Skip to content
UnifiedONE — Community Protection Intelligence
Compliance

Who Does NIS2 Cover, and What You Actually Have to Do

NIS2 covers 18 sectors across the EU. Check whether it applies to your company, what the ten required measures are, and which 2026 deadlines still bite.

Sher Khatak18 min read
Share
Illustration of a grid of organisations divided by a boundary line, showing which fall inside NIS2 scope and which are pulled in through the supply chain

Last updated: 23 July 2026 · Reading time: approx. 11 minutes · For executives, IT leadership and compliance owners

On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to transpose NIS2, and asked the Court to impose financial sanctions (European Commission, infringement package IP/26/1499, July 2026). The transposition deadline had passed on 17 October 2024, almost two years earlier.

That gap explains most of the confusion in the market. NIS2 has been binding EU law for years, national rules landed at wildly different times, and plenty of companies still cannot answer the first question: does this apply to us at all? This guide answers that, then sets out exactly what you owe once the answer is yes.

The short version

  • Scope comes from a two-part test: your sector (Annex I or Annex II) and your size (headcount, turnover, balance sheet).
  • 18 sectors are covered, including managed service providers, manufacturing, food, waste and research.
  • Some entities are covered at any size, including DNS providers, TLD registries, qualified trust service providers and public telecoms.
  • Once in scope you owe ten categories of risk-management measures, a 24 hour / 72 hour / one month reporting chain, registration with your national authority, and board-level accountability.
  • Fines reach EUR 10 million or 2 percent of worldwide turnover, whichever is higher, and management can be held personally liable.

NIS2 at a glance

Item Fact
Legal instrument Directive (EU) 2022/2555, transposed into national law
Transposition deadline 17 October 2024
Sectors in scope 18 (11 in Annex I, 7 in Annex II)
Entity classes Essential entities and important entities
Standard size floor 50 staff, or turnover and balance sheet each above EUR 10 million
Risk-management duties Ten categories, Article 21(2)
Reporting chain 24 hours, 72 hours, one month
Maximum fine EUR 10 million or 2 percent of worldwide turnover, whichever is higher
Management Must approve and oversee measures, must train, can be held liable

Who does NIS2 cover?

NIS2 covers medium and large organisations operating in 18 designated sectors across the EU, split into essential entities and important entities. Scope is decided by a two-part test: whether your activity appears in Annex I or Annex II of Directive (EU) 2022/2555, and whether you meet the size thresholds. A number of entity types are covered at any size.

The directive replaced the original 2016 NIS regime and widened it dramatically. Where the old rules captured a few hundred operators of essential services per country, NIS2 captures tens of thousands. Germany alone expects roughly 29,500 in-scope organisations (BSI figures reported by SCHUTZWERK, 2026).

Two things trip companies up. First, sector is about what you do, not what you call yourself: a mid-sized company that runs IT services for other businesses sits in Annex I under ICT service management, regardless of whether it thinks of itself as a technology firm. Second, member states may designate additional entities below the thresholds, so the size floor is a default, not a ceiling on regulator discretion.

The 18 sectors: Annex I and Annex II

Annex I covers “sectors of high criticality” and Annex II covers “other critical sectors”. The split matters because it drives whether you land in the essential or the important category.

Annex I (high criticality, 11 sectors) Annex II (other critical, 7 sectors)
Energy (electricity, district heating and cooling, oil, gas, hydrogen) Postal and courier services
Transport (air, rail, water, road) Waste management
Banking Chemicals (manufacture, production, distribution)
Financial market infrastructures Food (production, processing, distribution)
Health (providers, labs, medicinal product R&D) Manufacturing (medical devices, computers and electronics, electrical equipment, machinery, motor vehicles, other transport)
Drinking water Digital providers (online marketplaces, search engines, social networks)
Waste water Research organisations
Digital infrastructure (IXPs, DNS, TLD registries, cloud, data centres, CDNs, trust services, electronic communications)
ICT service management, B2B (managed service providers, managed security service providers)
Public administration
Space

Note the ninth entry in Annex I. Managed service providers and managed security service providers are named explicitly, which pulls a large part of the IT channel into direct regulation for the first time. If you run other people’s infrastructure, assume you are in scope until you have checked properly.

