Skip to content
UnifiedONE — Community Protection Intelligence
Compliance

Does NIS2 apply to my company? A 2-minute check

NIS2 covers 18 sectors across the EU. A fast 2-minute check on whether it applies to your company, the size floor, the entities covered at any size, and where UK firms stand in 2026.

Sher Khatak14 min read
Share
NIS2 applicability check: entities pass a single decision point and are sorted into in-scope and out-of-scope groups.

Last updated: 31 July 2026 · The check takes about 2 minutes · Full read approx. 9 minutes · For founders, IT leads and compliance owners

Here is the fast version, because most people arrive at this question in a hurry. NIS2 applies to your company if you operate in one of 18 designated sectors and you are at least a medium-sized business, roughly 50 staff or 10 million euro in turnover and balance sheet. Some entity types are covered at any size, and plenty of smaller companies get pulled in through their customers’ contracts. That is the whole test, and you can run it in about two minutes.

The reason it feels harder than it is: the deadlines have been a moving target. The transposition deadline passed on 17 October 2024, national laws landed at wildly different times, and on 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for still not having transposed the rules, asking for financial sanctions (European Commission, infringement package IP/26/1499, 8 July 2026). So the law is years old, but the enforcement clock only just started ringing in several countries. Germany is the sharpest example: today, 31 July 2026, is the last day of the BSI’s grace period for NIS2 registration.

The short version

  • Scope is a two-part test: your sector (Annex I or Annex II) and your size (staff, turnover, balance sheet).
  • 18 sectors are covered, from energy and health to food, waste, manufacturing and managed IT services.
  • Some entities are in scope at any size, including DNS providers, TLD registries, qualified trust service providers and public telecoms.
  • Below the size floor you are usually out of direct scope, but supplier clauses from regulated customers reach you anyway.
  • UK companies are not directly bound by NIS2, but an EU establishment, EU customers, or offering certain services into the EU can pull them in.

NIS2 applicability at a glance

Item Fact
Legal instrument Directive (EU) 2022/2555, transposed into national law
Transposition deadline 17 October 2024
Sectors in scope 18 (11 in Annex I, 7 in Annex II)
Entity classes Essential entities and important entities
Standard size floor 50 staff, or turnover and balance sheet each above 10 million euro
Covered at any size Critical infrastructure, qualified trust services, TLD registries, DNS, public telecoms
Financial firms Follow DORA instead of NIS2 for ICT risk (lex specialis)
Maximum fine 10 million euro or 2 percent of worldwide turnover, whichever is higher

The 2-minute check: four questions

Run these four questions in order. If you answer yes to any of the first three, you are almost certainly in scope. The fourth catches the companies that are not directly regulated but still have to meet the requirements in practice. Roughly 29,500 organisations are expected to be in scope in Germany alone (BSI figures reported by ad-hoc-news, July 2026), so being caught is the common case, not the edge case.

  1. Do you operate in one of the 18 sectors? Check your actual activity against Annex I and Annex II of the directive, not your job title or how you describe the company. A firm that runs IT for other businesses sits in Annex I as an ICT service manager, even if it thinks of itself as a small software shop.
  2. Do you meet the size floor? At least 50 staff, or turnover and balance sheet each above 10 million euro, using consolidated group figures where you have parent or linked companies. A small subsidiary of a large group is rarely as small as its own accounts suggest.
  3. Are you one of the always-covered types? DNS providers, top-level domain registries, qualified trust service providers, public electronic communications providers and operators of critical infrastructure are in scope at any headcount. A four-person DNS operator carries the same core duties as a utility.
  4. Do you sell to regulated customers? If a real share of your revenue comes from Annex I or Annex II organisations, their supply-chain obligations land on you as contract terms. You may not be legally in scope, but you will be treated as if you are.
The NIS2 two-part test: a company is in scope only where its sector and its size both qualify
The two-part test: scope exists only where sector and size both qualify. Source: Directive (EU) 2022/2555, Articles 2 and 3.

The output of this check matters as much as the answer. “We looked and decided we were out of scope” only works as a defence if you can show the working: which entities, which activities, which financial year. Write it down and date it.

Which sectors does NIS2 cover?

NIS2 covers 18 sectors, split into 11 in Annex I (“sectors of high criticality”) and 7 in Annex II (“other critical sectors”). The split decides whether you land in the essential or the important category. Sector is judged on what you actually do, so the same company can be in scope for one activity and not for another.

