Guides

NIS2 Guide · 8 min

Who is in scope for NIS2? Essential vs important entities, sectors and size thresholds

NIS2 reaches far wider than the directive it replaced, but not to everyone. Whether it reaches you turns on three questions: what sector you're in, how big you are, and whether you fall under one of a handful of size-independent exceptions. This guide works through each test so you can place yourself, and then explains the quieter route in, the one that catches organisations no authority ever formally designated. The transposition deadline of 17 October 2024 has passed; Member States are now enforcing as they finish writing national law.

Key takeaways

  • NIS2 sorts the organisations it covers into essential and important entities, by sector (Annex I/II) and size.
  • You're generally in from 50 staff or €10M turnover/balance: plus a few exceptions that apply at any size.
  • Even undesignated, you can be pulled in: NIS2 customers push their obligations onto you through contracts.

Two categories: essential and important entities

NIS2 sorts the organisations it covers into two tiers. Both carry the same baseline of security and reporting duties: the tier doesn't change what you must do, only how closely you're watched and how large the fines can grow.

Essential entities

Large organisations in the highest-criticality sectors (Annex I), plus certain entities designated regardless of size. Subject to proactive (ex-ante) supervision: audits, inspections and information requests can occur without a prior incident.

Important entities

Most other in-scope organisations meeting the size threshold, including the Annex II sectors. Subject to reactive (ex-post) supervision: authorities act when there is evidence of non-compliance.

Which sectors are covered?

The covered sectors live in two annexes: Annex I for the sectors of highest criticality, Annex II for the other critical ones. If your core activity sits in either list and you clear the size threshold, you're very likely in.

Annex I: sectors of high criticality

  • Energy (electricity, oil, gas, district heating, hydrogen)
  • Transport (air, rail, water, road)
  • Banking and financial market infrastructure
  • Health (providers, EU reference labs, pharmaceuticals, medical devices)
  • Drinking water and waste water
  • Digital infrastructure (DNS, TLD registries, data centres, cloud, CDNs, trust services, electronic communications)
  • ICT service management, B2B (managed service and managed security providers)
  • Public administration (central and regional)
  • Space

Annex II: other critical sectors

  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing (medical devices, computers and electronics, machinery, motor vehicles, other transport equipment)
  • Digital providers (online marketplaces, search engines, social networking platforms)
  • Research organisations

The size threshold

Inside a covered sector, NIS2 generally bites only from a minimum size (the size-cap rule) and it weighs both headcount and money.

Large: generally 'essential' (Annex I)

At least 250 employees, or turnover above €50 million and balance-sheet total above €43 million. Large entities in Annex I sectors are typically classified as essential. Large entities in Annex II sectors remain important, not essential.

Medium-sized: generally 'important'

At least 50 employees, or annual turnover or balance-sheet total above €10 million. Reaching the medium-size threshold in a covered sector typically brings you in as an important entity.

Below the medium threshold, micro and small organisations are usually out of scope: unless a size-independent exception applies.

See how your suppliers actually score

7-day free trial · no credit card · cancel anytime

Size-independent exceptions: in scope regardless of size

Some entities are covered however small they are, because of the role they play rather than their headcount. Qualified trust service providers, top-level domain registries and DNS providers, providers of public electronic communications networks or services, and any organisation that is the sole provider of a service essential to a Member State's society or economy: all are in regardless of size.

Public administration bodies and organisations identified as critical under the Critical Entities Resilience (CER) Directive can also be in scope independently of size, and Member States may designate specific entities one by one. If you run critical infrastructure, or a service with no real substitute, check your national authority's designation list rather than leaning on the size test alone.

Not designated? You can still be pulled in through the supply chain

Even when NIS2 doesn't name you directly, it can still reach you through the customers who are named. In-scope organisations have to manage the cybersecurity risk of their suppliers (Art. 21(2)(d)), and in practice that means your customers (banks, hospitals, energy companies, public bodies) will increasingly make evidence of your security posture a condition of doing business.

So the question is rarely just 'am I designated?' It's also 'do my customers fall under NIS2?' If they do, their obligations flow down to you through contracts, questionnaires and continuous monitoring: whether or not you're formally an essential or important entity yourself.

What being in scope means in practice

If you are in scope, the core obligations are:

  • Risk-management measures: the Art. 21 baseline: risk analysis, incident handling, business continuity, supply-chain security, encryption, access control and more.
  • Incident reporting: an early warning to your national CSIRT within 24 hours of a significant incident, a fuller notification within 72 hours, and a final report within one month (Art. 23).
  • Governance and accountability: management bodies must approve and oversee the measures and can be held liable; staff training is expected.
  • Registration: many entities must register with their national authority, providing contact and sector details.

Essential and important entities meet the same baseline; the tier mainly affects how they are supervised and the maximum penalties that apply: up to €10 million or 2% of total worldwide annual turnover (whichever is higher) for essential entities, and up to €7 million or 1.4% for important entities (Art. 34). Management bodies must approve the measures and can be held personally liable (Art. 20).

Source: Directive (EU) 2022/2555 (NIS2), Articles 2–3 and Annexes I–II — consult your national transposition law and supervisory authority for the binding details in your country.

How norppa.io helps

Once you know your suppliers are in scope, or that your customers expect NIS2-grade assurance, norppa.io gives you the continuous evidence both directions need. Every monitored supplier domain is checked across more than a hundred control points daily, with the time-sensitive ones re-run every six hours, and each finding is mapped to the NIS2 article it answers to as it's recorded.

Self-assessment questionnaires go to suppliers straight from the portal and sit alongside the technical risk profile, so process evidence and technical evidence live in one place: ready for a customer's due diligence or a supervisory audit.

