Last updated: 2026-08-03 · Jurisdiction: European Union (Directive (EU) 2022/2555, as transposed by each Member State)
Do I fall under NIS 2?
NIS 2 is the EU's second Network and Information Security Directive. It decides which organisations must run cybersecurity risk management and report significant incidents, and which Member-State authority will supervise them. This page is a vendor-neutral decision method for the applicability question: not a product pitch, and not a substitute for your competent authority or counsel. Where a step is faster as a form, we link our free interactive checker.
The short version
You are in the conversation if you provide services or carry out activities in the EU and your activity sits in Annex I or Annex II (or you are a size-independent special type such as a DNS provider, trust service, or public electronic communications provider). Size is measured with the SME ceilings in Recommendation 2003/361/EC: the default gate is at least medium-sized, using group figures where you are part of a group. Those in-scope entities are then essential or important under Article 3. The cybersecurity measures in Article 21 apply to both of those classes; the supervision model differs. Domain name registration services under Article 2(4) are a separate branch (mainly Article 28 duties), not an automatic essential/important label. Finally, read the national transposition law of your Member State: the directive sets the floor, national law is what binds.
What “do I fall under NIS 2?” actually asks
People usually mean three different things at once, and collapsing them produces bad answers.
- Direct legal scope. Does Directive (EU) 2022/2555, as transposed by your Member State, put duties on your organisation: as an essential or important entity under Articles 2 and 3 (risk management and incident reporting), or under a narrower branch such as Article 2(4) domain name registration services (mainly Article 28 duties)? That is the question this guide answers.
- Contractual flow-down. Even when you are out of direct scope, Article 21(2)(d) requires in-scope entities to address supply-chain security, and Recital 85 encourages contractual security measures with direct suppliers. That can create commercial requirements without making the supplier an essential or important entity.
- Overlap with sibling regimes. For many banks and other financial entities, DORA is the sector-specific act. Under NIS 2 Article 4, where a sector-specific Union act imposes equivalent cybersecurity risk-management and incident-notification duties, the matching NIS 2 provisions (including Articles 21 and 23, and the related supervision and enforcement rules) do not apply; DORA Article 1(2) is the usual expression of that lex specialis for the financial sector. Other critical entities may sit under the CER Directive; product cybersecurity can sit under the Cyber Resilience Act. Always open the sector-specific playbook first when one exists.
This guide stays on question one. It paraphrases the structure of Articles 2 and 3 and the SME recommendation NIS 2 points to. It does not reproduce official titles of standards or normative text from ISO or other standards bodies, and it is not legal advice.
The size gate, with the dual-ceiling rule most summaries skip
NIS 2 does not invent its own headcount table. Where size matters, it uses the SME definition in Commission Recommendation 2003/361/EC. Two mechanics matter more than the round numbers.
- Staff is a hard ceiling. Cross the staff threshold and you leave the band, even if turnover is tiny.
- Finance is either/or. Inside a band, the enterprise meets the financial side if either annual turnover or annual balance-sheet total stays under the ceiling. It does not need both.
- Group figures. When the entity is part of a larger enterprise group, apply the ceilings at group level in the usual case, not to the single local company number.
| Band | Staff | Financial ceilings | NIS 2 default effect |
|---|---|---|---|
| Small (and micro) | Fewer than 50 staff | AND (turnover ≤ EUR 10M or balance sheet ≤ EUR 10M). Leave this band if staff ≥ 50, or if both financial ceilings are exceeded | Generally out of the default size gate, unless a size-independent special type or Member-State judgement applies |
| Medium | Not large, and not small (see left) | Either staff ≥ 50 with finance still below the large ceiling, or staff < 50 but both turnover > EUR 10M and balance sheet > EUR 10M, while still below large | In scope if the activity is in Annex I or II (typically as an important entity, subject to Article 3 overrides) |
| Large | 250 or more staff, or | Turnover > EUR 50M and balance sheet > EUR 43M (either the staff ceiling or both financial ceilings) | In scope if the activity is in Annex I or II (Annex I large entities are typically essential) |
Version and jurisdiction stamp: size bands above paraphrase Commission Recommendation 2003/361/EC as used by Directive (EU) 2022/2555 as currently enacted. They are the EU baseline; a Member State's transposition act can extend who is covered. SME status under the Recommendation generally flips only after two consecutive accounting periods on the wrong side of a ceiling. Checked 2026-08-03. A Commission proposal of 20 January 2026 (COM(2026) 13) would amend parts of the NIS 2 applicability perimeter if adopted; it is not used in this assessment while it remains pending.
