Are You in Scope of NIS2? The Complete Entity Classification Checklist

Date: 13 August 2026

Featured Image

Your organisation falls under NIS2 if it operates in one of the 18 sectors listed in Annex I or Annex II of the directive and meets the medium or large enterprise size threshold (50+ employees or €10 million+ annual turnover). Certain entities, including DNS providers, top-level domain registries, and public administration bodies, are in scope regardless of size, and smaller suppliers can be pulled in indirectly through contracts with in-scope customers.

If that's all you needed, you now know enough to start classifying your entity. Everyone else should read on, because the size rule, the sector list, and the exceptions each have details that change the answer.

The Three-Question scope test

NIS2 scope isn't one rule — it's three filters applied in sequence. Most classification mistakes happen because organisations check only the first one.

Step

Question

What determines the answer

1. Sector

Does your organization operate in an Annex I or Annex II sector?

The 18-sector list below (Article 3, Annex I & II)

2. Size

Are you a medium or large enterprise?

Staff headcount + annual turnover/balance sheet (Recommendation 2003/361/EC)

3. Exception

Do you fall under a regardless-of-size or pull-through rule?

Article 2(2) exceptions, or a contractual obligation from an in-scope customer

If you pass Step 1 and Step 2, you're in scope. If you fail Step 2, check Step 3 before concluding you're exempt — this is the step almost every SME skips, and the one most likely to surprise them later.

Step 1: The 18 sectors — Annex I and Annex II

NIS2 splits covered sectors into two tiers. Annex I sectors are considered highly critical; a large entity in one of them is automatically classified as "essential." Annex II sectors are other critical sectors; entities here are classified as "important" regardless of whether they're medium or large.

Annex I — Sectors of High Criticality

#

Sector

Examples of covered entities

1

Energy

Electricity, district heating/cooling, oil, gas, hydrogen operators

2

Transport

Air, rail, water, and road transport operators

3

Banking

Credit institutions

4

Financial market infrastructure

Trading venues, central counterparties

5

Health

Hospitals, EU reference labs, pharma manufacturers, critical medical device makers

6

Drinking water

Suppliers and distributors

7

Waste water

Collection, disposal, treatment

8

Digital infrastructure

IXPs, DNS providers, TLD registries, cloud providers, data centres, CDNs, trust service providers, telecoms

9

ICT service management

Managed service providers (MSPs), managed security service providers (MSSPs)

10

Public administration

Central government bodies (regional, at Member State discretion)

11

Space

Operators of ground-based infrastructure supporting space services

Annex II — Other critical sectors

#

Sector

Examples of covered entities

12

Postal and courier services

Delivery and logistics operators

13

Waste management

Collection, treatment, disposal firms

14

Chemicals

Manufacture, production, distribution

15

Food

Production, processing, distribution

16

Manufacturing

Medical devices, electronics, electrical equipment, machinery, motor vehicles, other transport equipment

17

Digital providers

Online marketplaces, search engines, social networking platforms

18

Research

Research organisations

If your organisation doesn't fit anywhere in these two lists, NIS2 generally doesn't apply to you directly — though the pull-through rule in Step 3 is still worth checking if you sell into any of these sectors.

Step 2: Essential vs. Important — How size decides the category

This is where "am I in scope" turns into "which obligations apply to me," because essential and important entities face different supervisory intensity (though the same core security requirements). The classification hinges on the EU's standard company-size definitions from Recommendation 2003/361/EC.

Enterprise size

Staff headcount

Annual turnover or balance sheet

Large

250+

> €50 million turnover / > €43 million balance sheet

Medium

50–249

€10–50 million turnover / €10–43 million balance sheet

Small / Micro

< 50

< €10 million turnover / balance sheet

Combine that with the sector list, and the classification resolves as follows:

Sector list

Enterprise size

Classification

Annex I

Large

Essential entity

Annex I

Medium

Important entity

Annex II

Medium or Large

Important entity

Either

Small / Micro

Generally out of scope, subject to exceptions

Essential entities face proactive supervision. Regulators can audit them without a specific trigger. Important entities are supervised reactively, typically only after an incident or complaint surfaces a problem. ISMS.online

Step 3: In scope regardless of size

A meaningful set of entities is covered no matter how small they are, because Article 3 and Article 2(2) carve out exceptions to the size-cap rule. You fall into this bucket if any of the following apply:

  • You're a qualified trust service provider, a top-level domain name registry, or a DNS service provider. These are essential entities regardless of size. nis-2-directive.com

  • You're the sole provider of a service that's critical for maintaining vital societal or economic activity in a Member State.

  • A disruption to your service could have a significant impact on public safety, public security, or public health.

