Who NIS2 applies to: the sector lists (high-criticality vs other critical sectors), the size-cap rule and its exceptions (sole providers, critical dependence), and the essential vs important classification that drives the supervision and penalty regimes.
NIS2 applies to entities listed in two annexes that define the regulated universe.
Annex I covers sectors of high criticality: energy (electricity, district heating and cooling, oil, gas, hydrogen), transport (air, rail, water, road), banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration, and space 32022L2555 Annex I@2022-12-27.
Annex II covers other critical sectors: postal and courier services, waste management, manufacture, production and distribution of chemicals, production, processing and distribution of food, manufacturing across six subsectors (medical devices and in vitro diagnostic medical devices, computers and electronics, electrical equipment, machinery, motor vehicles, other transport equipment), digital providers (online marketplaces, online search engines, social networking platforms), and research organisations 32022L2555 Annex II@2022-12-27.
For most entities, NIS2 applies only to those that qualify as medium-sized enterprises under Recommendation 2003/361/EC, or exceed its ceilings 32022L2555 Article 2@2022-12-27. Small and micro enterprises operating in Annex I or II sectors therefore fall outside the directive's scope by default, unless an exception brings them in.
Article 2(2) lists six circumstances in which an entity in Annex I or II is in scope regardless of size 32022L2555 Article 2@2022-12-27:
Separately, entities identified as critical entities under the CER Directive (EU) 2022/2557 are in scope regardless of size, as are all entities providing domain name registration services 32022L2555 Article 2@2022-12-27.
Public administration entities carrying out activities in national security, defence, public security, or law enforcement are excluded from the directive 32022L2555 Article 2@2022-12-27. Member States may extend partial exemptions to entities carrying out activities in those areas, or which provide services exclusively to the public administration entities referred to in paragraph 7, though trust service providers cannot be exempted on this basis even where they touch national security functions 32022L2555 Article 2@2022-12-27. Entities already exempted from DORA (Regulation (EU) 2022/2554) under Article 2(4) of that regulation are also outside NIS2's scope 32022L2555 Article 2@2022-12-27.
Article 3 draws the line between essential and important entities. The classification is not cosmetic: it determines which supervisory and enforcement regime applies under the directive.
Essential entities are 32022L2555 Article 3@2022-12-27: - Annex I entities exceeding the medium-sized enterprise size ceilings - Qualified trust service providers, TLD name registries, and DNS service providers, regardless of size - Providers of public electronic communications networks or publicly available electronic communications services that qualify as medium-sized enterprises - Public administration entities of central government - Any Annex I or Annex II entity identified by a Member State as essential under Article 2(2)(b)–(e) - Entities identified as critical entities under the CER Directive - Entities designated as operators of essential services in accordance with Directive (EU) 2016/1148 or national law before 16 January 2023, where the Member State so provides
Important entities are Annex I or Annex II entities that do not meet any of the essential criteria, including entities identified by Member States as important under Article 2(2)(b)–(e) 32022L2555 Article 3@2022-12-27.
Practical illustration: a large electricity transmission system operator is automatically essential. A medium-sized chemical manufacturer in Annex II is classified as important unless a Member State's risk assessment places it under one of the Article 2(2) exceptions.
Member States were required to establish a list of essential and important entities as well as entities providing domain name registration services by 17 April 2025, with updates at least every two years thereafter 32022L2555 Article 3@2022-12-27. Entities must submit their name, current contact details, the relevant sector and subsector, and the Member States in which they provide in-scope services; any changes must be notified without delay, and in any event within two weeks of the change 32022L2555 Article 3@2022-12-27.
This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)
The cases below are labeled illustrative context only and carry no regulatory authority.
NIS2 compliance services expanding beyond the directive's formal scope CASE-2: In July 2026 Coro and PwC Italy announced a partnership to automate cybersecurity and NIS2 compliance for businesses of all sizes. The explicit reference to all sizes reflects a market dynamic that the directive itself does not create: entities below the size threshold — or in sectors outside Annexes I and II — face commercial and contractual pressure to meet equivalent standards when they operate in the supply chains of formally covered entities. This illustrates a gap worth flagging in scope analysis: formal NIS2 obligation and practical compliance expectation do not coincide for smaller operators.
The remaining cached cases (CASE-1, CASE-3) concern unrelated subjects and are not relevant to NIS2 scope.
1. Which of the following sectors is listed in Annex I as a sector of HIGH criticality?
Space appears explicitly in the Annex I list of high-criticality sectors, while postal/courier, waste management, and chemicals all belong to Annex II (other critical sectors). 32022L2555 Annex I@2022-12-27
2. Under NIS2's baseline size-cap rule, which entities operating in Annex I or II sectors are in scope by default?
Article 2 limits the baseline scope to entities meeting or exceeding the medium-sized enterprise threshold under Recommendation 2003/361/EC, leaving small and micro enterprises outside by default. 32022L2555 Article 2@2022-12-27
3. A micro-enterprise operates a top-level domain (TLD) name registry in an EU Member State. Is it in scope under NIS2?
Article 2(2) lists operation of a TLD name registry as one of the six circumstances that bring an entity into scope regardless of its size. 32022L2555 Article 2@2022-12-27
4. Which of the following entities is EXCLUDED from NIS2's scope?
The directive explicitly excludes public administration entities whose activities fall within national security, defence, public security, or law enforcement, and separately states that trust service providers cannot be exempted even where they touch national security functions. 32022L2555 Article 2@2022-12-27
5. By what deadline were Member States required to establish an initial list of essential and important entities?
Article 3 sets 17 April 2025 as the establishment deadline for the initial entity lists, with updates required at least every two years thereafter. 32022L2555 Article 3@2022-12-27