How to decide, step by step
- 1
Confirm you provide services or carry out activities in the EU
The first filter is territorial. NIS 2 reaches entities that provide services or carry out activities within the Union, not only entities that are incorporated there. A US-headquartered cloud provider with EU customers can be in scope; a purely non-EU company with no EU activity is not, on the directive's own terms. Even then, two caveats remain: national transposition can draw a slightly different perimeter, and in-scope customers routinely push NIS 2-aligned security and incident clauses down the supply chain by contract.
- 2
Match your activity to Annex I or Annex II
The directive does not regulate every company. It regulates entities whose activity sits in one of the sector lists. Annex I (sectors of high criticality) covers energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management offered B2B (managed and managed-security service providers), public administration, and space. Annex II (other critical sectors) covers postal and courier services; waste management where that is the undertaking's principal economic activity; manufacture, production and distribution of chemicals; food wholesale distribution and industrial production or processing; certain manufacturing (medical devices, computers and electronics, electrical equipment, machinery, motor vehicles, other transport equipment); digital providers (online marketplaces, online search engines, social networking platforms); and research organisations that primarily conduct applied research or experimental development with a view to commercial exploitation (educational institutions are out of that definition). If neither annex fits and you are not one of the size-independent special entity types in the next step, direct scope is unlikely. Borderline sector questions (for example, whether a niche SaaS is “cloud computing” under digital infrastructure) are facts your counsel and competent authority settle, not a checklist alone.
- 3
Check the size-independent special entity types first
Size is the usual gate, but it is not the only gate. Under Article 2(2)(a), certain digital-infrastructure and trust-service roles are in scope regardless of size: TLD name registries, DNS service providers, and trust service providers (qualified and non-qualified). Providers of public electronic communications networks or publicly available electronic communications services sit here too. Those Article 2(2)(a) types also feed the essential/important classification under Article 3. Separately, Article 2(4) brings providers of domain name registration services into the directive regardless of size (a registrar or privacy/proxy service can hit 2(4) without being a TLD registry or DNS provider). That is a different branch: Article 2(4) exists mainly so the registration-database and WHOIS-style duties in Article 28 apply, and it does notby itself make the provider an essential or important entity under Article 3, so the Article 21 risk-management catalogue does not automatically follow from 2(4) alone. Public administration entities under Article 2(2)(f), critical entities identified under the CER Directive (EU) 2022/2557, legacy operators of essential services retained under Article 3(1)(g), and express Member-State designations also override a simple size test. Run these checks before you conclude that “we are too small.”
- 4
Apply the SME size thresholds (Recommendation 2003/361/EC)
For entities that are in an Annex sector and are not a special type, the default rule is that NIS 2 reaches at least medium-sized enterprises. Size is measured with the SME definition in Commission Recommendation 2003/361/EC, which NIS 2 points to rather than inventing its own thresholds. Three details trip people up. First, staff is a hard ceiling, while the financial ceilings work as an either/or: an enterprise meets the financial side of a band if either its turnover orits balance-sheet total stays under the ceiling. Second, size aggregation follows Recommendation 2003/361/EC Articles 3 and 6: use the entity's own data if it is autonomous; add partner enterprises proportionally; add 100% of linked enterprises. A 30-person EU sales entity under a 400-person linked parent is not treated as small on its own numbers alone. NIS 2 Recital 16 also lets Member States disregard partner or linked enterprises where the entity is operationally independent, so confirm the national rule. Third, SME status under the Recommendation generally changes only when a ceiling is exceeded (or no longer exceeded) over two consecutive accounting periods, so a one-year spike does not always flip the band overnight.