  • A disruption to your service could create significant systemic risk, particularly for sectors with cross-border effects.

  • You're a public administration body at central government level (and, in some Member States, regional level too).

  • Your national authority has specifically designated you as critical based on your role in the local economy, even if you fall under the size thresholds.

If none of these describe you and you're below the size thresholds, you're very likely out of direct scope — but that's not the end of the assessment.

The Pull-Through Trap: Why Smaller Vendors Get Caught Anyway

Even a micro-business with zero direct NIS2 obligations can end up doing NIS2-level work. This is because Article 21 requires every in-scope entity to manage cybersecurity risk across its supply chain, including relationships with suppliers who aren't covered by the directive themselves.

In practice, this shows up as:

  • Security questionnaires and audit rights written into new vendor contracts by in-scope customers.

  • Contractual requirements to hold specific certifications, run incident notification procedures on the customer's timeline, or maintain evidence of a documented risk management process.

  • Being named in a customer's own supplier register, which means your security posture is now something they have to monitor and report on.

Protection under NIS2 effectively covers the entire chain a critical entity depends on, often independent of the supplier's own size.

If you sell into any Annex I or Annex II sector, even as a two-person software vendor, expect this pressure to arrive as a contract clause before it arrives as a legal requirement.

One More Variable: Your country's transposition

NIS2 is a directive, not a regulation. Each EU Member State transposes it into national law, and national legislators have discretion on several scope questions (notably which public administration bodies at regional level are covered, and the exact timeline for first compliance audits).

Two organisations with identical sector and size profiles in different countries can face different effective deadlines. Always check your national transposition status alongside this framework rather than in place of it.

What to do with your answer

Once you know your sector, your size classification, and whether an exception applies, you have exactly the inputs needed to formally classify your entity, Annex I or II, essential or important, and any regardless-of-size trigger that applies to you. Rather than tracking that in a spreadsheet that goes stale the moment your headcount or revenue crosses a threshold, classify your entity directly in your NIS2 Register, where the classification stays linked to the specific documents and controls it triggers under Article 21.

FAQS

1. Is my company in scope of NIS2?

Your company is in scope if it operates in one of the 18 sectors listed in NIS2 Annex I or Annex II and qualifies as a medium or large enterprise (50+ employees or €10 million+ annual turnover). Some entities, such as DNS providers, TLD registries, and certain public administration bodies, are in scope regardless of size, and smaller suppliers can be pulled in contractually even without direct legal obligations.

2. What is the difference between an essential entity and an important entity under NIS2?

Essential entities are large enterprises operating in Annex I (highly critical) sectors, plus a small set of entities that are essential regardless of size, such as DNS providers and TLD registries. Important entities are medium-sized enterprises in Annex I sectors, or medium/large enterprises in Annex II (other critical) sectors. The core security obligations are similar, but essential entities face proactive supervision, while important entities are typically supervised only after an incident or complaint.

3. What are the 18 sectors covered by NIS2?

NIS2 covers 11 Annex I sectors (energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, and space) and 7 Annex II sectors (postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research).

4. What size company needs to comply with NIS2?

As a general rule, NIS2 applies to medium and large enterprises: 50 or more employees, or annual turnover/balance sheet above €10 million. Small and micro enterprises are generally exempt unless they fall under a regardless-of-size exception or are contractually required to comply by an in-scope customer.

5. Can a small business be affected by NIS2 even if it's below the size threshold?

Yes. Even a company below the size thresholds can be required to meet NIS2-equivalent security standards if it supplies an in-scope essential or important entity. Article 21's supply-chain security requirement means in-scope organizations must manage risk across their vendors, which often shows up as security questionnaires, audit clauses, or certification requirements in contracts with smaller suppliers.

6. Does NIS2 apply the same way in every EU country?

Not exactly. NIS2 is a directive, not a regulation, so each Member State transposes it into national law with some discretion — particularly around which public administration bodies at regional level are covered and the exact timeline for first compliance audits. Two companies with identical sector and size profiles can face different effective deadlines depending on their country.

7. What happens if my organisation is classified incorrectly?

Misclassifying your entity (for example, treating an essential entity as important, or missing a regardless-of-size trigger) can mean applying the wrong supervisory expectations and missing incident reporting timelines. Since classification determines which Article 21 obligations and audit posture apply, it's worth revisiting whenever your headcount, revenue, or service offering changes.

8. How do I officially classify and document my NIS2 entity status?

Once you've confirmed your sector, size, and any applicable exceptions, record that classification along with the reasoning behind it — this becomes part of your compliance evidence. Doing this in a live NIS2 Register, rather than a static document, keeps your classification linked to the specific policies and controls it triggers, and keeps it current as your organisation changes.