NIS2 Scoring
EUEuropean Union · English
a service bySightadel

NIS2 guide

Is your organisation in scope of NIS2?

Two questions decide whether NIS2 applies to you: does your activity fall under a sector in Annex I or II of the directive, and do you reach the size threshold? For some types of entity, size does not matter at all. This page walks through the test as the directive sets it out.

Last updated: October 2026 · Legal basis: Directive (EU) 2022/2555 (NIS2); details depend on national law

NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. As a directive, it does not bind organisations directly. Each Member State had to transpose it into national law by 17 October 2024 and apply those rules from 18 October 2024 (Art. 41(1)). Many did so late, and some still have not. Your actual obligations therefore come from the national law of the Member State that has jurisdiction over you.

The directive sets the common framework that all national laws share: the sectors, the size thresholds, the two categories of entity, the minimum security measures, the reporting stages and the minimum fine ceilings. National laws may go further, for example by adding sectors or covering more public bodies. They may not fall below the directive. Which countries have adopted a law, and since when, is shown in our transposition overview.

Important: If your country has its own version on this site, use it. It reflects the national law, authority and deadlines. Country versions exist for Germany, Austria, the Netherlands, Belgium, Luxembourg, Italy and Portugal; France and Spain are in preparation. This EU version is meant for readers in other Member States, such as Ireland, Malta, the Nordic countries or Central and Eastern Europe, and for groups operating in several countries. Ireland has not yet transposed NIS2: only the General Scheme of the National Cyber Security Bill 2024 has been published.

Step 1: Is your activity in a covered sector?

The directive lists 18 sectors in two annexes. Annex I covers sectors of high criticality: energy (electricity, district heating and cooling, oil, gas, hydrogen), transport (air, rail, water, road), banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration and space.

Annex II covers other critical sectors: postal and courier services, waste management, the manufacture, production and distribution of chemicals, the production, processing and distribution of food, manufacturing (medical devices, computer and electronic products, electrical equipment, machinery, motor vehicles, other transport equipment), digital providers (online marketplaces, online search engines, social networking platforms) and research organisations.

What counts is the activity you actually carry out, not the name of your company or the code in your company register. A machinery manufacturer that also runs a large data centre for third parties may fall under two sectors. Annexes I and II define many sub-sectors by reference to other EU acts, such as the electricity market rules or the medical devices regulation, so check the precise definition before you rule yourself out.

Step 2: Do you reach the size threshold?

As a rule, NIS2 covers entities that are at least medium-sized under Commission Recommendation 2003/361/EC (Art. 2(1)). In practice:

SizeEmployeesFinancial threshold
Medium-sized50 to 249or annual turnover above €10 million and balance sheet total above €10 million
Large250 or moreor annual turnover above €50 million and balance sheet total above €43 million

The recommendation also counts staff and figures of partner and linked enterprises. A small subsidiary of a large group can therefore count as large. The directive allows Member States some leeway for disproportionate results where an entity is independent of its group in its network and information systems, and several national laws use it. Check how your national law treats group structures before you rely on the figures of a single legal entity.

Entities covered regardless of size

Some entities fall under NIS2 whatever their size (Art. 2(2) to (4)). They include:

  • providers of public electronic communications networks or publicly available electronic communications services,
  • trust service providers,
  • top-level domain name registries and DNS service providers,
  • the sole provider in a Member State of a service essential for critical societal or economic activities,
  • entities whose disruption could significantly affect public safety, public security or public health, or cause significant systemic risk,
  • entities identified as critical entities under the CER Directive (EU) 2022/2557,
  • public administration entities of central government, and regional ones according to national rules,
  • entities providing domain name registration services, for the purposes of Article 28.

Member States may also cover public administration at local level and education institutions (Art. 2(5)). Whether they do so differs widely from one country to the next.

Essential or important entity

NIS2 distinguishes two categories (Art. 3). Essential entities include large entities in Annex I sectors, qualified trust service providers, TLD name registries and DNS service providers regardless of size, medium-sized or larger providers of public electronic communications, public administration entities of central government, critical entities under the CER Directive and any further entities a Member State designates. All other in-scope entities from Annex I or II are important entities. In practice this means medium-sized Annex I entities and medium-sized and large Annex II entities.

Both categories have the same core duties: risk-management measures under Article 21, incident reporting under Article 23 and the duties of the management body under Article 20. The differences lie in supervision and fines. Essential entities are subject to proactive supervision, important entities to supervision after the fact (Art. 32 and 33). The minimum fine ceilings differ as well; see the page on fines and supervision.

Special cases and what to document

Financial entities covered by the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) apply DORA instead of the NIS2 rules on risk management and incident reporting, as DORA is a sector-specific act within the meaning of Article 4 NIS2. Similar rules may apply in other sectors with equivalent EU legislation.

For groups active in several Member States, jurisdiction matters. As a rule, an entity falls under the jurisdiction of the Member State in which it is established (Art. 26(1)). Certain digital providers, such as DNS service providers, cloud and data centre providers, managed service providers and online marketplaces, fall under the Member State of their main establishment in the Union. If you have subsidiaries in several countries, each may have to register under a different national law.

Whatever the outcome, document your assessment: the sectors you checked, the figures you used, the group structure and the result. If an authority asks why you did not register, a written assessment shows that you looked at the question seriously. Our NIS2 scoring gives you a first classification in a few minutes. Several authorities offer their own scope tools as well, which are listed in the transposition overview where known.

Frequently asked questions

Does NIS2 apply directly to my company?

No. NIS2 is a directive. Your obligations come from the national law that transposes it in the Member State with jurisdiction over you. Where no law has been adopted yet, the directive shows what to expect.

We have 40 employees. Are we out of scope?

Not necessarily. Turnover and balance sheet total also count, as do partner and linked enterprises in your group. Some entities, such as DNS service providers or trust service providers, are covered regardless of size (Art. 2(2)).

What is the difference between essential and important entities?

Both have the same core duties. Essential entities face proactive supervision and a higher minimum fine ceiling of €10 million or 2% of worldwide turnover; important entities face supervision after the fact and a ceiling of at least €7 million or 1.4%.

We are a bank. Does NIS2 apply?

For risk management and incident reporting, DORA largely takes precedence for financial entities. Check your national law for any remaining NIS2 duties, such as registration.