- 5
Classify essential versus important under Article 3
For entities that reach the directive through Article 2(1) or 2(2) (or another firm basis that feeds Article 3), Article 3 sorts them into essential or important. The rough pattern is: large entities in Annex I sectors are essential; medium entities and Annex II entities are important. Article 3 then lists overrides that a simple “Annex times size” table misses: qualified trust service providers, TLD name registries and DNS service providers are essential at any size; providers of public electronic communications networks or services that qualify as medium-sized are essential under Article 3(1)(c) (and large ones under Article 3(1)(a)); central public administration is essential; critical entities under the CER Directive and certain retained legacy operators of essential services are essential; and a Member State can designate an entity either way. The cybersecurity risk-management measures in Article 21 and the incident-reporting architecture in Article 23 apply to essential and important entities. Do not collapse every “in scope of the directive” result into that pair: a provider that stands only on Article 2(4) (domain name registration services) is mainly under the Article 28 registration-database duties and is not automatically essential or important. Between essential and important, the practical difference is supervision intensity: more proactive, ex-ante supervision for essential entities; more reactive, ex-post supervision for important entities.
- 6
Confirm against your Member State's transposition law
NIS 2 is a directive, not a regulation. The directive sets the EU floor; the binding obligations for an organisation come from the national transposition law of the Member State where it is mainly established or provides the service. The EU deadline to transpose was 17 October 2024. Several Member States missed it. The Commission issued formal notices, reasoned opinions, and in July 2026 referred some states to the Court of Justice of the EU. National laws can also extend the EU baseline (additional sectors, tighter size rules, earlier registration). So the last step is always: open the national act and the competent authority page for your Member State, not only the English directive text. Our NIS 2 transposition tracker lists all 27 states with a dated source per row; the free checker surfaces the same note for the country you pick.
Run the same test as a free interactive check
The free NIS 2 applicability checker asks the sector, size, special entity and Member-State questions and returns a structured assessment with reasons and the transposition note for the country you pick. Use this guide for the long-form legal structure (including the Article 2(4) domain-registration branch and the DORA lex specialis note); use the checker to run the interactive path. Both are starting points, not binding determinations. The checker runs in your browser and stores nothing.
Six mistakes that produce the wrong answer
Treating the directive text as the only law that binds you
NIS 2 is a directive. Your obligations come from the national transposition act of the Member State that has jurisdiction over you. The English EUR-Lex text is the EU floor, not the last word.
Using the subsidiary's headcount when you are part of a group
The SME recommendation is applied at group level in the usual case. A 40-person local entity under a 500-person parent is not small for NIS 2 size purposes.
Stopping at size and ignoring special entity types
DNS providers, TLD registries, trust services and public electronic communications providers can be in scope at any size and feed essential/important classification. Domain name registration services under Article 2(4) are a separate size-independent branch (mainly Article 28). Size is the default gate, not the only gate.
Assuming essential and important mean different security controls
Article 21 risk-management measures apply to both essential and important entities. The practical split is mainly supervision intensity (ex-ante for essential, ex-post for important) and how enforcement is structured, not a lighter control catalogue for important entities. Do not confuse that pair with the separate Article 2(4) domain-registration branch, which is mainly about Article 28 duties.
Ignoring DORA when you are a financial entity
For many credit institutions and other DORA-covered financial entities, DORA is the sector-specific act. NIS 2 Article 4 then displaces the equivalent NIS 2 risk-management, reporting, supervision and enforcement provisions. Opening only the NIS 2 Article 21 playbook is the wrong first move.
Ignoring contractual flow-down when you are out of direct scope
Even a genuine out-of-scope supplier often faces NIS 2-aligned security, audit and incident clauses from in-scope customers. Direct scope and commercial scope are not the same question.
Where this page sits in the NIS 2 cluster
| Surface | Job | Format |
|---|---|---|
| This guide | Explain the applicability test so a person (or an AI answer) can follow the legal structure | Long-form how-to |
| NIS 2 applicability checker | Run the same rules as an interactive questionnaire | Free tool |
| NIS 2 transposition tracker | Show which Member States have a national law in force | Reference dataset |
| NIS 2 framework page | Product-oriented overview of working under NIS 2 with ISMS Copilot | Framework hub |
Browse the full set of free compliance tools, including the DORA and Cyber Resilience Act applicability checkers when your sector sits next to those regimes.
Frequently asked questions
Do I fall under NIS 2 if I am a small SaaS company?
