Does NIS2 apply to your EU project?
If someone has told you "just check if you're in one of the 18 sectors", they have given you about 20% of the answer. Working out whether NIS2 applies to your EU project is genuinely tricky, and the trickiness is by design. This is the entity-side companion to the product-side question — for the latter, see Does the Cyber Resilience Act apply to your product? .
Three things make this harder than a typical compliance check:
- NIS2 regulates entities, not projects. The directive applies to legal persons (a company, an agency, an association). If your "project" is a product line, a research consortium or a digital service, the relevant question is which legal entity operates it, where that entity is established, and what it does. A single entity can run many projects; a single project can involve many entities — and each is assessed on its own.
- Group structures matter — sometimes. The size-cap test uses the EU SME definition in Commission Recommendation 2003/361/EC , which requires you to aggregate staff and financial data across partner and linked enterprises. Two entities that look small in isolation can be "medium" once you consolidate. But for jurisdiction and registration, each legal person stands alone.
- NIS2 is a directive, not a regulation. Member States had to transpose it by 17 October 2024 (Directive (EU) 2022/2555, Article 41 ; European Commission summary ), but many missed the deadline. As of early 2026, transposition status, registration portals, scope tweaks and sanction levels still vary materially across the 27 Member States — see the ECSO NIS2 Transposition Tracker for the live picture. Two identical companies in Berlin and Brussels can be in scope on different dates, register with different authorities and face different "gold-plating".
Do not stop at "are we in a covered sector?" Walk every step.
The decision tree
flowchart TD
Start([Start: assess each legal entity separately]):::startNode --> S1{"Step 1
Established in an
EU Member State?
Or Article 26 1 b category
offering services in the EU
via an EU representative?"}
S1 -->|No| Out1["Out of direct scope
Watch for supply-chain
flow-down via EU customers"]:::outNode
S1 -->|Yes| S2{"Step 2
Activity listed in
Annex I or Annex II
of Directive EU 2022 2555?"}
S2 -->|No| Out2["Out of direct scope
Check Member-State add-ons
and supply-chain cascade"]:::outNode
S2 -->|Yes| S3{"Steps 3 and 4
Medium or larger
AFTER group consolidation?
≥50 staff OR turnover
OR balance sheet >€10M
per Rec. 2003 361 EC
partner pro-rata + linked 100%"}
S3 -->|Yes| S6{"Step 6
Annex I sector
AND large enterprise?"}
S3 -->|No| S5{"Step 5
Regardless-of-size
under Article 2 2?
Trust service providers,
DNS, TLD, public e-comms,
sole provider, CER critical,
public administration"}
S5 -->|Yes| S6
S5 -->|No| OutSmall["Out of scope
Small or micro enterprise"]:::outNode
S6 -->|Yes| Essential["ESSENTIAL ENTITY
Ex-ante + ex-post supervision
Fines ≥ €10M or 2%
worldwide annual turnover"]:::essentialNode
S6 -->|No| Important["IMPORTANT ENTITY
Ex-post supervision
Fines ≥ €7M or 1.4%
worldwide annual turnover"]:::importantNode
Essential --> S7{"Step 7
DORA or other
lex specialis applies?
Article 4 equivalence test"}
Important --> S7
S7 -->|Yes| LexSpec["Sector-specific act
displaces NIS2 substantive duties
Registration may still apply"]:::actionNode
S7 -->|No| S8["Step 8
Identify Member State,
competent authority and CSIRT
via national transposition"]:::actionNode
LexSpec --> S8
S8 --> S9["Step 9
Register under Article 3
paragraphs 3 and 4
plus Article 27 if applicable"]:::actionNode
S9 --> S10["Step 10
Implement Article 21 measures
Article 23 incident reporting
24h early warning
72h notification
1 month final report"]:::actionNode
S10 --> S11["Step 11
Manage penalty exposure
under Article 34
Train management Article 20"]:::actionNode
classDef startNode fill:#e1f5fe,stroke:#01579b,stroke-width:2px,color:#000
classDef outNode fill:#ffebee,stroke:#c62828,stroke-width:2px,color:#000
classDef essentialNode fill:#ffe0b2,stroke:#e65100,stroke-width:3px,color:#000
classDef importantNode fill:#fff9c4,stroke:#f57f17,stroke-width:2px,color:#000
classDef actionNode fill:#e8f5e9,stroke:#2e7d32,stroke-width:1.5px,color:#000Blue is the entry point. Red endpoints mean the entity is out of direct scope (though supply-chain cascade may still pull NIS2-style requirements through customer contracts). Orange denotes Essential entity classification and the heavier supervision/penalty regime; yellow denotes Important entity classification. Green nodes are the operational follow-on steps once you have confirmed scope. The diamond labelled "Steps 3 and 4" deliberately merges the raw size test with the partner/linked-enterprise consolidation rule, because in practice you must run them together — answering Step 3 on standalone figures before consolidating is the single most common scoping error.
