NIS 2 applicability checker
Find out whether the EU NIS 2 Directive applies to your organisation — and whether you would be an essential or an important entity — in about two minutes.
Classification follows Directive (EU) 2022/2555, Articles 2 & 3 and Annexes I & II, read with the SME thresholds in Commission Recommendation 2003/361/EC. This tool gives a structured starting point, not legal advice.
The core NIS 2 obligations
If NIS 2 applies to your organisation, these are the duties it imposes. Essential and important entities carry the same core security and reporting obligations; their supervision and enforcement regimes differ. Use the checker above to see whether you are in scope and which category you fall into.
- •Cybersecurity risk-management measures (Art. 21) — a defined set of technical and organisational measures.
- •Significant-incident reporting (Art. 23) — early warning within 24h, notification within 72h, final report within one month.
- •Governance & management accountability (Art. 20) — management bodies approve and oversee the measures and can be held liable.
- •Registration with the competent authority and keeping your entity data up to date.
Official sources
Jurisdiction: EU; obligations apply through national transposition law. Instrument: Directive (EU) 2022/2555 (NIS 2), read with the SME thresholds in Commission Recommendation 2003/361/EC, as in force on the dates below.
- Directive (EU) 2022/2555 (NIS 2 Directive), EUR-Lex (Last verified by us 2026-07-17)
- Commission Recommendation 2003/361/EC (SME definition), EUR-Lex (Last verified by us 2026-07-17)
- European Commission: NIS 2 Directive transposition tracker (Last verified by us 2026-07-17)
FAQ
- Does NIS 2 apply to my company?
- NIS 2 generally applies to medium-sized and larger organisations operating in the EU within one of the sectors listed in Annex I (sectors of high criticality) or Annex II (other critical sectors). Some entity types — including DNS service providers, TLD registries, trust service providers and public electronic communications providers — are in scope regardless of size. This checker walks the actual Article 2 and Article 3 logic to give you a structured starting-point classification.
- What is the difference between an essential and an important entity?
- Both face the same core security and incident-reporting obligations. The difference is supervision: essential entities are subject to proactive, ex-ante supervision; important entities are supervised reactively, ex-post. Broadly, large entities in Annex I sectors are essential, while medium-sized entities and Annex II entities are important — but several specific rules in Article 3 override this, which is why a checklist alone is unreliable.
- Is this NIS 2 checker legal advice?
- No. It is a free, structured starting point based on the directive’s text and your inputs. NIS 2 applicability depends on facts specific to your organisation, and several exceptions involve a judgement your competent national authority makes. Always confirm the result with that authority or your counsel before relying on it.
- Do you store my answers?
- No. The classification runs entirely in your browser. We do not gate the tool behind a form, and we do not capture or store the answers you enter.
- Is NIS 2 transposed in my country yet?
- NIS 2 is a directive, so it takes effect through national transposition law. The transposition deadline was 17 October 2024 and several Member States are still completing the process. The checker shows the transposition status we last verified for your country, with the date and a link to the most authoritative source we verified (the national authority where we track one, otherwise the official EU tracker) so you can re-check. For the full picture across all 27 Member States, see our NIS 2 transposition tracker at /learn/nis-2-transposition-tracker, which renders from the same verified dataset.
- We are below the size threshold — are we safe to ignore NIS 2?
- Not necessarily. Size-independent exceptions can still bring small entities into scope, and even if you are genuinely out of direct scope, in-scope customers routinely pass NIS 2-aligned security and reporting obligations down their supply chain by contract.
- Where can I read the decision method without using the form?
- See the long-form guide Do I fall under NIS 2? at /learn/do-i-fall-under-nis-2. It walks the same legal structure (EU activity, Annex I/II, size-independent special types, SME dual-ceiling size rule, essential versus important, national transposition) in prose, with primary sources. This checker is the interactive form of that test.
By ISMS Copilot. Classification follows Directive (EU) 2022/2555, Articles 2 & 3 and Annexes I & II, read with the SME thresholds in Commission Recommendation 2003/361/EC. This tool gives a structured starting point, not legal advice.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
