NIS2 scope checker
Do you operate in the EU?
NIS2 applies to entities that “provide their services or carry out their activities within the Union”. This includes non-EU entities that offer in-scope services into the EU. Art. 2 — Directive (EU) 2022/2555
How NIS2 decides who is in scope
NIS2 — Directive (EU) 2022/2555 — works in two moves. First, Art. 2 decides who is in scope. The main rule brings in entities of a type listed in Annex I or Annex II that are medium-sized or larger and that provide services or carry out activities in the Union. On top of that, Art. 2(2) to 2(4) pull certain entities in regardless of size: providers of public electronic communications, trust service providers, TLD name registries and DNS providers, entities a Member State identifies as critical, central and regional public administration, entities identified as critical under the CER Directive (EU) 2022/2557, and providers of domain name registration services.
Second, Art. 3 sorts the in-scope entities into two tiers. Essential entities include large Annex I entities, qualified trust service providers, TLD registries and DNS providers of any size, medium-or-larger public electronic communications providers, central-government public administration, and CER-critical entities. Everyone else in scope — medium Annex I entities, Annex II entities, non-qualified trust providers — is an important entity. The two tiers carry the same core duties but differ on supervision and on the fine ceiling.
What “medium-sized or larger” means
NIS2 borrows the size thresholds from Commission Recommendation 2003/361. An entity is medium-sized or larger if it has 50 or more staff, or an annual turnover above €10 million and a balance-sheet total above €10 million. It is large — the ceiling that makes an Annex I entity essential rather than important — at 250 or more staff, or a turnover above €50 million and a balance sheet above €43 million. Staff and financial figures aggregate partner and linked enterprises, and NIS2 disapplies the small-enterprise exemption in Art. 3(4) of the 2003/361 Annex.
What in-scope entities have to do
In-scope entities carry four duties. Governance: the management body approves and oversees the security measures and can be held liable, and its members must be trained (Art. 20). Risk management: the ten Art. 21(2) measures, from risk-analysis policies and incident handling through supply-chain security, cryptography and multi-factor authentication. Reporting: for a significant incident, an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month (Art. 23). Registration: name, address, contacts, sector and Member States filed with the competent authority (Art. 3(4)). The maximum administrative fines run to at least €10 million or 2% of worldwide turnover for essential entities, and at least €7 million or 1.4% for important entities (Art. 34).
Provision links point at the Official Journal text of Directive (EU) 2022/2555 on EUR-Lex. Article lists, the reporting clock and the fine figures were fetched from the Ansvar gateway's served NIS2 corpus; short forms of the Art. 21(2) list are ours.