Step 1 — the geographic and establishment test
The question: Is the entity established in the EU? If not, does it nevertheless offer in-scope services in the EU?
The rule. Under Article 26(1) of the directive, "Entities falling within the scope of this Directive shall be considered to fall under the jurisdiction of the Member State in which they are established", with three carve-outs:
- (a) Providers of public electronic communications networks/services fall under the jurisdiction of the Member State where they provide their services.
- (b) DNS service providers, TLD name registries, domain name registration service providers, cloud computing providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, of online search engines and of social networking services platforms fall under the jurisdiction of the Member State of their main establishment in the Union.
- (c) Public administration entities fall under the jurisdiction of the Member State that established them.
The "main establishment" is defined in Article 26(2) using a cascading test: (i) the Member State where decisions on cybersecurity risk-management measures are predominantly taken; failing that, (ii) where cybersecurity operations are carried out; failing that, (iii) where the entity has the establishment with the highest number of employees in the Union.
If a category-(b) provider is not established in the Union but offers services in the Union, Article 26(3) obliges it to designate an EU representative in one of the Member States where the services are offered. The entity then falls under the jurisdiction of the representative's Member State. The Commission's January 2026 proposal would extend this representative-designation duty more broadly to any essential or important entity offering services in the Union without being established there (COM(2026) 13 proposal ).
Note also Article 2(7)–(8) of NIS2: the directive does not apply to public administration entities carrying out activities in the areas of national security, public security, defence or law enforcement, and is without prejudice to Member States' responsibility for safeguarding national security (EUR-Lex consolidated text ).
Decision points
- The entity has a legal establishment in at least one EU Member State. → Continue.
- The entity is not EU-established, but it is in one of the Article 26(1)(b) digital/ICT categories and offers those services in the EU. → It must appoint an EU representative; treat the representative's Member State as the home jurisdiction and continue.
- Neither of the above. → NIS2 does not impose direct obligations on the entity (although supply-chain flow-down to EU customers may still drive contractual cybersecurity requirements).
Step 2 — the sectoral test (Annex I and Annex II)
The question: Does the entity's activity fit a sub-sector listed in Annex I (sectors of high criticality) or Annex II (other critical sectors) of Directive (EU) 2022/2555?
The directive covers 18 sectors in total — 11 in Annex I and 7 in Annex II (European Commission – NIS2 Directive page ; EUR-Lex summary ).
Annex I — sectors of high criticality
- Energy — electricity (including undertakings, DSOs, TSOs, producers, NEMOs, aggregation/demand response/storage market participants), district heating and cooling, oil (pipelines, production/refining/treatment, central stockholding), gas (supply, distribution, transmission, storage, LNG), and hydrogen.
- Transport — air, rail, water (maritime/inland waterways and port operators) and road.
- Banking — credit institutions as defined under EU banking law.
- Financial market infrastructures — operators of trading venues and central counterparties.
- Health — healthcare providers, EU reference laboratories, R&D of medicinal products, manufacturers of basic pharmaceutical products and preparations, manufacturers of critical medical devices.
- Drinking water — suppliers and distributors of water for human consumption.
- Waste water — undertakings collecting, disposing of or treating urban, domestic or industrial waste water.
- Digital infrastructure — Internet exchange points, DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, trust service providers, providers of public electronic communications networks, providers of publicly available electronic communications services.
- ICT service management (business-to-business) — managed service providers (MSPs) and managed security service providers (MSSPs).
- Public administration — central government entities; regional administrations under certain conditions; Member States may also bring local administrations into scope.
- Space — operators of ground-based infrastructure supporting space-based services (excluding providers of public electronic communications networks).
Annex II — other critical sectors
- Postal and courier services.
- Waste management (where this is the principal economic activity).