Not ready to start? Get your country's NIS2 status

We'll send your country's NIS2 transposition status (authority, national law, key dates) plus a concise supplier due-diligence checklist. One email, then occasional NIS2 updates.

We never share your email. Unsubscribe in one click. Stored in the EU.

See what NIS2-grade monitoring looks like

A sample supplier report (findings, NIS2 mapping and evidence) in about two minutes.

7-day free trial · no credit card · cancel anytime

Last reviewed: 19 June 2026

This guide is general information about EU law, not legal advice. NIS2 takes effect through each EU Member State's national transposition law, which can differ in detail. Verify the obligations that apply to you with your competent authority or legal counsel.

Related guides

How to comply with NIS2: a step-by-step roadmap

The steps to NIS2 compliance in order: confirm scope, register, management accountability (Art. 20), the Article 21(2) measures, supply-chain security, incident reporting (Art. 23) and continuous, evidenced assurance.

NIS2 for suppliers: you're not designated, but your customers are

Most companies are never designated under NIS2, yet many must comply anyway. How a covered customer's Article 21(2)(d) supply-chain duty flows down to you, what they'll ask for, and how to respond credibly.

NIS2 and the supply chain requirement: what it means in practice

NIS2 requires essential and important entities to assess their supply chain cyber risks. Supplier tiering, 4th-party risk, Art. 23 notification, and what auditors look for.

How a breach happens in 2026: your external surface and your supply chain

The 2026 attack chain step by step — stolen credentials, exploited edge devices, email spoofing — across both your own external surface and your suppliers', and where norppa.io breaks the chain.

Supplier cyber risk assessment: what automated NIS2 monitoring checks

All check categories explained: ransomware, dark web leaks, TLS/DNSSEC, cookie security, CVE/EPSS, sanctions, MX blacklists and SAQ. Finding lifecycle and NIS2 article mapping.

NIS2 Art. 21(2): supplier security checklist

Checklist for procurement and security teams: what to ask, what evidence to collect, and how to respond when a supplier falls short. Includes suggested evidence documents.

NIS2 supplier questionnaire (SAQ): what to ask, how to score it, and a free template

What to ask suppliers under Art. 21(2)(d), how to score answers and respond to gaps, why self-attestation needs verification, and a free copy-paste questionnaire template.

NIS2 incident reporting: the 24- and 72-hour deadlines explained

What counts as a significant incident, the Article 23 timeline (24-hour early warning, 72-hour notification, one-month final report), and when a supplier's incident becomes your obligation.

NIS2 and management responsibility: what boards and leadership must know

What NIS2 expects of the management body: approval and oversight duties, personal liability (Art. 20), training, board reporting KPIs, and the penalties under Art. 34.

ISO 27001 and NIS2: what your ISMS already covers, and the gaps it doesn't

If you hold ISO 27001, what carries over to NIS2 and what does not: statutory incident reporting, management liability, registration, and continuous supply-chain assurance: plus how to close the gap.

NIS2 fines and penalties: how much, who is liable, and how to avoid them

What NIS2 penalties are: the Article 34 caps (€10M / 2% for essential, €7M / 1.4% for important entities), the management body's personal liability (Art. 20, Art. 32), non-monetary enforcement, and how to avoid them with continuous, evidenced diligence.

NIS2 vs DORA: how they differ, where they overlap, and which one applies to you

How the two EU regimes differ and overlap, why DORA is lex specialis for financial entities, which applies to you, and what both mean for third-party and supply-chain risk.

GDPR vs NIS2: how they overlap, where they differ, and when one incident triggers both

How GDPR and NIS2 differ and overlap, when one incident triggers both (GDPR Art. 33 72h to the DPA vs NIS2 Art. 23 24h/72h/1-month to the CSIRT), the Art. 35 cooperation and no-double-fine rule, and what both mean for supplier due diligence.

The EU Cyber Resilience Act (CRA): scope, timeline and what it means for your supply chain

What the CRA requires, its phased dates (in force 2024, reporting Sept 2026, full compliance Dec 2027), who is in scope and why pure SaaS often isn't, how it complements NIS2, and what it means for procurement and supplier due diligence.

The EU AI Act: risk tiers, the timeline, and what deployers must do (Article 26)

What the EU AI Act requires: the risk tiers, the phased dates (in force 2024, prohibited Feb 2025, GPAI Aug 2025, high-risk Aug 2026), the Article 26 deployer obligations, how it stacks with NIS2 and the GDPR, and what it means for AI procurement.

NIS2 transposition status: which EU countries have it in force

Which of the 27 EU Member States have written NIS2 into national law and which are still finalising it, and why the gaps reach your supply chain regardless.

NIS2 supplier contract clauses: what to require from your suppliers

The contract clauses that turn NIS2's supply-chain duty into something enforceable: security baseline, incident-notification window, evidence and audit rights, subcontractor flow-down, and how to verify them continuously.

Your external security posture under NIS2: what suppliers and customers can see

The publicly visible signals customers assess under NIS2 Art. 21(2)(d): email spoofability (SPF/DMARC), certificate hygiene, internet-exposed systems and leaked credentials, why each matters and how to check and fix them.

Do your suppliers use AI? NIS2 supplier risk meets the EU AI Act

Suppliers increasingly embed AI in the services you depend on, and so do their suppliers. Where supplier and nth-party AI creates risk under NIS2 Art. 21(2)(d) and the EU AI Act, what to assess, and how to keep visibility.

Vendor impersonation and CEO-fraud (BEC): email spoofing, DMARC and NIS2

One of the most common supply-chain attacks needs no breach: spoofed email that redirects a payment or steals data. How BEC and vendor impersonation work, the SPF, DKIM and DMARC settings that stop them, and how it fits NIS2 Art. 21(2)(d).