The size thresholds

Size follows the EU definition of medium and large enterprises. The table below reflects the directive’s baseline and the way Germany implemented it in section 28 of the BSI Act, which is a useful reference point because it is one of the more literal transpositions.

Class Sector Size test
Essential entity Annex I At least 250 staff, or turnover above EUR 50 million and balance sheet above EUR 43 million
Important entity Annex I At least 50 staff, or turnover and balance sheet each above EUR 10 million
Important entity Annex II At least 50 staff, or turnover and balance sheet each above EUR 10 million
Out of scope by default Annex I or II Below 50 staff and below EUR 10 million on both turnover and balance sheet

Count the whole legal entity, not the IT department. Group structures need care: partner and linked enterprises are normally consolidated under the EU SME definition, so a small subsidiary of a large group is rarely as small as it looks on its own accounts.

Entities covered regardless of size

Some activities are considered so structurally important that the size test does not apply at all. Under section 28(1) of the German BSI Act these are treated as essential entities whatever their headcount:

  1. Operators of critical infrastructure
  2. Qualified trust service providers
  3. Top-level domain name registries
  4. DNS service providers
  5. Providers of public electronic communications networks or publicly available electronic communications services

A four-person DNS operator carries the same core duties as a utility. That is deliberate, and it is the single most common reason a company that “obviously” falls under the thresholds turns out to be regulated anyway.

The supply chain catch

Article 21(2)(d) requires in-scope entities to manage “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”. Regulated customers meet that duty by pushing requirements down their contracts.

So a 20-person software vendor selling into a hospital group is not directly regulated, but will be asked for evidence of patching discipline, access control, incident notification timelines and backup testing, and will lose the account without it. This is how NIS2 reaches well past its formal scope. If a meaningful share of your revenue comes from Annex I customers, treat the requirements as commercially binding even when they are not legally binding on you.

Essential vs important entities: what actually differs

Both classes owe the same technical measures under Article 21 and the same reporting deadlines under Article 23. The differences are supervision and penalties. Essential entities face proactive supervision, including scheduled audits and inspections. Important entities are supervised reactively, meaning regulators act on evidence of a problem.

That distinction gets misread as “important entities have it easier”. They do not, on the substance. The controls are identical. What changes is how likely you are to be examined without an incident, and how much a failure costs.

Dimension Essential entities Important entities
Typical profile Annex I, large, plus size-exempt types Annex I medium, and all of Annex II
Supervision Proactive: audits, inspections, information requests Reactive: triggered by indications of non-compliance
Article 21 measures All ten categories All ten categories
Reporting deadlines 24 h / 72 h / 1 month 24 h / 72 h / 1 month
Maximum fine EUR 10 million or 2 % of worldwide turnover, whichever is higher EUR 7 million or 1.4 % of worldwide turnover, whichever is higher

Fine levels are set by Article 34(4) and 34(5) of Directive (EU) 2022/2555 for breaches of Article 21 or Article 23.

How to run a NIS2 applicability assessment

A defensible applicability assessment takes five steps and produces a dated, signed document you can hand to a regulator, an auditor or a customer. Most organisations can complete it in a week. The output matters as much as the answer, because “we looked and concluded we were out of scope” is only a defence if you can show the working.

  1. List every legal entity in the group, with country of establishment. NIS2 applies per entity and per member state, so a group can be regulated in one country and not another.
  2. Map each entity’s actual activities against Annex I and Annex II, using the NACE-style descriptions rather than your internal business unit names. Record the reasoning for anything borderline.
  3. Apply the size test using consolidated figures where partner or linked enterprises exist. Note the reference financial year.
  4. Check the size-exempt categories separately. Trust services, DNS, TLD, telecoms and critical infrastructure override the thresholds entirely.
  5. Record the conclusion, date it, and have management sign it. Re-run it when you acquire a company, cross a threshold, or add a regulated service line.