- Manufacture, production and distribution of chemicals.
- Production, processing and distribution of food.
- Manufacturing — of medical devices and in vitro diagnostic medical devices; of computer, electronic and optical products; of electrical equipment; of machinery and equipment n.e.c.; of motor vehicles, trailers and semi-trailers; of other transport equipment (NACE Rev. 2 references in the Annex).
- Digital providers — providers of online marketplaces, online search engines and social networking services platforms.
- Research — research organisations whose primary goal is to carry out applied research or experimental development with a view to exploiting results for commercial purposes (excluding higher-education institutions).
This list, including the sub-sectors and the entity types covered, is the authoritative reference in the Annexes to Directive (EU) 2022/2555 ; third-party summaries should not be relied upon if they conflict with the official Annexes.
Decision points
- My activity matches an Annex I sub-sector. → Likely Essential if large; Important if medium (unless Member State designates otherwise). Continue.
- My activity matches an Annex II sub-sector. → Likely Important. Continue.
- No match in either Annex. → You are out of direct scope, but be aware of (i) Member-State add-ons under Article 2(2)(b)–(e) and (ii) supply-chain flow-down (Article 21(2)(d)), which often pushes NIS2-style requirements down through contracts to suppliers outside scope.
A note on watching the goalposts move. On 20 January 2026 the Commission proposed targeted NIS2 amendments that would refine these sectoral definitions (e.g. a 1 MW generation-capacity threshold for electricity producers, and tweaks for healthcare, hydrogen and chemicals), add submarine data-cable infrastructure and EU Digital Identity/Business Wallet providers as essential entities, and introduce a "small mid-cap" category (Commission cybersecurity package Q&A ; Freshfields commentary ). These are proposals, not law; the existing Annexes apply until adoption and a 12-month transposition window has elapsed.
Step 3 — the size-cap test
The question: Is the entity at least a medium enterprise within the meaning of Commission Recommendation 2003/361/EC ?
NIS2's scope is built on the EU SME definition. From Article 2(1) of NIS2 , the directive applies to entities in Annex I or II that qualify as medium-sized enterprises, or exceed the ceilings for medium-sized enterprises, under Article 2 of the Annex to Recommendation 2003/361/EC.
The Recommendation defines the relevant tiers as follows (Annex, Article 2 of Recommendation 2003/361/EC ):
| Tier | Headcount | Turnover | Balance-sheet total |
|---|---|---|---|
| Micro | < 10 | ≤ €2 M | ≤ €2 M |
| Small | < 50 | ≤ €10 M | ≤ €10 M |
| Medium | < 250 | ≤ €50 M | ≤ €43 M |
| Large | ≥ 250 | > €50 M | > €43 M |
The qualification logic is: an enterprise is medium if it has 50–249 staff or turnover/balance sheet above the small-enterprise ceilings (€10 M) but below the medium ceilings (€50 M turnover / €43 M balance sheet). An enterprise is large if it exceeds 250 staff and exceeds either €50 M turnover or €43 M balance sheet — i.e. it falls outside the SME definition entirely.
For NIS2, this maps onto entity classification (Article 3(1) of NIS2 ):
- Large (exceeds the ceilings for medium) in an Annex I sector → Essential entity.
- Medium in an Annex I sector → Important entity (unless Member State designates as Essential).
- Medium or large in an Annex II sector → Important entity (unless Member State designates as Essential).
- Micro/small → generally out of scope, with the major exceptions listed in Step 5.
Decision points
- Headcount ≥ 50 staff. → Continue with the consolidation check (Step 4).
- Headcount < 50 and turnover ≤ €10 M and balance sheet ≤ €10 M. → You are a small/micro enterprise. Skip to Step 5 — you are likely out unless a "regardless of size" rule applies.
- Headcount < 250 and (turnover > €10 M or balance sheet > €10 M) up to the medium ceilings (€50 M / €43 M). → Medium enterprise. In scope subject to Step 5.
Step 4 — the group consolidation rule
The question: Have you correctly aggregated the entity's data with its partner and linked enterprises before answering Step 3?
This step trips up more organisations than any other. The SME Recommendation distinguishes three categories of enterprise relationship (Article 3 of the Annex to Recommendation 2003/361/EC ):
- Autonomous: no shareholding/voting-rights links of 25% or more with another enterprise (with carve-outs for certain investors such as venture capital, university R&D investors, business angels up to €1,250,000, and certain regional/public investors).