Annex I runs from energy, transport, banking and financial market infrastructure through health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II adds postal and courier services, waste management, chemicals, food, manufacturing, digital providers such as online marketplaces and search engines, and research organisations.

Two entries catch people out. Managed service providers and managed security service providers are named directly in Annex I, which pulls a large slice of the IT channel into regulation for the first time. And “digital infrastructure” is broad: it includes cloud providers, data centres, content delivery networks, DNS and trust services. If you run other people’s systems, assume you are in scope until you have checked properly. For the full sector-by-sector breakdown and the ten measures you owe once you are in, our companion guide on who NIS2 covers and what you actually have to do lays out both Annexes in a single table.

What are the size thresholds?

The size floor follows the EU definition of medium and large enterprises. Important entities start at 50 staff, or turnover and balance sheet each above 10 million euro. Essential entities in Annex I sit higher, at 250 staff, or turnover above 50 million euro and a balance sheet above 43 million euro. Below both floors you are usually out of direct scope, unless you are an always-covered type.

Class Sector Size test
Essential entity Annex I At least 250 staff, or turnover above 50 million euro and balance sheet above 43 million euro
Important entity Annex I At least 50 staff, or turnover and balance sheet each above 10 million euro
Important entity Annex II At least 50 staff, or turnover and balance sheet each above 10 million euro
Out of scope by default Annex I or II Below 50 staff and below 10 million euro on both turnover and balance sheet

Count the whole legal entity, not the IT team. And count the group: under the EU SME definition, partner and linked enterprises are normally consolidated, so ownership by a larger group can push a small company over the line on its own.

Essential or important: does the difference change your answer?

No, not for the applicability question. Both classes owe the same technical measures under Article 21 and the same reporting deadlines under Article 23. The difference is supervision and penalties: essential entities face proactive audits and fines up to 10 million euro or 2 percent of worldwide turnover, important entities are supervised reactively with a ceiling of 7 million euro or 1.4 percent.

So the label does not change whether you are covered, only how closely you are watched and how much a failure costs. People read “important” as the lighter tier and relax. The controls are identical. What differs is your odds of being examined without an incident to trigger it. If you want the detailed comparison, we covered the essential versus important split in depth in the companion guide.

Does NIS2 apply to UK companies?

Not directly. NIS2 is an EU directive, and the UK, having left the EU, does not implement it. UK organisations still follow the Network and Information Systems Regulations 2018, the domestic regime the ICO and other authorities enforce (ICO, The Guide to NIS, 2026). But three routes pull UK companies back toward NIS2 in practice, so “we’re not in the EU” is rarely the end of the answer.

The first route is an EU establishment. If your company has an office or operations in a member state, that establishment falls under that state’s NIS2 rules. The second is service provision: certain entity types that offer services into the EU without being established there, including DNS providers, cloud and data-centre operators, CDNs, managed service providers and online platforms, must appoint an EU representative and answer to the member state where that representative sits (Directive (EU) 2022/2555, Article 26). The third is the supply chain, the same contractual pressure that reaches small EU vendors. Sell to an in-scope EU customer and their Article 21(2)(d) duty becomes your problem, through the contract.

The UK is also tightening its own rules. The Cyber Security and Resilience Bill, introduced to Parliament in November 2025 and now in the House of Lords after its second reading on 14 July 2026, would widen the 2018 regime to cover managed service providers and data centres and strengthen incident reporting (UK Parliament, Cyber Security and Resilience Bill, HL Bill 32, 2026). If you are an MSP on either side of the Channel, the direction of travel is the same: more scope, not less. We wrote separately about what that means for the channel on our MSP page.

You are in scope. Now what?

Being in scope means ten categories of risk-management measures under Article 21(2), a reporting chain of 24 hours, 72 hours and one month under Article 23, registration with your national authority, and board-level accountability under Article 20 that cannot be contracted away. The measures are written as outcomes, so an auditor asks for evidence that each one works, not proof that you bought a product.

The ten measures cover risk policies, incident handling, business continuity and backups, supply-chain security, secure development and vulnerability handling, testing whether the measures actually work, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. The one that trips people most is effectiveness testing: a policy library with no test evidence behind it is a finding an auditor can write up in an afternoon.

Registration is the duty most often missed, because it lands before the technical work is done and nothing in a security roadmap reminds you about it. Germany shows how tight this has become. The national law entered into force on 6 December 2025 with no transition period, the registration deadline fell on 6 March 2026, and by the end of May only about 18,500 of an expected 29,500 organisations had registered, which is why the BSI ran an enforcement grace period that ends today (figures reported by ad-hoc-news, July 2026). For a full walkthrough of turning these obligations into daily operations, see our companion guide on who NIS2 covers and what you actually have to do.

