NIS2 scope checker

Does NIS2 apply to your organisation, and are you an essential or an important entity? Pick your sector, enter your size (including group companies), and get a reasoned answer with the articles behind it, plus notes for the Netherlands, Italy, Belgium and Germany.

Based on Directive (EU) 2022/2555 and Recommendation 2003/361/EC, as of 1 October 2026
1. Where is your main establishment?
2. What do you do?
Several activities? Check each one; one in-scope activity is enough. Annex I sectors are "high criticality", Annex II "other critical".
3. How big are you?

Figures from your latest approved accounts, calculated on an annual basis. Turnover excludes VAT.

Full-time equivalents over the year: employees, owner-managers, working partners. Not apprentices.

Part of a group? Add linked and partner enterprises

Linked enterprises (you control them or they control you, e.g. a majority of voting rights): add 100 %. Partner enterprises (a holding of 25 % up to 50 %, directly up- or downstream): add their figures pro rata. Holdings by venture capital, business angels (under EUR 1 250 000), universities or small local authorities do not create a partnership. Unlike the SME definition, NIS2 ignores the 25 % public-body rule (Art. 2(1), second subparagraph).

4. Anything that overrides size?

Your result appears here as you fill in the form.

How NIS2 scope works

Three questions decide it (Directive (EU) 2022/2555, Arts. 2-3):

  1. Sector. Is your entity type listed in Annex I (energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space) or Annex II (postal, waste, chemicals, food, manufacturing of medical devices, electronics, electrical equipment, machinery, vehicles and other transport equipment, digital providers, research)?
  2. Size. Are you at least a medium-sized enterprise under Recommendation 2003/361/EC?
  3. Exceptions. Some entities are in scope whatever their size, and Member States can add more.

Size thresholds

CategoryStaffand turnoveror balance sheetNIS2 effect (if in an Annex sector)
Micro< 10≤ EUR 2 M≤ EUR 2 MOut, unless size-independent
Small< 50≤ EUR 10 M≤ EUR 10 MOut, unless size-independent
Medium< 250≤ EUR 50 M≤ EUR 43 MImportant (Annex I and II)
LargeExceeds the medium-sized ceilingsEssential (Annex I), important (Annex II)

The staff ceiling always applies; for the money you need to stay within either the turnover or the balance sheet ceiling. A company with 40 staff, EUR 12 million turnover and a EUR 8 million balance sheet is still small. One with 40 staff and EUR 12 million on both counts is medium-sized and in scope if its sector is listed. A category changes only when the ceilings are crossed in two consecutive accounting periods (Annex Art. 4(2)).

In scope regardless of size

  • Always essential: qualified trust service providers, TLD name registries and DNS service providers (Art. 3(1)(b)); central government entities (Art. 3(1)(d)); critical entities under the CER Directive (Art. 3(1)(f)).
  • In scope at any size: providers of public electronic communications networks or services (essential from medium-sized, Art. 3(1)(c)) and non-qualified trust service providers (Art. 2(2)(a)).
  • Designated by the Member State: sole providers of an essential service, or entities whose disruption would hit public safety, security or health, create systemic risk or matter specifically at national or regional level (Art. 2(2)(b)-(e)).
  • Domain name registration services are covered for the registration data duties of Article 28 (Art. 2(4)).

Essential or important: what changes

Both categories must take the risk-management measures of Article 21, have the management body approve and oversee them (Art. 20), and report significant incidents (Art. 23). The difference is supervision and fines. Essential entities are supervised proactively (Art. 32) and face fines of at least up to EUR 10 million or 2 % of worldwide turnover; important entities are supervised after the fact (Art. 33) with fines of at least up to EUR 7 million or 1.4 % (Art. 34). Financial entities under DORA follow DORA for ICT risk and incident reporting (Art. 4).

Out of scope, but still asked

Article 21(2)(d) makes NIS2 entities responsible for the security of their supply chain. Expect security questionnaires, contract clauses and audit rights from customers that are in scope, especially if you provide IT, software, hosting or components. Having your policies, ISO 27001 status and incident process documented saves days per questionnaire.

Country notes

What may change

On 20 January 2026 the Commission proposed targeted amendments to NIS2, including a "small mid-cap" category (fewer than 750 staff and turnover up to EUR 150 million or balance sheet up to EUR 129 million) whose members could at most be important entities. As of 1 October 2026 this is a proposal in the legislative procedure; the checker applies the current Directive.

Indicative only, not legal advice. National transpositions can add sectors or entities, and your competent authority decides on designation and registration.

Questions

What is the size threshold for NIS2?

NIS2 applies to entities in Annex I or II sectors that are at least medium-sized under Commission Recommendation 2003/361/EC: 50 or more staff, or annual turnover above EUR 10 million and a balance sheet total above EUR 10 million. Large enterprises in Annex I sectors (250+ staff, or turnover above EUR 50 million and balance sheet above EUR 43 million) are essential entities.

Do group companies count towards the size?

Yes. Under Article 6 of the Annex to Recommendation 2003/361/EC, you add 100 % of the figures of linked enterprises (for example a parent or subsidiary you control) and a pro-rata share of partner enterprises (holdings of 25 % to 50 %). A small subsidiary of a large group is therefore usually not small.

Which entities are in scope regardless of size?

Providers of public electronic communications networks or services, trust service providers, TLD name registries and DNS service providers, central government entities, critical entities under the CER Directive, and entities a Member State identifies as sole providers or otherwise critical (Article 2(2)-(4)). Domain name registration services are covered for registration-data duties.

We are out of scope. Can we ignore NIS2?

Not entirely. NIS2 entities must manage supply-chain security (Article 21(2)(d)), so suppliers of IT services, software and components receive security questionnaires, contract clauses and audit requests. Being able to answer them quickly is a sales advantage.