- Partner: an enterprise holds 25–50% of capital or voting rights in another (or vice-versa), without control.
- Linked: one enterprise controls the other (e.g. majority of voting rights, dominant influence).
When determining size for NIS2 purposes:
- For an autonomous enterprise, only its own headcount and financials count.
- For a partner enterprise, you add a proportional share of partner enterprises' staff and financial data (in proportion to the shareholding).
- For linked enterprises, you aggregate 100% of the linked enterprises' staff and financial data.
Practical example. A 30-person German subsidiary that on its own looks "small" can flip into "medium" or "large" once aggregated with its 600-person parent group. If the group operates an Annex I activity through that subsidiary, the subsidiary may be a NIS2 Essential entity, even though its own headcount and revenue would suggest otherwise.
Decision points
- You have mapped partner and linked enterprises in line with Article 3 of the SME Recommendation Annex.
- You have applied the partner pro-rata and the linked 100% aggregation rules.
- You have re-run the Step 3 test using consolidated figures.
If consolidation flips you from "small" to "medium" or above, you are likely in scope. If you genuinely remain a small/micro enterprise after consolidation, go to Step 5.
Step 5 — size-cap exceptions: entities in scope regardless of size
The question: Even if you are below the medium threshold, does the entity fall into one of the categories that NIS2 covers without reference to size?
Article 2(2) of NIS2 brings the following entities into scope regardless of size:
- (a) Providers of public electronic communications networks or of publicly available electronic communications services.
- (b) Trust service providers (qualified and non-qualified, as defined under Regulation (EU) No 910/2014 / eIDAS).
- (c) TLD name registries and DNS service providers.
- (d) A sole provider in a Member State of a service that is essential for the maintenance of critical societal or economic activities.
- (e) Any entity whose disruption of services could have a significant impact on public safety, public security or public health; or could induce significant systemic risk (in particular for sectors where such disruption could have a cross-border impact); or where the entity is critical because of its specific importance at national or regional level for that particular sector or type of service, or for other interdependent sectors in the Member State.
- (f) Public administration entities of central government as defined under national law, and (at Member-State discretion) regional government entities providing services where disruption could have significant cross-border impact.
In addition, the directive explicitly applies, regardless of size:
- To entities providing domain name registration services (Article 2(3)).
- To entities identified as critical entities under Directive (EU) 2022/2557 (the Critical Entities Resilience or "CER" Directive). Under Article 6(1) of NIS2 , entities identified as critical under CER are considered essential entities under NIS2 by default.
Decision points
- The entity is a qualified or non-qualified trust service provider. → In scope, regardless of size.
- The entity is a DNS service provider, TLD name registry or provides domain name registration services. → In scope, regardless of size.
- The entity provides public electronic communications networks or publicly available electronic communications services. → In scope, regardless of size.
- The entity is the sole provider in your Member State of a service essential to critical societal or economic activities. → In scope.
- The entity is a central or (where designated) regional public administration entity. → In scope.
- The entity has been identified as a critical entity under the CER Directive. → Treated as Essential under NIS2.
Step 6 — Essential vs Important: classification and what it means
NIS2 abandons the NIS1 distinction between "operators of essential services" and "digital service providers", and replaces it with the two-tier classification in Article 3 :
Essential entities include:
- Annex I entities that exceed the medium-enterprise ceilings (i.e. large enterprises);
- Qualified trust service providers, TLD name registries, DNS service providers (regardless of size);
- Providers of public electronic communications networks/services that qualify as medium enterprises (note: small/medium telcos are Essential; larger ones likewise);
- Public administration entities of central government as defined by Member States;
- Entities identified as critical under the CER Directive;
- Any other entity that Member States identify as essential under Article 2(2)(b)–(e).
Important entities include:
- Annex I entities that meet the medium-enterprise thresholds but do not exceed them;
- All other entities of a type listed in Annex I or II that meet the size-cap criteria and are not classified as essential;
- Any entity that a Member State identifies as important under Article 2(2)(b)–(e).