One clarification that saves financial firms a lot of wasted effort: banks, insurers and most other regulated financial entities follow DORA, Regulation (EU) 2022/2554, which has applied since 17 January 2025. DORA is the more specific law, so for ICT risk management it takes precedence over NIS2 (Directive (EU) 2022/2555, Article 4). If you are a financial entity, your ICT-risk homework is DORA, not NIS2.

Covering the requirements without building a SOC from scratch

Most of the ten measures describe continuous work: detection, patching, access review, effectiveness testing. That is hard to sustain alone, especially for the mid-market companies NIS2 has just pulled into scope for the first time. The threat picture is not helping. ENISA analysed 4,875 incidents in its 2025 assessment and found ransomware behind 81.1 percent of cybercrime incidents affecting EU organisations, with phishing involved in around 60 percent of intrusions (ENISA, Threat Landscape 2025, October 2025).

Community-based threat protection: one validated finding at the hub protects every connected member
The community model: a threat validated once protects every connected member.

UnifiedONE takes a community approach to that load. A threat validated once protects every connected member automatically, which is where “Investigate Once. Protect Many.” comes from. For Microsoft environments, meaning Defender, Entra ID, Sentinel and Microsoft 365, that becomes continuous monitoring and shared defence run to European data protection standards. Not sure where your entities land? Talk to the UnifiedONE team about NIS2 and continuous monitoring for your Microsoft estate.

Frequently asked questions about NIS2 applicability

Does NIS2 apply to my company?

It applies if you operate in one of the 18 sectors in Annex I or Annex II of Directive (EU) 2022/2555 and meet the size thresholds, normally at least 50 staff or turnover and balance sheet each above 10 million euro. Some types, including DNS providers, TLD registries, qualified trust service providers and public telecoms, are covered at any size.

Does NIS2 apply to UK companies?

Not directly, because the UK does not implement the EU directive and instead applies the NIS Regulations 2018. UK firms are still reached if they have an EU establishment, offer certain services into the EU and must appoint an EU representative under Article 26, or supply in-scope EU customers who pass NIS2 requirements down through contracts.

Does NIS2 apply to small companies?

Usually not directly. Companies below 50 staff and below 10 million euro on both turnover and balance sheet fall outside default scope, unless they are an always-covered type such as a DNS or trust service provider. Many are still affected, because regulated customers must manage supplier security under Article 21(2)(d), which arrives as contract clauses.

Is NIS2 mandatory?

Yes. It has been binding EU law since Directive (EU) 2022/2555 entered into force, with a transposition deadline of 17 October 2024, and it applies through each member state’s national law. As of May 2026, 22 of 27 member states had adopted transposing legislation, and the Commission referred four others to the Court of Justice in July 2026.

What is the difference between NIS2 and DORA?

DORA, Regulation (EU) 2022/2554, governs ICT risk for financial entities and has applied since 17 January 2025. It is the more specific law, so financial firms follow DORA rather than NIS2 for ICT risk management, under NIS2 Article 4. Non-financial companies in scope follow NIS2. A group with both kinds of entity can be subject to both.

Does NIS2 require an SBOM?

Not by name. Article 21(2)(e) requires security in acquisition, development and maintenance including vulnerability handling, and Article 21(2)(d) requires supply-chain security. A software bill of materials is a common and practical way to evidence both, and regulated customers increasingly ask for one, but it is not an explicit legal requirement.

Which sectors are covered by the NIS2 directive?

Eighteen in total. Annex I lists energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II lists postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research organisations.

The two-minute version, one more time

If you operate in one of the 18 sectors and you are medium-sized or larger, you are almost certainly in scope. If you are one of the always-covered types, size is irrelevant. If you are smaller but sell to regulated customers, the requirements will reach you through their contracts. And if you are a UK company, check for an EU establishment, EU service provision and EU customers before you conclude the directive leaves you alone.

Run the four questions, write down the answer with the date and the reasoning, and register where you need to. The companies that handle their first supervisory contact calmly are the ones that treated scope as a documented decision rather than an assumption.


Sources

Written by

Sher Khatak

UnifiedONE

Newsletter

Get the next one in your inbox.

A useful read once a month. No spam.

See it in action

See it in action.

Turn one validated threat into protection for your whole community. Start free, or book a walkthrough with our team.