Who is covered by NIS2? Criteria and how to check

Picture of Anders m. Damgren

Anders m. Damgren

Head of Safety & Documentation

The NIS2 directive has been transposed into national law across the EU, and in most member states the registration deadlines have already passed. Denmark’s act took effect on 1 July 2025 with registration due by 1 October 2025; Germany’s followed on 6 December 2025 with registration due by 6 March 2026. Yet many companies still don’t know whether they are covered. The answer depends on two criteria read together: your sector and your size.

Table of contents

Two criteria decide it: sector and size

The first criterion is the sector. The directive covers 18 sectors: 11 sectors of high criticality in Annex I, including energy, transport, drinking water, waste water, health and digital infrastructure, and 7 other critical sectors in Annex II, including manufacturing of machinery and electronics, food production, chemicals, waste management and digital providers.

The second criterion is size. As a general rule, you are covered if you operate within one of the sectors and are at least a medium-sized enterprise: 50 or more employees, or an annual turnover and balance sheet above €10 million.

Both criteria must be met. A machine builder with 20 employees falls outside the directive as a general rule, even though the sector is listed. A logistics company with 300 employees falls outside if its activities are not in the annexes. The assessment means holding your actual activities up against the annex descriptions, and this is where most borderline cases arise: What counts is what the company actually does, and not which industry code it is registered under.

National authorities publish scope guidance and self-assessment tools. Denmark’s Agency for Civil Protection and Preparedness offers a self-assessment tool, and Germany’s BSI runs an official scope check. Start there if you want to make the assessment yourself.

Sector

Are your actual activities listed in Annex I or Annex II of the directive?

and

Size

50 or more employees, or an annual turnover and balance sheet above €10 million?

Yes to both

You are covered by NIS2, and you must register with your national authority.

No to one of them

You are not directly covered, but the requirements can reach you through your customers' contracts.

Exceptions apply regardless of size, including DNS service providers, top-level domain registries and sole providers of services essential to society.

Essential or important entity: the difference

The directive distinguishes between two categories of covered entities, and the category determines the intensity of supervision and the fine levels.

Important entities are, as a general rule, companies in the covered sectors with 50 to 249 employees, or an annual turnover above €10 million and a balance sheet above €10 million.

Essential entities are, as a general rule, companies in the Annex I sectors with 250 employees or more, or an annual turnover above €50 million and a balance sheet above €43 million. Certain entity types also count as essential regardless of size, particularly within digital infrastructure.

The cybersecurity requirements are broadly the same for both categories. The difference lies in supervision, where essential entities are subject to proactive oversight, and in sanctions: Member states must provide for maximum fines of at least €10 million or 2 % of global annual turnover for essential entities, and at least €7 million or 1.4 % for important entities. The levels are set in the directive and mirrored in the national acts.

Important entity
Essential entity
Employees
50–249
250 or more
Turnover and balance sheet
Turnover above €10m and balance sheet above €10m
Turnover above €50m and balance sheet above €43m
Supervision
On specific grounds
Proactive
Maximum fine
€7 million or 1.4 % of global annual turnover
€10 million or 2 % of global annual turnover

The cybersecurity requirements are broadly the same for both categories. The difference lies in supervision and in sanctions. Certain entity types count as essential regardless of size.

Covered regardless of size: the exceptions

The size criterion has exceptions. Certain entities are covered however small they are, including DNS service providers, top-level domain name registries and qualified trust service providers.

Member states can also cover entities below the size thresholds where the entity is the sole provider of a service essential to society, or where a disruption of its service could have a significant impact on public safety or health. If you deliver a niche service into critical infrastructure, it is worth checking whether one of the exceptions applies to you, even with fewer than 50 employees.

Not directly covered? The requirements can still reach you

Covered entities are required to manage the security of their supply chain. They must assess security-related aspects of their supplier relationships, and in practice they translate that duty into contract requirements.

If you supply equipment or services into energy, transport, utilities or other covered sectors, you are therefore likely to meet requirements for documented security practices from your customers, even though you are not named in any law yourself. What those requirements typically look like, and how to prepare for them, is covered in our article on NIS2 for suppliers.

The registration deadlines have passed: what to do now

Registration deadlines are national, and in both Denmark and Germany they have already expired. If you find that you are covered and have not yet registered, the answer is simple: Do it now, with your national authority. Supervision is ramping up, and a missing registration does not improve with age.

Registration is also the smallest part of the task. The substantive requirements, from management accountability through risk management to incident reporting, apply on an ongoing basis. What they involve in practice is covered in our article on NIS2 requirements in practice.

If you are unsure where you stand, a gap analysis is the natural first step. Our free NIS2 gap workshop walks through 21 control areas with your team in three hours, so you know what is in place and what is missing.

Contact us

Still unsure whether NIS2 applies to you, or want to map how far you are with the requirements? Book a free NIS2 gap workshop, or contact us through PS Engineering for a practical look at your situation.

FAQ

NIS2 is the EU directive on cybersecurity, Directive (EU) 2022/2555. It sets requirements for risk management, incident handling and management accountability in companies within critical sectors, and it is implemented through national legislation in each member state.

The directive lists 18 sectors: 11 high-criticality sectors in Annex I, including energy, transport, water, health and digital infrastructure, and 7 other critical sectors in Annex II, including manufacturing, food, chemicals, waste and digital providers.

The categories broadly follow company size and sector. Essential entities are the largest, face proactive supervision and higher maximum fines of at least €10 million or 2 % of global annual turnover. Important entities are supervised on specific grounds, with maximum fines of at least €7 million or 1.4 %.

As a general rule no, unless one of the exceptions applies, for example as a DNS service provider or as the sole provider of a service essential to society. But if you supply covered companies, you can meet equivalent requirements through your contracts.

Not directly. But your customers are required to manage the security of their supply chain, and many of them therefore set contract requirements for documented security practices at their suppliers.

The registration duty still applies. Register with your national authority as soon as possible, and then start documenting how you meet the substantive requirements.

Yes, public administration is among the covered sectors, so the directive covers public bodies as well as private companies. The exact national scope follows from each member state’s implementing act.

Are you struggling to find qualified workforce for your project?

Fill our form and and receive a call within 24 hours.

We respect your privacy and will only use your personal data to administer your account and provide requested products/services. We may contact you about our products/services and other content of interest. Please indicate below if you consent to being contacted.

Opt-out anytime. See our Privacy Policy for details on how to unsubscribe and how we protect your privacy. By submitting, you allow Plant supervision to process your info for requested content. By clicking submit below, you consent to allow Plant supervision to store and process the personal information submitted above to provide you the content requested.