← Thought Leadership

Compliance Guides

Does NIS2 apply to my business?

NIS2 applies to medium-sized and larger entities in a defined list of essential and important sectors, plus some entities regardless of size. Here is how to check whether you are in scope, sector first, then size.

Martin Foerster
Co-founder
· Updated on · 8 min read
High-voltage electricity transmission pylons against a sunset sky

Photo: Matthew Henry / Unsplash

New to the topic? Start with What sovereign compliance actually means.

NIS2 sorts organisations with two filters, run in order: your sector, then your size. It applies to your business if you operate in one of its listed essential or important sectors and are generally medium-sized or larger: at least 50 employees, or annual turnover or balance sheet above €10 million. Some entities are in scope regardless of size. So the answer comes down to those two readings, sector and size. Here is how to check both.

Who does NIS2 apply to?

NIS2 is the second Network and Information Security Directive, and it names the sectors it covers in two annexes. Annex I holds the sectors of highest criticality. Annex II holds the other critical sectors. Read your main activity against both lists. If it appears in neither, NIS2 does not reach you directly.

Annex I: sectors of high criticalityAnnex II: other critical sectors
EnergyPostal and courier services
TransportWaste management
BankingManufacture, production and distribution of chemicals
Financial market infrastructuresProduction, processing and distribution of food
HealthManufacturing (e.g. medical devices, computers and electronics, machinery, motor vehicles)
Drinking waterDigital providers (online marketplaces, search engines, social networking platforms)
Waste waterResearch organisations
Digital infrastructure
ICT service management (business-to-business)
Public administration
Space

NIS2 replaced the original 2016 NIS Directive and widened these lists considerably, so many organisations that sat outside the first regime are now inside this one. If you are unsure which other EU regimes sit alongside it, start with which EU regulations apply to your company.

The size threshold

Sitting in a listed sector is necessary, and on its own it is not enough. NIS2 adds a second filter for size: it generally reaches medium-sizedand larger entities, those with at least 50 employees, or annual turnover or annual balance sheet total above €10 million, operating in the Annex I or Annex II sectors.

The size filter has carve-outs. A set of entities is in scope regardless of size, because what they run is too load-bearing for a threshold to excuse. Among them are certain providers of critical digital infrastructure (such as DNS service providers, top-level-domain name registries, and providers of public electronic communications networks or services) and specified public-administration entities. If your service is one a member state cannot afford to see disrupted, size will not exempt you.

Essential vs important entities

Once NIS2 applies, it places you in one of two categories. That category sets how intensely a regulator supervises you. It does not change the security measures you owe, which are the same for both.

Definition
Essential entity (NIS2)
An in-scope entity in one of NIS2’s highest-criticality sectors (Annex I) that meets the size threshold, or that is designated in scope regardless of size. Essential entities face proactive, ex-ante supervision: regulators can inspect them without waiting for an incident.
Definition
Important entity (NIS2)
An in-scope entity in one of NIS2’s other listed sectors (Annex II), or an Annex I entity that does not reach the essential-entity threshold. Important entities face reactive, ex-post supervision, where regulators act when there is evidence of non-compliance. They must meet the same core security measures.

Both categories carry the same core risk-management and reporting duties. What changes between them is supervisory intensity: essential entities are watched proactively, important entities are held to account after the fact. The fine ceilings also split by tier, and we set them out in what non-compliance costs, below.

What NIS2 requires

For an in-scope entity, NIS2 comes down to three obligations:

  • Risk-management measures (Article 21): a set of appropriate technical, operational, and organisational measures, including policies on risk analysis and information-system security, incident handling, business continuity and backup, supply-chain security, vulnerability handling, encryption, access control, and the use of multi-factor authentication.
  • Incident reporting (Article 23), a phased notification of significant incidents to your CSIRT or competent authority: an early warning within 24 hours, a fuller incident notification within 72 hours, and a final report within one month.
  • Management-body accountability: senior management must approve and oversee the cybersecurity measures, can be held liable for failures, and must undergo training.

That third obligation puts the accountability at the top of the organisation by design: the management body has to sign off on the measures and can be held liable for them. The same operational-resilience pattern runs through other recent EU digital law, notably DORA for financial entities. If you sit in banking or financial market infrastructure, check whether DORA applies to your company too, since the two regimes can overlap.

What non-compliance costs

The penalty side of NIS2 has two parts worth reading closely: fines calculated on global group revenue, and enforcement powers that reach individual executives.

The two fine tiers

Essential entities (Annex I)Important entities (Annex II)
Maximum administrative fine€10 million or 2% of total worldwide annual turnover, whichever is higher€7 million or 1.4% of total worldwide annual turnover, whichever is higher
Legal basisArticle 34(4)Article 34(5)

The turnover base is the whole group, measured worldwide

This is the detail that sets the size of the number. Article 34 bases the fine on 2% of the total worldwide annual turnover of the undertaking to which the entity belongs, the whole group the in-scope entity is part of.

That means:

  • The base is the group’s global revenue, including the parts of the group outside the subsidiary that happens to be in scope.
  • A large non-EU group with a modest European subsidiary is exposed against its worldwide turnover.
  • “Our European operation is small” is not a defence, and it is not a cap.

For a group with €5 billion in worldwide turnover, a 2% ceiling is a maximum fine of €100 million, per infringement.