Why the label matters. Both tiers must comply with the same substantive obligations under Article 21 (risk-management measures) and Article 23 (incident reporting). The differences are in supervision and sanctions:
| Essential entities | Important entities | |
|---|---|---|
| Supervision regime (Articles 32 & 33 ) | Ex ante and ex post: regular audits, on-site inspections, security scans, ad-hoc audits, requests for documentation. | Ex post only: triggered by evidence/indication of non-compliance or an incident. |
| Minimum maximum fine (Article 34 ) | At least €10,000,000 or at least 2% of total worldwide annual turnover, whichever is higher. | At least €7,000,000 or at least 1.4% of total worldwide annual turnover, whichever is higher. |
| Management liability (Article 20 and Article 32(6)) | Management bodies can be held personally liable; competent authorities may temporarily prohibit individuals from exercising managerial functions. | Management bodies bear personal accountability for approving and overseeing measures; supervisory powers are exercised ex post. |
Decision points
- You have identified Annex I/II classification.
- You have applied size + Article 2(2) exceptions.
- You have a clear Essential vs Important label, on a per-entity basis.
Group-level reminder. Each legal entity in a corporate group is classified separately. A holding company can be out of scope while two of its subsidiaries are Essential, and a third is Important — and each has to register and comply on its own footing.
Step 7 — sector-specific lex specialis (DORA and friends)
The question: Is the entity already covered by a sector-specific EU act that imposes cybersecurity obligations at least equivalent to NIS2's?
Article 4 of NIS2 is the lex specialis bridge. Where another EU act applies cybersecurity risk-management or reporting obligations to an entity that are "at least equivalent in effect" to NIS2's, then the corresponding NIS2 provisions do not apply. The Commission's Guidelines on the application of Article 4(1) and (2) of Directive (EU) 2022/2555, 2023/C 328/02 flesh this out.
The most common carve-out is DORA (Regulation (EU) 2022/2554 ). DORA is lex specialis to NIS2 for the financial sector. Financial entities in scope of DORA (credit institutions, investment firms, central counterparties, trading venues, insurance/reinsurance undertakings, crypto-asset service providers and a long list of others) follow DORA's ICT risk-management, incident-reporting, testing and third-party risk rules instead of NIS2's. DORA's recital 28 expressly says DORA "constitutes lex specialis" to NIS2 for financial entities.
Other interactions worth noting:
- CER Directive (Directive (EU) 2022/2557) — physical and operational resilience for entities identified as critical. NIS2 and CER are complementary: critical entities under CER are automatically essential entities under NIS2 (Article 6(1)).
- eIDAS / Regulation (EU) No 910/2014 — NIS2 amends it; trust service providers are governed both by their sectoral act and by NIS2.
- European Electronic Communications Code (Directive (EU) 2018/1972) — NIS2 amends it; security incident notification for public e-comms providers is consolidated under NIS2.
- Cyber Resilience Act (Regulation (EU) 2024/2847) — governs the product side (cybersecurity of products with digital elements placed on the EU market). If your customers are NIS2-regulated, the supply-chain cascade under Article 21(2)(d) can pull CRA-relevant security requirements into your vendor contracts. The detailed product-side walkthrough lives in Does the Cyber Resilience Act apply to your product? .
Decision points
- You have checked whether a sector-specific EU act with "at least equivalent" cybersecurity provisions applies (most likely DORA for financial entities).
- If yes, you have identified which NIS2 obligations are displaced and which (notably registration under Article 27 and Article 3(3)) may still apply.
Step 8 — Member-State variation: find your transposition
NIS2 is a minimum-harmonisation directive (Article 5 of NIS2 ). Member States may adopt stricter rules, broaden scope (for example to local public administration or to small entities of national importance), or introduce additional obligations.
Transposition deadline: 17 October 2024, with rules applying from 18 October 2024 (Article 41 of NIS2 ; European Commission summary ).
As of early 2026, transposition is still a patchwork. The Commission opened infringement procedures against 23 Member States in November 2024 and sent reasoned opinions to 19 Member States in May 2025 (European Commission – NIS2 transposition in EU countries ). Notable examples (subject to ongoing change — always check the ECSO NIS2 Transposition Tracker and the European Commission transposition page ):
- Belgium — Law of 26 April 2024, in force since 18 October 2024. Competent authority: Centre for Cybersecurity Belgium (CCB) . Registration via the Safeonweb@work portal closed in March 2025 for in-scope entities. Belgium has gold-plated certain measures (e.g. a coordinated vulnerability disclosure policy).
