NIS2 entity-scope classifier

Does NIS2 apply to your organisation?

Pick your sector, size and EU footprint to see whether you are an essential, important or out-of-scope entity — with the obligations and competent authority that attach.

Directive (EU) 2022/2555 · scope logic verified 16 Jun 2026 · dataset v1.1.1

Sources: EUR-Lex — Directive (EU) 2022/2555 · European Commission — NIS2 policy

Entity-scope classifierDirective (EU) 2022/2555

NIS2 entity scope decision form

Step 1 — Sector

Annex I lists the high-criticality sectors (essential by default at large size). Annex II lists the other critical sectors (important by default at large size). Choose 'none' if neither annex describes you.

Step 2 — Size

Article 2(1) anchors scope to the Annex to the Recommendation 2003/361/EC (medium = 50–249 employees AND turnover ≤ €50M OR balance ≤ €43M; large = ≥ 250 employees OR turnover > €50M).

Step 3 — EU footprint

An entity is in scope if it is established in the EU. Non-EU providers of certain services (DNS, TLD registry, cloud, data centre, CDN, managed services, online marketplace, search engine, social network) must designate a representative under Article 26.

Used to flag Article 26 representative-designation obligations for non-EU entities.

Step 4 — Primary Member State

Used to surface the competent authority + CSIRT designated under Articles 8 and 10. For multi-country providers Article 26(2) routes jurisdiction to a single MS.

Step 5 — NIS1 history (optional)

NIS1 OES / DSP designations grandfather scope considerations under NIS2 transitional rules (Article 41).

Last verified: 2026-06-16

Covered sectors
18
Annex I + Annex II
Early warning
24h
of awareness (Art. 23)
Incident notification
72h
of awareness (Art. 23)

NIS2 scope at a glance

NIS2 (Directive (EU) 2022/2555) entered into force on 16 January 2023, with a Member-State transposition deadline of 17 October 2024. It applies to entities operating in one of the 18 Annex I and Annex II sectors that are medium or large (generally ≥ 50 staff OR > €10M turnover).

Annex I high-criticality sectors (energy, transport, banking, financial-market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space) at large size are ESSENTIAL entities; Annex I at medium size and all Annex II sectors (postal, waste, chemicals, food, manufacturing, digital providers, research) are IMPORTANT entities.

In-scope entities owe cybersecurity risk-management measures (Art. 21), incident reporting — a 24-hour early warning and 72-hour notification (Art. 23) — registration, and management liability (Art. 20). DNS providers, TLD registries, trust service providers and public electronic-communications providers are in scope regardless of size (Art. 2(2)); non-EU entities serving the Union are in scope through a designated representative (Art. 26(3)).

Sources: EUR-Lex — Directive (EU) 2022/2555 · European Commission — NIS2 policy · ENISA — NIS2 Directive

Scope logic verified 16 Jun 2026 against the European Commission NIS2 page and the directive text · Articles 2, 26 and 34: scope · non-EU entities · fines.

Frequently asked questions

Is my small DNS / TLD / trust-service / public-comms business exempt because it is under 50 employees?

No. Article 2(2) of Directive (EU) 2022/2555 puts DNS service providers, top-level-domain name registries, trust service providers, and providers of public electronic communications networks or services in scope regardless of size. The micro/small exclusion in Article 2(1) does not apply to those categories — a small DNS provider is an essential entity with the full obligation stack.

I'm a non-EU company (e.g. a US cloud or SaaS provider) serving EU customers — am I out of scope?

No. Under Article 26(3), a non-EU entity that offers the listed services in the Union is in scope through a designated EU representative. It carries the full Article 20 governance, Article 21 risk-management and Article 23 incident-reporting duties and is subject to Article 34 fines — not merely a “designate a representative and register” duty.

What's the difference between an essential and an important entity?

Annex I (high-criticality) sectors at large size are essential entities (Article 3(1)(a)); Annex I at medium size, and all Annex II (other-critical) sectors, are important entities (Article 3(2)). Essential entities face proactive supervision; important entities face ex-post supervision. The classification also sets the Article 34 fine ceiling.

What are the incident-reporting deadlines and the maximum NIS2 fines?

Article 23 requires an early warning within 24 hours of becoming aware of a significant incident and an incident notification within 72 hours, with a final report within one month. Under Article 34, essential entities face at least €10,000,000 or 2% of total worldwide annual turnover, whichever is higher; important entities face at least €7,000,000 or 1.4%, whichever is higher. National transposing law sets the actual penalty regime on top.

When did NIS2 take effect and when was it due to be transposed?

The directive entered into force on 16 January 2023 and Member States were required to transpose it into national law by 17 October 2024. Many Member States missed that deadline, so the precise rules and the competent authority depend on your national transposing act — verify with the authority surfaced in the result panel.

Does this tool give me a binding compliance opinion?

No. It walks the scope tests in Articles 2, 3 and 26 of the directive and is a free orientation aid, not legal advice. National transposition adds specifics, and edge cases (sole providers of an essential service, group-level thresholds) need a lawyer. Confirm with your competent authority before reporting under Article 23.

Check NIS2 scope