NIS 2

NIS 2: who is in scope and what it demands

The directive applied from 17 October 2024 and reaches far beyond critical infrastructure. Here is how to tell whether you are covered, and what changes if you are.
Certifyi compliance team · Updated September 2026
Short answer. NIS 2 (Directive (EU) 2022/2555) applies to medium and large organisations, generally 50 or more employees or over €10 million turnover, operating in the sectors listed in its Annex I (high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space) and Annex II (other critical: postal, waste, chemicals, food, manufacturing of key products, digital providers, research). Entities are classed as essential or important, with stricter supervision and higher fines for essential entities. Management bodies must approve and oversee cybersecurity measures and can be held personally liable.

The size-cap rule, and its exceptions

The default test is size: medium-sized (50 to 249 staff, or €10M to €50M turnover) and large organisations in a listed sector are in scope. Small and micro organisations are normally out, with exceptions for providers whose disruption would matter regardless of size: qualified trust service providers, TLD name registries, DNS providers, public electronic communications providers, and any entity a member state designates as critical. Digital providers such as cloud, data centre, CDN, managed service and managed security providers are in scope from medium size, which pulls in many B2B SaaS companies that never considered themselves infrastructure.

Essential vs important

Essential entitiesImportant entities
WhoLarge organisations in Annex I sectors, plus designated providersMedium organisations in Annex I, and medium and large in Annex II
SupervisionProactive: audits, inspections, information requests at any timeReactive: after evidence or indication of non-compliance
Maximum fines€10M or 2% of global turnover€7M or 1.4% of global turnover
ManagementApproval, oversight, training; personal liability; possible temporary ban from management rolesApproval, oversight, training; personal liability

The ten minimum measures (Article 21)

Incident reporting: 24 hours, 72 hours, one month

Significant incidents must be reported to the national CSIRT or competent authority with an early warning within 24 hours of becoming aware, a notification with an initial assessment within 72 hours, and a final report within one month. A significant incident is one causing or capable of causing severe operational disruption or financial loss, or affecting others with considerable damage. The clock demands a rehearsed incident process, not a plan in a drawer.

Transposition and where you actually comply

NIS 2 is a directive, so each member state transposed it into national law with its own registration portal, authority and detail; several states missed the October 2024 deadline and enforcement is uneven. You comply in each state where you provide services or are established. If you hold ISO 27001, most of Article 21 is already evidenced; the gaps are usually supply chain depth, management training and the reporting timelines. In Certifyi, NIS 2 maps onto the shared control library alongside ISO 27001 and DORA, and the incident module is built around the 24/72-hour clock.

NIS 2, answered

If you offer in-scope services in the EU, such as cloud computing, managed services or online marketplaces, you are in scope regardless of where you are established, and you must designate an EU representative.

Not automatically, but it covers most of the Article 21 measures. Member states may recognise certifications; the reporting duties and management obligations still apply separately.

Members of the management body who approve and oversee the measures. For essential entities, authorities can temporarily prohibit individuals from exercising management functions after repeated failures.

DORA is lex specialis for the financial sector: financial entities covered by DORA follow DORA’s ICT risk rules instead of NIS 2’s equivalent provisions.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top