Does NIS2 apply to your organisation?
Pick your sector, size and EU footprint to see whether you are an essential, important or out-of-scope entity — with the obligations and competent authority that attach.
Directive (EU) 2022/2555 · scope logic verified 16 Jun 2026 · dataset v1.1.1
Sources: EUR-Lex — Directive (EU) 2022/2555 · European Commission — NIS2 policy
NIS2 entity scope decision form
- Covered sectors
- 18 Annex I + Annex II
- Early warning
- 24h of awareness (Art. 23)
- Incident notification
- 72h of awareness (Art. 23)
NIS2 scope at a glance
NIS2 (Directive (EU) 2022/2555) entered into force on 16 January 2023, with a Member-State transposition deadline of 17 October 2024. It applies to entities operating in one of the 18 Annex I and Annex II sectors that are medium or large (generally ≥ 50 staff OR > €10M turnover).
Annex I high-criticality sectors (energy, transport, banking, financial-market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space) at large size are ESSENTIAL entities; Annex I at medium size and all Annex II sectors (postal, waste, chemicals, food, manufacturing, digital providers, research) are IMPORTANT entities.
In-scope entities owe cybersecurity risk-management measures (Art. 21), incident reporting — a 24-hour early warning and 72-hour notification (Art. 23) — registration, and management liability (Art. 20). DNS providers, TLD registries, trust service providers and public electronic-communications providers are in scope regardless of size (Art. 2(2)); non-EU entities serving the Union are in scope through a designated representative (Art. 26(3)).
Sources: EUR-Lex — Directive (EU) 2022/2555 · European Commission — NIS2 policy · ENISA — NIS2 Directive
Frequently asked questions
Is my small DNS / TLD / trust-service / public-comms business exempt because it is under 50 employees?
No. Article 2(2) of Directive (EU) 2022/2555 puts DNS service providers, top-level-domain name registries, trust service providers, and providers of public electronic communications networks or services in scope regardless of size. The micro/small exclusion in Article 2(1) does not apply to those categories — a small DNS provider is an essential entity with the full obligation stack.
I'm a non-EU company (e.g. a US cloud or SaaS provider) serving EU customers — am I out of scope?
No. Under Article 26(3), a non-EU entity that offers the listed services in the Union is in scope through a designated EU representative. It carries the full Article 20 governance, Article 21 risk-management and Article 23 incident-reporting duties and is subject to Article 34 fines — not merely a “designate a representative and register” duty.
What's the difference between an essential and an important entity?
Annex I (high-criticality) sectors at large size are essential entities (Article 3(1)(a)); Annex I at medium size, and all Annex II (other-critical) sectors, are important entities (Article 3(2)). Essential entities face proactive supervision; important entities face ex-post supervision. The classification also sets the Article 34 fine ceiling.
What are the incident-reporting deadlines and the maximum NIS2 fines?
Article 23 requires an early warning within 24 hours of becoming aware of a significant incident and an incident notification within 72 hours, with a final report within one month. Under Article 34, essential entities face at least €10,000,000 or 2% of total worldwide annual turnover, whichever is higher; important entities face at least €7,000,000 or 1.4%, whichever is higher. National transposing law sets the actual penalty regime on top.
When did NIS2 take effect and when was it due to be transposed?
The directive entered into force on 16 January 2023 and Member States were required to transpose it into national law by 17 October 2024. Many Member States missed that deadline, so the precise rules and the competent authority depend on your national transposing act — verify with the authority surfaced in the result panel.
Does this tool give me a binding compliance opinion?
No. It walks the scope tests in Articles 2, 3 and 26 of the directive and is a free orientation aid, not legal advice. National transposition adds specifics, and edge cases (sole providers of an essential service, group-level thresholds) need a lawyer. Confirm with your competent authority before reporting under Article 23.