- Germany — NIS2UmsuCG (amending the BSIG) promulgated in the Bundesgesetzblatt on 6 December 2025 and in force the same day. Competent authority: BSI (Bundesamt für Sicherheit in der Informationstechnik) . Registration deadline: 6 March 2026 (three months from entry into force).
- Italy — Decreto legislativo n. 138/2024, in force 16 October 2024. Competent authority: Agenzia per la Cybersicurezza Nazionale (ACN) . Audit deadline now 30 June 2026.
- France — Resilience Bill ("UC32") under final parliamentary stages in late 2025/early 2026; competent authority: ANSSI . Transposition not complete at time of writing.
- Netherlands — Cyberbeveiligingswet under parliamentary review; expected in force in Q2 2026.
- Ireland — competent authorities split across sectors (NCSC for general; CRU for energy/water; ComReg for digital infrastructure; CBI for banking; sectoral aviation/rail/maritime authorities for transport). See the Irish NCSC NIS2 FAQ .
Many Member States have introduced national twists: Hungary, Finland and Belgium exclude banking/financial entities from scope (covered by DORA); Bulgaria and Portugal initially omitted local public administration; Hungary added public transport; Slovakia added thermal power engineering; Poland classified electronic communications under digital infrastructure. Always read the national transposition text before drawing conclusions.
Decision points
- You have identified the Member State(s) under whose jurisdiction the entity falls.
- You have the national transposition act and the current registration deadline.
- You have the identity of the competent authority (supervision/enforcement) and the CSIRT (incident notification) for your sector.
Step 9 — registration obligations
Article 3(3) of NIS2 required Member States to establish a list of essential and important entities (and entities providing domain name registration services) by 17 April 2025, and to review it at least every two years thereafter.
Article 3(4) requires entities to provide at least the following to the competent authority:
- (a) the name of the entity;
- (b) the address and up-to-date contact details, including email addresses, IP ranges and telephone numbers;
- (c) where applicable, the relevant sector and subsector referred to in Annex I or II;
- (d) where applicable, a list of Member States where they provide services falling within the scope of NIS2.
Article 27 of NIS2 further requires certain digital infrastructure and digital service providers (DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, MSPs, MSSPs, providers of online marketplaces, of online search engines and of social networking services platforms) to submit a specific set of information to enable ENISA to maintain a Union-level registry, by 17 January 2025.
Practical reality. Registration in many Member States happens through a dedicated national portal — e.g. Safeonweb@work in Belgium, the BSI portal in Germany, the ACN portal in Italy. Deadlines, the granularity of self-classification questionnaires and the consequences of late registration vary by country (see ECSO NIS2 Transposition Tracker ).
Decision points
- You have located the correct national registration portal.
- You have prepared at least the Article 3(4) information set.
- If you are an Article 27 digital infrastructure/service provider, you have completed the additional registration (for the ENISA-maintained Union registry).
- You have flagged any sector-specific registrations (e.g. trust-service registers under eIDAS).
Step 10 — key obligations once you are in scope
If you survive Steps 1–6, you are in scope. The two operational obligations to plan around immediately are:
Article 21 — cybersecurity risk-management measures
Article 21(2) of NIS2 requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures, based on an "all-hazards" approach, comprising at least:
- (a) policies on risk analysis and information system security;
- (b) incident handling;
- (c) business continuity, such as backup management and disaster recovery, and crisis management;
- (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;
- (e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
- (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures;
- (g) basic cyber hygiene practices and cybersecurity training;
- (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption;
- (i) human resources security, access control policies and asset management;
- (j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate.
Article 21(5) authorises the Commission to adopt implementing acts specifying technical and methodological requirements. The first of these — Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 — applies to DNS service providers, TLD name registries, cloud computing, data centre, CDN, managed service and managed security service providers, and providers of online marketplaces, online search engines, social networking services platforms and trust service providers. ENISA also publishes implementation guidance for Article 21.
For entities operating industrial automation and control systems — Annex I sectors like energy, transport, water and manufacturing — the IEC 62443 family is the recognised technical standard for evidencing Article 21 measures. The mapping is concrete: Article 21(2)(a) and (e) — risk analysis and secure development — align with the asset owner's management programme under IEC 62443-2-1 and the system-design discipline of IEC 62443-3-2 and 3-3 . Article 21(2)(d) — supply-chain security — is most defensibly evidenced by demanding IEC 62443-4-1 and 4-2 certification from product suppliers and IEC 62443-2-4 certification from service providers. Treating these standards as the technical answer to Article 21 in OT contexts is how the cybersecurity team translates the directive into procurement contracts and audit evidence.