These are floors that member states can exceed

Article 34 sets fines at “a maximum of at least” those figures. Member states must meet those levels and are free to exceed them, and some have. Check the national implementing law where you operate: Germany’s transposition, for example, has been reported to set a higher ceiling for essential entities and to provide for personal fines against managers. Verify the current national figures before relying on them.

Article 34(6) also allows member states to impose periodic penalty payments to force an entity to stop an ongoing infringement, a running daily cost until you fix it.

The part that reaches individuals

Fines are the visible penalty. The powers that reach named individuals are the ones that tend to change behaviour. Article 20 requires the management body to approve the cybersecurity measures, oversee their implementation, and undergo training, and management can be held personally liable for failures.

Beyond fines, Article 32(5) hands supervisory authorities two powers over essential entities that no amount of budget can settle:

  • suspend the entity’s certification or authorisation for some or all of its services; and
  • temporarily ban a natural person, at chief-executive or legal-representative level, from exercising managerial functions.

A fine is a cost the company absorbs. A ban on holding managerial functions attaches to a named person, and no budget line covers it. That is the design: NIS2 places the duty on the management body itself, so the pressure lands on the people who set the security posture.

One limit worth knowing

Under Article 35, where a GDPR fine has already been imposed for the same conduct, the NIS2 authority may not also impose an administrative fine for that same conduct, though the other enforcement measures remain available. NIS2 stacks alongside GDPR; it does not double-fine identical facts.

What this looks like in practice

A global cloud and search company. Cloud computing and data centres sit in Annex I (digital infrastructure), so a large provider is an essential entity: proactive supervision, and a maximum fine of 2% of the group’s worldwide turnover. At that scale, 2% is a number measured in billions.

A German vehicle manufacturer. Manufacture of motor vehicles sits in Annex II, so a carmaker is an important entity: reactive supervision, and a maximum of 1.4% of group worldwide turnover, one tier below the 2% ceiling. Still an enormous figure on automotive revenues, but the tier matters and it is routinely reported wrongly.

A non-EU manufacturer of network components. Manufacture of computer, electronic and optical products is in Annex II, so a component maker carrying out activities in the Union is an important entity at 1.4% of group worldwide turnover, and the group means the Chinese, US, or Korean parent behind the European sales office.

But NIS2 is only one of three levers pointed at that company, and for a pure exporter it may not even be the one that bites first. Product cybersecurity is governed by the Cyber Resilience Act, which reaches any manufacturer placing a product with digital elements on the EU market (no European establishment required) and carries higher maximum fines of €15 million or 2.5% of worldwide turnover. On top of that, its European telecoms and infrastructure customers are themselves essential entities, and Article 21(2)(d) requires them to push supply-chain security requirements down the contract chain. We set out how those three regimes interact, and which one applies to you, in EU cybersecurity rules for non-EU manufacturers.

If your business is outside the EU

NIS2 is a directive: each member state transposes it into national law, so the precise thresholds, registration duties, and penalties vary by country. You need to check the implementing law of each member state where you operate, going beyond the directive text itself.

A non-EU establishment does not automatically place you outside NIS2. Certain digital service providers, such as DNS providers, cloud computing services, online marketplaces, and search engines, that offer services in the EU must designate a representative established in the Union, and fall under the jurisdiction of the member state where that representative sits. Doing business in Europe generally means meeting European requirements, wherever you are based, a point we cover more broadly in non-EU company selling into the EU. The same reach applies under the EU AI Act if you also build or deploy AI systems.

How COMPLY.Reg helps

COMPLY.Reg takes NIS2, and its national transpositions, and turns the directive into a working set of requirements. It uses AI to extract the individual Article 21 measures and Article 23 reporting duties, map them to your controls, and track the evidence that proves each one, with a human reviewing the result. The data stays where it lives: your source documents remain on your own systems, and your compliance data is processed in the EU. It is built for European companies and for companies outside Europe that need to meet EU requirements to do business in the EU, and our information-security posture is on track for ISO 27001 and SOC 2 in 2027.

Frequently asked questions

Who does NIS2 apply to?
Medium-sized and larger entities operating in one of the sectors listed in NIS2's Annex I (essential: energy, transport, banking, health, digital infrastructure, public administration and others) or Annex II (important: postal, waste, chemicals, food, manufacturing, digital providers, research). Some entities, such as certain critical digital-infrastructure and public-administration providers, are in scope regardless of size.
What size does a company have to be for NIS2 to apply?
Generally medium-sized or larger, at least 50 employees, or annual turnover or balance sheet total above €10 million, if it operates in a listed sector. Some entities are in scope regardless of size, such as certain digital-infrastructure and public-administration providers.
What is the difference between essential and important entities?
Essential entities face proactive, ex-ante supervision; important entities face reactive, ex-post supervision. Both must meet the same core risk-management and incident-reporting requirements.
Does NIS2 apply to companies outside the EU?
It can. NIS2 is transposed into national law in each member state, and certain digital service providers offering services in the EU must designate an EU representative even without an EU establishment.
How large can NIS2 fines be?
Up to €10 million or 2% of total worldwide annual turnover (whichever is higher) for essential entities, and €7 million or 1.4% for important entities. The base is the whole group's global revenue, so the EU entity's size does not cap it, and these are floors that member states may exceed.

Sources