Keep the evidence. In Germany, failing to register alone carries a fine of up to EUR 500,000, and “we did not think we were covered” is a weak position without a documented assessment behind it.

What you actually have to do: the ten measures

Article 21(2) sets out ten categories of cybersecurity risk-management measures. They are minimum requirements, applied proportionately to your risk exposure, size and the societal impact of an outage. They are also written as outcomes rather than technologies, which means an auditor will ask for evidence that each one works, not that you bought something.

# Article 21(2) requirement Evidence a regulator will ask for
a Policies on risk analysis and information system security Current risk register, review cadence, management approval
b Incident handling Playbooks, detection coverage, escalation paths, drill records
c Business continuity: backup management, disaster recovery, crisis management Tested restores with timestamps, defined RTO and RPO
d Supply chain security Supplier register, risk tiering, security clauses in contracts
e Security in acquisition, development and maintenance, including vulnerability handling and disclosure Patch SLAs by severity, published disclosure channel
f Policies to assess the effectiveness of the measures Test results over time, not a policy that says testing happens
g Basic cyber hygiene and cybersecurity training Completion rates, phishing simulation trend
h Cryptography and, where appropriate, encryption Key management, coverage of data at rest and in transit
i Human resources security, access control, asset management Joiner-mover-leaver records, privileged access review, asset inventory
j Multi-factor or continuous authentication, secured communications MFA coverage percentage, including admin and remote access

Item (f) is the one most often failed. It requires you to assess whether the other nine actually work. A policy library with no test evidence behind it satisfies (a) and fails (f), and that is a finding an auditor can write up in an afternoon.

Incident reporting: the 24 / 72 / one month chain

Significant incidents must be reported to your CSIRT or competent authority in stages: an early warning within 24 hours of becoming aware, a full incident notification within 72 hours, an intermediate report on request, and a final report no later than one month after the notification (Directive (EU) 2022/2555, Article 23(4)).

Three-stage NIS2 incident reporting timeline: early warning within 24 hours, full notification within 72 hours, final report within one month
The reporting chain under Article 23(4): 24 hour early warning, 72 hour notification, final report within one month. The clock starts at awareness, not at containment.

An incident counts as significant if it has caused or is capable of causing severe operational disruption or financial loss to you, or has affected or is capable of affecting others by causing considerable material or non-material damage (Article 23(3)). “Capable of causing” does a lot of work in that sentence: the trigger is potential impact, so you cannot wait for confirmed damage before starting the clock.

The 24 hour clock starts at awareness, not at containment, and awareness is judged on what your organisation reasonably knew. Practically, that means the on-call engineer who sees the first alert at 02:00 on a Saturday needs a decision path that reaches a named person authorised to file. Most organisations that miss the deadline miss it on internal escalation, not on the report itself.

Registration, and why management is on the hook

Registration is a separate duty from the security measures and carries its own deadline, its own national portal and its own penalty. It is also the duty most often missed, because it lands before any technical work is finished and nothing in a security roadmap reminds you about it. Germany illustrates how tight this has become. The national implementing act, the NIS2UmsuCG, entered into force on 6 December 2025 with no transition period (BSI, press release, December 2025). The statutory registration deadline fell on 6 March 2026. Only about 18,500 of an expected 29,500 organisations had registered, so the BSI granted an enforcement grace period to 31 July 2026 (SCHUTZWERK, NIS-2-Registrierung bis 31. Juli 2026, 2026).

Worth being precise about what that grace period is: it is forbearance in enforcement, not a change in the law. Organisations that missed 6 March 2026 have been in breach since then.

