NIS2 | Scope Determination
Guide for determining whether your organisation falls under NIS2 and in which category.
Decision Tree
Annex I --- Essential Entities
Detailed Sector Overview
| # | Sector | Sub-sectors | Example entities |
|---|---|---|---|
| 1 | Energy | Electricity | Generators, distributors, suppliers, exchanges |
| Oil | Pipeline operators, refineries | ||
| Gas | Distributors, LNG terminals, storage | ||
| Hydrogen | Producers, infrastructure operators | ||
| Heat | District heating | ||
| 2 | Transport | Aviation | Airports, airlines, handling |
| Rail | Infrastructure managers, carriers | ||
| Maritime | Ports, ferries, inland waterways | ||
| Road | Motorway managers, ITS | ||
| 3 | Banking | Credit institutions | |
| 4 | Financial markets | Exchanges, clearing houses, trade repositories | |
| 5 | Healthcare | Hospitals, laboratories, pharmaceutical manufacturers, medical device manufacturers | |
| 6 | Drinking water | Drinking water suppliers | |
| 7 | Waste water | Waste water treatment operators | |
| 8 | Digital infrastructure | DNS, TLD, cloud computing, data centres, CDN, IXP | |
| 9 | ICT services B2B | Managed services, managed security services | |
| 10 | Public administration | Central bodies, regional (above threshold) | |
| 11 | Space | Satellite operators |
Annex II --- Important Entities
| # | Sector | Sub-sectors | Example entities |
|---|---|---|---|
| 1 | Postal services | Couriers, postal operators | |
| 2 | Waste | Collection, processing, recycling | |
| 3 | Chemicals | Manufacturing, distribution | |
| 4 | Food | Production, processing, distribution | |
| 5 | Manufacturing | Medical devices | Medical device manufacturers |
| Computers/electronics | Computer and electronics manufacturers | ||
| Machinery | Machine and equipment manufacturers | ||
| Motor vehicles | Automotive manufacturers | ||
| Transport equipment | Other transport equipment | ||
| 6 | Digital services | Online marketplace, search engines, social networks | |
| 7 | Research | Research organisations |
Size Criteria
Rules
| Criterion | Essential (Annex I) | Important (Annex II) |
|---|---|---|
| Employees | >50 | >50 |
| OR Turnover | >EUR 10M | >EUR 10M |
| OR Balance sheet | >EUR 10M | >EUR 10M |
Exceptions (Automatically IN SCOPE regardless of size)
- DNS service providers
- TLD name registries
- Cloud computing providers
- Data centre providers
- CDN providers
- Qualified trust service providers
- Public administration (central bodies)
- Critical suppliers of essential entities
Self-Assessment Checklist
Step 1: Sector Identification
- We are in an Annex I sector
- We are in an Annex II sector
- We are not in any regulated sector
Step 2: Size Verification
| Criterion | Your value | Met? |
|---|---|---|
| Number of employees | [ ] >50 | |
| Annual turnover | EUR______ | [ ] >EUR 10M |
| Annual balance sheet | EUR______ | [ ] >EUR 10M |
Step 3: Exceptions
- We are automatically IN SCOPE (DNS, cloud, DC, TLD, CDN)
- We are a critical supplier of an essential entity
- We are the sole provider in the region
Step 4: Conclusion
| Result | Your situation |
|---|---|
| [ ] Essential Entity | Annex I + size criteria met |
| [ ] Important Entity | Annex II + size criteria met |
| [ ] Out of Scope | Criteria not met |
Differences Between Essential and Important
| Aspect | Essential | Important |
|---|---|---|
| Supervision | Proactive (ex-ante) | Reactive (ex-post) |
| Audits | Regular | Incident-based |
| Penalties | Higher (up to EUR 10M / 2%) | Lower (up to EUR 7M / 1.4%) |
| Reporting | Stricter | Standard |
| Management liability | Higher | Standard |
Scope Determination Record
Next Steps
- Scope determined
- ISMS requirements
- Compliance checklist
- Register with national authority (if applicable)