Article 23 — incident reporting timelines
Article 23(4) of NIS2 imposes a multi-stage reporting cadence for significant incidents:
- Early warning — without undue delay and in any event within 24 hours of becoming aware of the significant incident. The early warning should indicate, where applicable, whether the incident is suspected to be caused by unlawful or malicious acts and whether it could have a cross-border impact.
- Incident notification — within 72 hours of becoming aware (24 hours for trust service providers in respect of significant incidents affecting their trust services). The notification updates the early warning and includes an initial assessment of severity and impact, plus indicators of compromise where available.
- Intermediate report — on request from the CSIRT or competent authority, providing status updates.
- Final report — not later than one month after the incident notification. The final report must include a detailed description of the incident (including severity and impact), the type of threat or root cause likely to have triggered it, applied and ongoing mitigation measures, and any cross-border impact.
An incident is "significant" where it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity, or has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage (Article 23(3) ).
Other obligations to bake in
- Article 20 — Management bodies must approve and oversee implementation of risk-management measures, undertake training, and offer similar training to employees.
- Article 24 — Possible use of European cybersecurity certification schemes (under Regulation (EU) 2019/881 ) to demonstrate compliance.
- Article 28 — Domain name registration data requirements for TLD registries and entities providing domain name registration services.
- Articles 32–33 — Supervisory powers (audits, inspections, requests for information).
Step 11 — penalties
Article 34 of NIS2 sets minimum maximum administrative fines for breaches of Article 21 or 23:
- Essential entities — fines of a maximum of at least €10,000,000 or of a maximum of at least 2% of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher.
- Important entities — fines of a maximum of at least €7,000,000 or of a maximum of at least 1.4% of the total worldwide annual turnover in the preceding financial year of the undertaking to which the important entity belongs, whichever is higher.
Member States may set higher ceilings. Article 34(6) also allows periodic penalty payments to compel compliance. Public administration entities are subject to a Member-State-specific regime: Article 36 allows Member States to decide whether and to what extent administrative fines apply to public administration entities.
Beyond fines, supervisory authorities may, under Articles 32–33:
- issue binding instructions;
- order security audits at the entity's expense;
- temporarily suspend a certification or authorisation;
- request public disclosure of the breach;
- (for essential entities) temporarily prohibit individuals exercising managerial responsibilities from doing so.
Practical tips for entities operating in multiple Member States
If your project touches more than one Member State — and most digital projects do — assume the following until proven otherwise:
- Each EU subsidiary is assessed separately. Group-level NIS2 compliance does not exist. Each in-scope entity must register and comply in its own Member State.
- The "main establishment" rule is your friend — but only for the Article 26(1)(b) list. Cloud providers, MSPs, MSSPs, CDN providers, data-centre operators, DNS providers, TLD registries, domain name registration services, online marketplaces, online search engines and social networking services all benefit from single-Member-State jurisdiction at their main establishment. Other sectors (energy, transport, health, water, manufacturing, etc.) face per-establishment jurisdiction, which can mean parallel registration and parallel reporting across several countries.
- Treat transposition variation as a project risk. Definitions of "significant incident", registration formats, audit-readiness deadlines, sanction levels, and the existence of national-level sectoral additions (waste management, public transport, mining, education) all differ. The ECSO NIS2 Transposition Tracker and the European Commission transposition page are your friends.
- Map your registrations to your competent authorities, not just to "NIS2". Within a single Member State, jurisdiction can be split across the CSIRT, a horizontal cybersecurity authority and one or more sectoral regulators (Ireland is a notable example).
- Coordinate NIS2 with GDPR, DORA, CER and the CRA. A single incident can trigger parallel notifications under GDPR (72 h), NIS2 (24 h early warning), DORA (4 h initial notification for financial entities), CER (resilience implications) and — if a product vulnerability is involved — the CRA (24 h to ENISA and the coordinator CSIRT, see Does the Cyber Resilience Act apply to your product? ). Maintain a single incident register and synchronise the facts you report to each authority — inconsistencies are themselves an enforcement risk.