On accountability, Article 20 is unusually direct. Management bodies must approve the risk-management measures, oversee their implementation, and “can be held liable for infringements”. Article 20(2) requires members of management bodies to follow training, and requires member states to encourage equivalent training for staff. In Germany this is carried into section 38 of the BSI Act, where the liability cannot be contracted away.

Read together, that removes the usual escape route. Cybersecurity stops being something the board delegates and hears about quarterly.

What non-compliance costs

Penalties run to EUR 10 million or 2 percent of worldwide annual turnover for essential entities, whichever is higher, and EUR 7 million or 1.4 percent for important entities (Directive (EU) 2022/2555, Article 34). Regulators can also suspend authorisations and temporarily ban individuals from management functions in an essential entity.

Breach Consequence
Article 21 or 23 breach, essential entity Up to EUR 10 million or 2 % of worldwide annual turnover, whichever is higher
Article 21 or 23 breach, important entity Up to EUR 7 million or 1.4 % of worldwide annual turnover, whichever is higher
Failure to register (Germany) Up to EUR 500,000
Persistent non-compliance, essential entity Temporary suspension of certification or authorisation, temporary management ban
Management failure to approve or oversee Personal liability under national implementing law

The reputational cost usually arrives first. Supervisory action against an essential entity is a matter of public record in several member states, and regulated customers notice.

Where the rules still differ by country

NIS2 is a directive rather than a regulation, so each member state writes its own version and the details diverge on thresholds, registration portals and sector definitions. As of May 2026, 22 of 27 member states had adopted transposing legislation, which means multi-country groups are still working against a moving target.

That figure comes from DIGITALEUROPE and national transposition trackers (2026). The five member states still in legislative procedure are why the Commission escalated in July 2026.

The Netherlands is a useful illustration of how fast this moves: its Senate approved the Cyberbeveiligingswet on 7 July 2026, one day before the Commission filed its referral, with entry into force set for 15 August 2026.

What this means in practice for multi-country groups:

  • Register per country. Registration is a national duty with national portals and national deadlines.
  • Check thresholds locally. Several states designate additional entities below the EU size floor.
  • Watch the reporting channel. The 24 / 72 / one month structure is harmonised, but the recipient authority and the submission format are not.
  • Do not assume the strictest state sets your baseline. It usually does in practice, but the documentation still has to exist per entity.

The threat picture behind all of this has not softened. ENISA analysed 4,875 incidents in its 2025 assessment and found that ransomware accounted for 81.1 percent of cybercrime incidents affecting EU organisations, with phishing involved in around 60 percent of intrusions (ENISA, Threat Landscape 2025, October 2025).

For a deeper walkthrough of turning these obligations into day-to-day operations, our German-language companion piece NIS2 in der Praxis: von der Pflicht zum laufenden Schutz covers the operational side in detail.

Covering the requirements without building a SOC from scratch

Most of the ten measures describe continuous activity: detection, patching, access review, effectiveness testing. That is difficult to sustain alone, particularly for the mid-market organisations NIS2 has just pulled into scope for the first time.

UnifiedONE takes a community approach to that problem. A threat validated once protects every connected member automatically, which is where “Investigate Once. Protect Many.” comes from. For Microsoft environments, meaning Defender, Entra ID, Sentinel and Microsoft 365, that translates into continuous monitoring and shared threat defence operated to European data protection standards.

A central hub distributing a validated threat finding outward to connected organisations, with protection shown mid-propagation

Not sure where your entities land? Talk to the UnifiedONE team about continuous monitoring for your Microsoft environment.

Frequently asked questions about NIS2 scope

Does NIS2 apply to my company?

It applies if you operate in one of the 18 sectors listed in Annex I or Annex II of Directive (EU) 2022/2555 and meet the size thresholds, normally at least 50 staff or turnover and balance sheet each above EUR 10 million. Some entity types, including DNS providers, TLD registries, qualified trust service providers and public telecoms, are covered at any size.

Who falls under NIS2?

