Does NIS2 apply to me?
NIS2 covers medium and large companies in 18 sectors, and some smaller ones regardless of size. Answer five questions about your sector, size and EU footprint, and see whether you are an essential or important entity, or a supplier your customers will hold to NIS2 by contract.
NIS2 applies to medium and large companies (50 or more staff, or over EUR 10 million in both turnover and balance sheet) in the sectors in its Annexes I and II that provide services in the EU. It includes cloud, data centre and managed service providers. Some entities are covered at any size, such as DNS and trust service providers. Large Annex I entities are essential; the rest are important.
Result
Medium-sized entities in Annex I sectors, and medium or large entities in Annex II sectors, are important entities. The duties are the same as for essential entities; supervision is ex post, after evidence of non-compliance, and the fine ceiling is lower. Medium-sized public electronic communications providers are essential, not important. Non-EU cloud, data centre, CDN, managed and managed security service providers must designate an EU representative.
- Confirm: check the transposing law in each member state where you operate: registration deadlines, the competent authority and any national additions differ.
- Register: with the national authority. Cloud, data centre, CDN, managed and managed security service providers register in the member state of their main establishment.
- Gap-assess: against the Article 21(2) measures. ISO 27001 covers most of them; see the ISO 27001 checker.
- Rehearse: the 24-hour early warning. Most teams have never reported an incident to a regulator on a clock.
Who NIS2 covers
NIS2 applies to public and private entities of the types listed in its two annexes that are medium-sized or larger and provide services or carry out activities in the EU. Annex I (high criticality): energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure (including cloud computing, data centres, content delivery networks, DNS, trust services and electronic communications), ICT service management for businesses (managed and managed security service providers), public administration and space. Annex II: postal and courier, waste management, chemicals, food, manufacturing (including medical devices, electronics, machinery and vehicles), digital providers (online marketplaces, search engines, social networks) and research.
The size cap, stated exactly
Article 2(1) applies NIS2 to entities of a type in Annex I or II that qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed those ceilings. That Recommendation defines a small enterprise as one with fewer than 50 staff and annual turnover and/or balance sheet total of EUR 10 million or less. So an entity in an Annex sector is in scope if it has 50 or more staff, or if both its turnover and its balance sheet exceed EUR 10 million. Headcount and financials of partner and linked enterprises are generally added in, figures come from the latest approved accounts, and a change of category needs two consecutive accounting periods over or under a ceiling. Two common errors: 50 staff does not put you in scope on its own, because you must also be in an Annex sector; and EUR 7 million is the minimum fine ceiling for important entities, not a turnover threshold.
Small and micro entities are out, except where Article 2(2) applies: public electronic communications providers, trust service providers, TLD registries and DNS providers, the sole provider of an essential service in a member state, entities whose disruption would have significant public safety, security, health or systemic impact, and certain public administration bodies. Articles 2(3) and 2(4) add critical entities under the CER Directive and domain name registration services, also regardless of size. Financial entities follow DORA for ICT risk and incident reporting, which NIS2 treats as sector-specific law.
Essential or important
The obligations are the same; supervision and fines differ. Essential entities (mainly large Annex I entities, plus some designated at any size) face ex ante supervision, with fines up to at least EUR 10 million or 2% of worldwide turnover. Important entities (everyone else in scope) face ex post supervision, with fines up to at least EUR 7 million or 1.4%. These are minimum ceilings: member states can set higher ones.
Transposition varies
NIS2 is a directive, so it applies through national law. Member states had to transpose it by 17 October 2024. Many were late, and in 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposition. National laws differ on registration deadlines, authorities and penalties, so check the law in each country where you operate. On 20 January 2026 the Commission proposed targeted amendments to simplify NIS2; that is a proposal, not adopted law.
Sources
- Directive (EU) 2022/2555 (NIS2 Directive), EUR-Lex
- Commission Recommendation 2003/361/EC (SME definition), EUR-Lex
- European Commission: NIS2 Directive
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Does NIS2 apply to SaaS companies?
It can. Cloud computing service providers are an Annex I sector, and the Directive's recitals list Software as a Service as a cloud service model. Whether a particular SaaS product counts depends on national interpretation, so confirm it with the authority in your main EU market.
Does NIS2 apply to non-EU companies?
Yes, if they provide services in the EU and meet the criteria. Non-EU cloud, data centre, CDN, managed service, managed security service and certain digital providers must designate a representative in the EU.
What are the NIS2 incident reporting deadlines?
An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of the notification.
What are the NIS2 fines?
For essential entities, a maximum of at least EUR 10 million or 2% of worldwide annual turnover, whichever is higher. For important entities, at least EUR 7 million or 1.4%. Member states can set higher ceilings.
Has every EU country transposed NIS2?
No. The deadline was 17 October 2024, and several member states missed it; the Commission has referred four to the Court of Justice. Check the transposition status in each country where you operate.
Is every company with 50 employees in scope of NIS2?
No. Size alone never brings you in. You must also be an entity of a type listed in Annex I or II, such as cloud computing, managed services, energy, health or manufacturing, and provide services in the EU.
Do NIS2 requirements apply to suppliers?
Not directly, unless the supplier is in scope itself. But in-scope entities must manage the security of their direct suppliers under Article 21(2)(d), so suppliers get NIS2 questionnaires and contract clauses from their customers.
Is ISO 27001 enough for NIS2?
Not on its own. ISO 27001 covers most Article 21 measures, but NIS2 adds registration, management accountability and training, and 24-hour incident reporting to the authorities.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.