- Use the supply-chain cascade to your advantage. If you are out of scope but your customers are in scope, expect contractual flow-down. Designing your security baseline to NIS2 standards is often cheaper than running parallel processes for each customer's bespoke vendor questionnaire.
Relationship with the Critical Entities Resilience (CER) Directive
NIS2 has a sibling: the Critical Entities Resilience Directive — Directive (EU) 2022/2557 . CER addresses physical and operational resilience (not cybersecurity) of "critical entities" identified by Member States in 11 sectors largely overlapping with NIS2 Annex I (energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, public administration, space and food). Member States had to identify their critical entities by 17 July 2026 (Article 6 of CER ).
Two practical consequences:
- Under Article 6(1) of NIS2 , critical entities under CER are automatically treated as essential entities under NIS2. The two regimes operate in parallel: NIS2 covers the cyber risk surface, CER covers physical, environmental and personnel-based threats.
- If your entity is identified as critical under CER, plan for risk assessments, resilience plans, background checks for personnel in sensitive roles and incident notifications under CER in addition to NIS2 obligations.
Recent developments to watch (early 2026)
20 January 2026 — Commission's targeted NIS2 amendment proposal (COM(2026) 13 ; Commission Q&A ) is intended to simplify compliance for around 28,700 companies (including 6,200 micro and small enterprises). Key proposals: refined sectoral scope (electricity, hydrogen, chemicals, healthcare); inclusion of submarine data-cable infrastructure and EU Digital Identity Wallet / EU Business Wallet providers; a new "small mid-cap" category that would generally be classified as Important rather than Essential; harmonisation of Article 21 technical measures via implementing acts; clarification of jurisdictional rules; ransomware-specific reporting; and broader EU-representative requirements for non-EU entities. The proposal foresees a 12-month transposition period after adoption; political agreement is targeted by early 2027.
19 November 2025 — Digital Omnibus package (Commission Digital Omnibus ; commentary at Bird & Bird ) proposes a single-entry point for incident reporting managed by ENISA, covering NIS2, DORA, CER, eIDAS and GDPR-related reporting, applicable 18 months after adoption.
Ongoing infringement proceedings by the Commission against Member States that missed the 17 October 2024 transposition deadline (23 Member States in November 2024; reasoned opinions to 19 Member States in May 2025).
None of these proposals changes the current state of the law: until they are adopted and transposed, the directive as published in OJ L 333, 27.12.2022, p. 80, governs.
A worked-through "am I in scope?" checklist you can copy
Print this and fill it in for each legal entity in your project.
- Step 1 — The entity is established in an EU Member State, or it is one of the Article 26(1)(b) categories offering services in the EU and will appoint an EU representative.
- Step 2 — The entity's activity is listed in an Annex I sub-sector or an Annex II sub-sector of Directive (EU) 2022/2555 (cite the specific sub-sector).
- Step 3 — I have computed staff headcount and the higher of turnover/balance sheet for the entity.
- Step 4 — I have aggregated partner enterprises (pro rata) and linked enterprises (100%) per Commission Recommendation 2003/361/EC, and re-applied the size test.
- Step 5 — I have checked each "regardless of size" trigger in NIS2 Article 2(2): trust service provider; DNS provider; TLD name registry; domain name registration services; public electronic communications provider; sole provider in a Member State; significant-impact triggers; central or designated regional public administration; critical entity under CER.
- Step 6 — I have classified the entity as Essential or Important under Article 3, and recorded the rationale.
- Step 7 — I have checked whether DORA or another sector-specific EU act displaces NIS2 substantive duties under Article 4 (and I have read the Commission Guidelines on Article 4(1) and (2)).
- Step 8 — I have identified the Member State(s) with jurisdiction under Article 26 and the national transposition law, competent authority and CSIRT.
- Step 9 — I have registered (Article 3(3)/(4) and, if applicable, Article 27) by the national deadline and have a process for keeping registration data current.
- Step 10 — I have implemented Article 21 measures across (a)–(j) and Article 23 incident reporting (24 h / 72 h / 1 month, with the 24 h variant for trust service providers).
- Step 11 — Management bodies are trained (Article 20); penalty exposure (Article 34) is on the risk register and reflected in board reporting.
If you can tick all eleven boxes with citations to your evidence, you are not just "compliant on paper" — you are audit-ready. And if your project also places products on the EU market, walk the product-side checklist next: Does the Cyber Resilience Act apply to your product? .