemic risk, in particular where it could have a cross-border impact |
| Article 2(2)(e) | The entity is critical because of its specific importance at national or regional level for the sector or for other interdependent sectors |
| Article 2(2)(f) | Public administration entities of central government, and certain entities at regional level |
| Article 2(3) | Entities identified as critical entities under Directive (EU) 2022/2557 |
| Article 2(4) | Entities providing domain name registration services |
Points (b) to (e) share a characteristic you have to understand in order not to get this wrong: they are not boxes you tick yourself. They are criteria on the basis of which a Member State identifies entities and puts them on its list. You do not become "the sole provider in a Member State" because you are convinced you are; you become it because the competent authority has identified you as such. If one of those cases looks plausible for you, the right move is neither to ignore it nor to self-declare — it is to ask the national authority.
The cases in Article 2(2)(a), (3) and (4) work differently: they depend on an objective qualification — operating a public network, being a trust service provider, providing domain name registration services — and not on a discretionary decision. If you are in one of them, the size question simply does not arise.
What if none of the three applies to me?#
Then you are not a regulated entity under NIS2, and nobody should tell you otherwise. That is the case for most small IT agencies and managed service providers: the sector is indeed the one in Annex I, but the Article 2 thresholds leave them outside the direct scope.
And yet the supplier security questionnaire will arrive all the same. Not by mistake, and not out of over-zealousness: through the supply chain. Article 21 of the directive requires regulated entities to treat supply chain security as a risk-management area in its own right, taking into account the vulnerabilities specific to each direct supplier and the quality of their cybersecurity practices. An IT provider, holding administrator access to its client's infrastructure, is exactly the supplier that obligation has in mind.
This is a distinction, not a turn of phrase. Your client is not asking you to comply with NIS2 — the directive is not addressed to you. It is asking you to give it evidence that you will not be the weak link its own compliance depends on. The full mechanism, and what regulated clients concretely ask for, are covered in a dedicated article on the supply chain.
The practical consequence is uncomfortable for anyone hoping for a liberating "no": answering no to all three questions exempts you from regulatory obligations, not from client questions. And in the field, the second category arrives earlier than the first.
Where do I check officially whether I am in scope?#
With the national authority, and nowhere else. The directive sets a European framework, but it is national law that transposes it, establishes the list of essential and important entities, and organises registration. Two identical companies in two Member States can face different arrangements, because Article 5 lets each State go beyond the European floor.
The European Commission maintains an overview of the directive and of the transposition state of play on its NIS2 Directive policy page, which is the right place to start when you need to identify the competent authority in a given country. From there, it is that authority — not a vendor's blog post — that is authoritative on the national timetable, the registration route and the criteria retained. This article does not replace those sources and does not summarise them, because national detail moves and a date copied into a blog post ages badly.
One methodological point, before you set off: document your reasoning as you do it. The sector you settled on, the type of entity in the annex you attach yourself to or not, the headcount and figures used, the date of the calculation. A conclusion of "we are not in scope" with no trace of the reasoning behind it is very hard to defend two years later in front of a client, an insurer or an acquirer — and it has to be redone from scratch every time somebody asks the question again.
What do I do with the answer, either way?#
The work to be done is surprisingly similar on both sides of the line, and that is what makes the scope question less dramatic than it looks.
If you are in scope, the answer is structured by the text: risk-management measures, incident reporting obligations, management-body accountability, supervision by the national authority. The guide for IT service providers sets out those obligations and the deadlines attached to them.
If you are outside it, the answer is structured by your clients, and it needs the same foundation: knowing where you stand, being able to prove it, and being able to prove it again in six months. That is exactly the subject of proving compliance over time — a state observed on one date is only worth something if it is kept current, and a missing reading is an absence of evidence, not favourable evidence.
In both cases, the reasonable starting point is a maturity assessment of your own organisation rather than a compliance project. The 42 cyber hygiene measures published by ANSSI are a free, public baseline, and the ReCyF framework gives that assessment a structure by objective, reusable from one client to the next and from one year to the next.
Vigicap runs that assessment — the same objectives you put your clients through, applied this time to your own organisation, during the free trial.
Read next
NIS2: how supply chain rules reach you anyway
Your firm is below the NIS2 size thresholds, but your regulated clients still ask you for evidence. Here is why, and what they expect.
NIS2: a guide for IT service providers
Who NIS2 covers, what it concretely requires, the incident notification deadlines — and how an IT service provider turns all of it into an offer.
ReCyF, NIS2, ISO 27001: the mapping table
ReCyF's 20 objectives mapped to NIS2 Article 21 and to ISO/IEC 27001:2022 controls — and what such a mapping does and does not tell you.