← Course outline
Aavistus Training · nis2 · NIS.01

Scope: essential and important entities

What you'll learn

Who NIS2 applies to: the sector lists (high-criticality vs other critical sectors), the size-cap rule and its exceptions (sole providers, critical dependence), and the essential vs important classification that drives the supervision and penalty regimes.

Regulation — cited to the current EU text

Who is covered: the two sector lists

NIS2 applies to entities listed in two annexes that define the regulated universe.

Annex I covers sectors of high criticality: energy (electricity, district heating and cooling, oil, gas, hydrogen), transport (air, rail, water, road), banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration, and space 32022L2555 Annex I@2022-12-27.

Annex II covers other critical sectors: postal and courier services, waste management, manufacture, production and distribution of chemicals, production, processing and distribution of food, manufacturing across six subsectors (medical devices and in vitro diagnostic medical devices, computers and electronics, electrical equipment, machinery, motor vehicles, other transport equipment), digital providers (online marketplaces, online search engines, social networking platforms), and research organisations 32022L2555 Annex II@2022-12-27.

The baseline size-cap rule

For most entities, NIS2 applies only to those that qualify as medium-sized enterprises under Recommendation 2003/361/EC, or exceed its ceilings 32022L2555 Article 2@2022-12-27. Small and micro enterprises operating in Annex I or II sectors therefore fall outside the directive's scope by default, unless an exception brings them in.

Exceptions that override the size cap

Article 2(2) lists six circumstances in which an entity in Annex I or II is in scope regardless of size 32022L2555 Article 2@2022-12-27:

  1. The entity provides public electronic communications networks or publicly available electronic communications services, is a trust service provider, or operates a top-level domain (TLD) name registry or DNS service.
  2. The entity is the sole provider in a Member State of a service essential for maintaining critical societal or economic activities.
  3. Disruption of the entity's service could have a significant impact on public safety, public security, or public health.
  4. Disruption could induce a significant systemic risk, in particular for sectors where such disruption could have a cross-border impact.
  5. The entity is critical because of its specific importance at national or regional level for the particular sector or type of service, or for other interdependent sectors in the Member State.
  6. The entity is a public administration entity of central government, or a regional-level entity where a risk-based assessment shows that disruption of its services could significantly affect critical societal or economic activities.

Separately, entities identified as critical entities under the CER Directive (EU) 2022/2557 are in scope regardless of size, as are all entities providing domain name registration services 32022L2555 Article 2@2022-12-27.

Exclusions

Public administration entities carrying out activities in national security, defence, public security, or law enforcement are excluded from the directive 32022L2555 Article 2@2022-12-27. Member States may extend partial exemptions to entities carrying out activities in those areas, or which provide services exclusively to the public administration entities referred to in paragraph 7, though trust service providers cannot be exempted on this basis even where they touch national security functions 32022L2555 Article 2@2022-12-27. Entities already exempted from DORA (Regulation (EU) 2022/2554) under Article 2(4) of that regulation are also outside NIS2's scope 32022L2555 Article 2@2022-12-27.

Essential vs important: the classification that drives supervision and penalties

Article 3 draws the line between essential and important entities. The classification is not cosmetic: it determines which supervisory and enforcement regime applies under the directive.

Essential entities are 32022L2555 Article 3@2022-12-27: - Annex I entities exceeding the medium-sized enterprise size ceilings - Qualified trust service providers, TLD name registries, and DNS service providers, regardless of size - Providers of public electronic communications networks or publicly available electronic communications services that qualify as medium-sized enterprises - Public administration entities of central government - Any Annex I or Annex II entity identified by a Member State as essential under Article 2(2)(b)–(e) - Entities identified as critical entities under the CER Directive - Entities designated as operators of essential services in accordance with Directive (EU) 2016/1148 or national law before 16 January 2023, where the Member State so provides

Important entities are Annex I or Annex II entities that do not meet any of the essential criteria, including entities identified by Member States as important under Article 2(2)(b)–(e) 32022L2555 Article 3@2022-12-27.

Practical illustration: a large electricity transmission system operator is automatically essential. A medium-sized chemical manufacturer in Annex II is classified as important unless a Member State's risk assessment places it under one of the Article 2(2) exceptions.

Registration obligations

Member States were required to establish a list of essential and important entities as well as entities providing domain name registration services by 17 April 2025, with updates at least every two years thereafter 32022L2555 Article 3@2022-12-27. Entities must submit their name, current contact details, the relevant sector and subsector, and the Member States in which they provide in-scope services; any changes must be notified without delay, and in any event within two weeks of the change 32022L2555 Article 3@2022-12-27.

Your operations manual

This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

The cases below are labeled illustrative context only and carry no regulatory authority.

NIS2 compliance services expanding beyond the directive's formal scope CASE-2: In July 2026 Coro and PwC Italy announced a partnership to automate cybersecurity and NIS2 compliance for businesses of all sizes. The explicit reference to all sizes reflects a market dynamic that the directive itself does not create: entities below the size threshold — or in sectors outside Annexes I and II — face commercial and contractual pressure to meet equivalent standards when they operate in the supply chains of formally covered entities. This illustrates a gap worth flagging in scope analysis: formal NIS2 obligation and practical compliance expectation do not coincide for smaller operators.

The remaining cached cases (CASE-1, CASE-3) concern unrelated subjects and are not relevant to NIS2 scope.

Check your understanding

1. Which of the following sectors is listed in Annex I as a sector of HIGH criticality?

2. Under NIS2's baseline size-cap rule, which entities operating in Annex I or II sectors are in scope by default?

3. A micro-enterprise operates a top-level domain (TLD) name registry in an EU Member State. Is it in scope under NIS2?

4. Which of the following entities is EXCLUDED from NIS2's scope?

5. By what deadline were Member States required to establish an initial list of essential and important entities?