Usually only if you match an Annex I or II activity and clear the medium-size threshold (or a size-independent special type). A small pure software vendor that is not cloud infrastructure, not a managed service provider, not a digital provider listed in Annex II, and not a special entity type is often out of direct scope. Even then, large customers may still require NIS 2-aligned controls by contract, and national law can extend the perimeter. Run the sector and special-entity checks before assuming size alone saves you.
What is the difference between an essential and an important entity?
Both classes must implement the cybersecurity risk-management measures in Article 21 and the incident-reporting duties that national law transposes from Article 23. The main difference is how they are supervised: essential entities face more proactive, ex-ante supervision; important entities face more reactive, ex-post supervision. Classification follows Article 3 (Annex membership, size, and specific overrides such as DNS providers, trust services, public administration, CER critical entities, and Member-State designation). A provider that is in the directive only under Article 2(4) as a domain name registration service is not automatically essential or important; that branch is mainly about Article 28 duties.
I am a bank under DORA. Do I still follow NIS 2 Articles 21 and 23?
For financial entities that are covered by DORA (Regulation (EU) 2022/2554) and that would otherwise be essential or important under NIS 2, DORA is the sector-specific act. NIS 2 Article 4 provides that where a sector-specific Union legal act requires cybersecurity risk-management measures or significant-incident notification that are at least equivalent in effect, the matching NIS 2 provisions (including the related supervision and enforcement rules) do not apply; DORA Article 1(2) expresses that relationship for the financial sector. Open the DORA playbook for those equivalent duties. Confirm coverage against both acts and your competent authority; not every firm that touches finance is a DORA financial entity.
Does NIS 2 apply if we are headquartered outside the EU?
Headquarters alone does not decide it. The directive reaches entities that provide services or carry out activities within the Union, regardless of where they are established. A non-EU headquartered provider with real EU operations can be in scope; a company with no EU activity is not on the directive's own terms. National transposition and contractual flow-downs can still create duties even when direct scope is unclear.
Is this guide legal advice?
No. It is educational content that paraphrases the structure of Directive (EU) 2022/2555 and the SME recommendation it points to. Applicability is fact-specific, several Article 2(2) bases involve a Member-State judgement, and only your competent national authority or counsel can give a binding view. Use the free checker for a structured starting point, then confirm against the national act.
How is this different from the free NIS 2 applicability checker?
This page is the long-form decision method: the legal tests, the size dual-ceiling rule, the essential versus important split, and the national-law step, written so a person or an AI answer can cite the structure. The free checker at /resources/nis-2-applicability-checker is the interactive form of the same rules: answer the questions and get a structured verdict (essential, important, or likely out of scope) with reasons. Use the guide to understand the test; use the checker to run it.
Primary sources
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), Articles 2, 3, 4, 21, 23, 26 and 28 and Annexes I and II (scope, essential/important classification, sector-specific lex specialis, risk management, incident reporting, jurisdiction, domain registration). eur-lex.europa.eu (checked 2026-08-03).
- Commission Recommendation 2003/361/EC of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (SME staff and financial ceilings, autonomous/partner/linked aggregation, and the two-consecutive-accounting-period rule that NIS 2 uses for the medium/large size gate). eur-lex.europa.eu (checked 2026-08-03).
- Regulation (EU) 2022/2554 (DORA), Article 1(2), sector-specific ICT risk act for financial entities that displaces equivalent NIS 2 provisions under NIS 2 Article 4. eur-lex.europa.eu (checked 2026-08-03).
- Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities (CER Directive), the critical-entity identification that NIS 2 Article 3 treats as an essential-entity basis. eur-lex.europa.eu (checked 2026-08-03).
- European Commission: NIS 2 Directive transposition tracker (Member-State implementation status; the EU-level source we fall back to when a national authority page is unavailable). digital-strategy.ec.europa.eu (checked 2026-08-03).
Written and maintained by the ISMS Copilot team. Our compliance content is produced by certified information security professionals, including a CISM-certified ISO 27001 Lead Implementer who still runs audits. Last reviewed 2026-08-03.
This page paraphrases the structure of Directive (EU) 2022/2555 and Commission Recommendation 2003/361/EC in original wording. It is educational content, not legal advice and not a binding determination of your organisation's status. For a formal view, consult your competent national authority or counsel and read the national transposition act that applies to you.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
