EU

NIS2: Scope and Definitions

Scope and Definitions [Art 2-6]

Rule: NIS2 applies to medium and large entities in essential and important sectors, with some entities covered regardless of size.

Essential Entities [Art 3(1), Annex I]

SectorSub-sectors
EnergyElectricity, oil, gas, hydrogen, district heating/cooling
TransportAir, rail, water, road
BankingCredit institutions
Financial market infrastructureTrading venues, central counterparties
HealthHealthcare providers, EU reference labs, pharma, medical devices
Drinking waterWater suppliers
Waste waterWaste water operators
Digital infrastructureIXPs, DNS providers, TLD registries, cloud, data centers, CDNs, trust services, public electronic comms
ICT service management (B2B)Managed service providers, managed security service providers
Public administrationCentral government entities
SpaceGround-based infrastructure operators

Important Entities [Art 3(2), Annex II]

SectorExamples
Postal/courierPostal service providers
Waste managementWaste collection, treatment, disposal
ChemicalsManufacture, production, distribution
FoodProduction, processing, wholesale distribution
ManufacturingMedical devices, computers, electronics, machinery, motor vehicles, transport equipment
Digital providersOnline marketplaces, search engines, social networking platforms
ResearchResearch organizations

Size Thresholds [Art 2(1)]

Entity must be medium or large:

CategoryEmployeesORTurnoverORBalance Sheet
Medium50-249OR€10M-€50MOR€10M-€43M
Large250+OR€50M+OR€43M+

Covered Regardless of Size [Art 2(2)]

Some entities always covered, regardless of size:

Entity TypeReason
Trust service providersCritical digital infrastructure
TLD registriesDNS ecosystem criticality
DNS service providersInternet core function
Public electronic communicationsEssential communications
Public administrationCentral government
Sole providerOnly entity providing essential service in Member State
Critical impactSignificant impact on public safety, security, health
Cross-border impactSystemic risk across Member States

Key Definitions [Art 6]

TermDefinition
Network and information systemElectronic communications network, device/group processing data, digital data stored/processed/transmitted
Security of network and information systemsAbility to resist events that compromise availability, authenticity, integrity, confidentiality
IncidentEvent compromising availability, authenticity, integrity, or confidentiality of data or services
Significant incidentCauses serious operational disruption OR financial loss OR affects others
Cyber threatPotential circumstance, event, or action that could damage, disrupt, or adversely impact systems
Near missEvent that could have been an incident but was prevented or didn’t occur

Exclusions [Art 2(3)-(10)]

NOT covered:

  • Entities in sectors already covered by sector-specific legislation (e.g., DORA for finance)
  • National security, defense, law enforcement activities
  • Diplomatic and consular missions
  • Judicial, parliamentary, and central bank entities performing non-commercial activities

Group Undertakings [Art 2(1)]

Assessment at individual entity level, not group:

  • Each subsidiary assessed separately
  • Cannot aggregate parent and subsidiary metrics
  • Entity must independently meet thresholds

Essential vs Important — Why It Matters

AspectEssentialImportant
Maximum fine€10M or 2% turnover€7M or 1.4% turnover
SupervisionEx-ante (proactive)Ex-post (reactive)
Audit frequencyRegular, mandatoryAfter incidents
Compliance checksRoutine inspectionsTriggered inspections

Citation

Art 2-6, Directive (EU) 2022/2555

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt