Anders m. Damgren
Head of Safety & Documentation
The NIS2 directive has been transposed into national law across the EU, and in most member states the registration deadlines have already passed. Denmark’s act took effect on 1 July 2025 with registration due by 1 October 2025; Germany’s followed on 6 December 2025 with registration due by 6 March 2026. Yet many companies still don’t know whether they are covered. The answer depends on two criteria read together: your sector and your size.
Table of contents
Two criteria decide it: sector and size
The first criterion is the sector. The directive covers 18 sectors: 11 sectors of high criticality in Annex I, including energy, transport, drinking water, waste water, health and digital infrastructure, and 7 other critical sectors in Annex II, including manufacturing of machinery and electronics, food production, chemicals, waste management and digital providers.
The second criterion is size. As a general rule, you are covered if you operate within one of the sectors and are at least a medium-sized enterprise: 50 or more employees, or an annual turnover and balance sheet above €10 million.
Both criteria must be met. A machine builder with 20 employees falls outside the directive as a general rule, even though the sector is listed. A logistics company with 300 employees falls outside if its activities are not in the annexes. The assessment means holding your actual activities up against the annex descriptions, and this is where most borderline cases arise: What counts is what the company actually does, and not which industry code it is registered under.
National authorities publish scope guidance and self-assessment tools. Denmark’s Agency for Civil Protection and Preparedness offers a self-assessment tool, and Germany’s BSI runs an official scope check. Start there if you want to make the assessment yourself.
Sector
Are your actual activities listed in Annex I or Annex II of the directive?
Size
50 or more employees, or an annual turnover and balance sheet above €10 million?
Yes to both
You are covered by NIS2, and you must register with your national authority.
No to one of them
You are not directly covered, but the requirements can reach you through your customers' contracts.
Exceptions apply regardless of size, including DNS service providers, top-level domain registries and sole providers of services essential to society.
Essential or important entity: the difference
The directive distinguishes between two categories of covered entities, and the category determines the intensity of supervision and the fine levels.
Important entities are, as a general rule, companies in the covered sectors with 50 to 249 employees, or an annual turnover above €10 million and a balance sheet above €10 million.
Essential entities are, as a general rule, companies in the Annex I sectors with 250 employees or more, or an annual turnover above €50 million and a balance sheet above €43 million. Certain entity types also count as essential regardless of size, particularly within digital infrastructure.
The cybersecurity requirements are broadly the same for both categories. The difference lies in supervision, where essential entities are subject to proactive oversight, and in sanctions: Member states must provide for maximum fines of at least €10 million or 2 % of global annual turnover for essential entities, and at least €7 million or 1.4 % for important entities. The levels are set in the directive and mirrored in the national acts.
The cybersecurity requirements are broadly the same for both categories. The difference lies in supervision and in sanctions. Certain entity types count as essential regardless of size.
Covered regardless of size: the exceptions
The size criterion has exceptions. Certain entities are covered however small they are, including DNS service providers, top-level domain name registries and qualified trust service providers.
Member states can also cover entities below the size thresholds where the entity is the sole provider of a service essential to society, or where a disruption of its service could have a significant impact on public safety or health. If you deliver a niche service into critical infrastructure, it is worth checking whether one of the exceptions applies to you, even with fewer than 50 employees.
Not directly covered? The requirements can still reach you
Covered entities are required to manage the security of their supply chain. They must assess security-related aspects of their supplier relationships, and in practice they translate that duty into contract requirements.
If you supply equipment or services into energy, transport, utilities or other covered sectors, you are therefore likely to meet requirements for documented security practices from your customers, even though you are not named in any law yourself. What those requirements typically look like, and how to prepare for them, is covered in our article on NIS2 for suppliers.
The registration deadlines have passed: what to do now
Registration deadlines are national, and in both Denmark and Germany they have already expired. If you find that you are covered and have not yet registered, the answer is simple: Do it now, with your national authority. Supervision is ramping up, and a missing registration does not improve with age.
Registration is also the smallest part of the task. The substantive requirements, from management accountability through risk management to incident reporting, apply on an ongoing basis. What they involve in practice is covered in our article on NIS2 requirements in practice.
If you are unsure where you stand, a gap analysis is the natural first step. Our free NIS2 gap workshop walks through 21 control areas with your team in three hours, so you know what is in place and what is missing.
Contact us
Still unsure whether NIS2 applies to you, or want to map how far you are with the requirements? Book a free NIS2 gap workshop, or contact us through PS Engineering for a practical look at your situation.
FAQ
NIS2 is the EU directive on cybersecurity, Directive (EU) 2022/2555. It sets requirements for risk management, incident handling and management accountability in companies within critical sectors, and it is implemented through national legislation in each member state.
The directive lists 18 sectors: 11 high-criticality sectors in Annex I, including energy, transport, water, health and digital infrastructure, and 7 other critical sectors in Annex II, including manufacturing, food, chemicals, waste and digital providers.
The categories broadly follow company size and sector. Essential entities are the largest, face proactive supervision and higher maximum fines of at least €10 million or 2 % of global annual turnover. Important entities are supervised on specific grounds, with maximum fines of at least €7 million or 1.4 %.
As a general rule no, unless one of the exceptions applies, for example as a DNS service provider or as the sole provider of a service essential to society. But if you supply covered companies, you can meet equivalent requirements through your contracts.
Not directly. But your customers are required to manage the security of their supply chain, and many of them therefore set contract requirements for documented security practices at their suppliers.
The registration duty still applies. Register with your national authority as soon as possible, and then start documenting how you meet the substantive requirements.
Yes, public administration is among the covered sectors, so the directive covers public bodies as well as private companies. The exact national scope follows from each member state’s implementing act.