Essential entities and important entities. Essential entities are typically large organisations in Annex I sectors, at least 250 staff or turnover above EUR 50 million and a balance sheet above EUR 43 million, plus operators of critical infrastructure. Important entities are medium-sized Annex I organisations and all qualifying Annex II organisations. Both classes owe the same technical measures.

What is the difference between essential and important entities?

The obligations under Article 21 and the reporting deadlines under Article 23 are identical. Supervision and penalties differ. Essential entities are supervised proactively through audits and inspections and face fines up to EUR 10 million or 2 percent of worldwide turnover. Important entities are supervised reactively and face up to EUR 7 million or 1.4 percent.

Does NIS2 apply to small companies?

Organisations below 50 staff and below EUR 10 million on both turnover and balance sheet usually fall outside direct scope, unless they are one of the size-exempt types. Many are still affected indirectly, because Article 21(2)(d) requires regulated customers to manage supplier security, which arrives as contractual requirements on smaller vendors.

What does NIS2 actually require you to do?

Ten categories of risk-management measures under Article 21(2), covering risk policies, incident handling, business continuity, supply chain security, secure development and vulnerability handling, effectiveness testing, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. Plus incident reporting, registration with the national authority, and management approval and oversight.

What are the NIS2 reporting deadlines?

Three stages under Article 23(4): an early warning within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within one month of that notification. An intermediate report can be requested in between. The clock starts at awareness, not at containment.

Is NIS2 mandatory?

Yes. It has been binding EU law since Directive (EU) 2022/2555 entered into force, with a transposition deadline of 17 October 2024. Obligations apply through each member state’s national implementing law. As of May 2026, 22 of 27 member states had adopted that legislation, and the Commission referred four others to the Court of Justice in July 2026.

Does NIS2 require an SBOM?

The directive does not name a software bill of materials. Article 21(2)(e) requires security in acquisition, development and maintenance including vulnerability handling, and Article 21(2)(d) requires supply chain security. An SBOM is a common and practical way to evidence both, and regulated customers increasingly ask for one, but it is not an explicit legal requirement.

Conclusion: scope first, then evidence

The hardest part of NIS2 is not the controls. Most of the ten measures describe things a competent security team already does. The hard part is proving, on a specific date, which of your entities are covered, under which classification, in which member states, and being able to show the working when somebody asks.

Start there. Run the applicability assessment, date it, get it signed, and register where you need to. Then work through the ten measures and pay particular attention to item (f), because effectiveness testing is what separates a policy library from an actual security posture. The organisations that will handle their first supervisory contact calmly are the ones that treated scope as a documented decision rather than an assumption.


Sources

  • European Union, Directive (EU) 2022/2555 (NIS2), Articles 20, 21, 23, 34 and Annexes I and II, retrieved 2026-07-23, eur-lex.europa.eu
  • European Commission, Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity (IP/26/1499), 8 July 2026, retrieved 2026-07-23, ec.europa.eu
  • Gesetze im Internet, BSI-Gesetz (BSIG) 2025, section 28 on besonders wichtige und wichtige Einrichtungen, retrieved 2026-07-23, gesetze-im-internet.de
  • BSI, Cybersicherheitsrecht: NIS-2-Umsetzungsgesetz ab morgen in Kraft, press release, 5 December 2025, retrieved 2026-07-23, bsi.bund.de
  • SCHUTZWERK, NIS-2-Registrierung bis 31. Juli 2026: Was Unternehmen jetzt beachten sollten, 2026, retrieved 2026-07-23, schutzwerk.com
  • ENISA, Threat Landscape 2025, October 2025, retrieved 2026-07-23, enisa.europa.eu
  • DIGITALEUROPE, NIS2 Transposition Overview, 2026, retrieved 2026-07-23, digitaleurope.org

Written by

Sher Khatak

UnifiedONE

Newsletter

Get the next one in your inbox.

A useful read once a month. No spam.

See it in action

See it in action.

Turn one validated threat into protection for your whole community. Start free, or book a walkthrough with our team.