Skip to content
ReadinessNavigator

Directive (EU) 2022/2555

Whether NIS2 binds you — and as which kind of entity

NIS2 raised the EU baseline for cybersecurity risk management and incident reporting, and widened who has to meet it. Unlike the rest of this site, it regulates the operator running essential or important services, not the product a manufacturer ships. The first question is never "how compliant are you" — it is "are you in scope, and as an essential or an important entity", because that determination decides everything that follows.

Why scope comes first

Scope is a legal test, and it is not obvious

NIS2 scope turns on three things that interact: whether you operate in a sector the directive lists, whether you meet the size of a medium enterprise, and whether you are one of the special cases that are covered whatever your size. Get any of them wrong and you either assume duties you do not have or — far more dangerous — miss duties whose deadlines are already running.

The essential-versus-important split is not a severity score. It decides your supervisory regime: essential entities face proactive supervision — audits and inspections that can arrive unannounced — while important entities are supervised reactively, after something surfaces. Both carry the same core security and reporting duties, and both put those duties on management personally.

This check follows the directive text. NIS2 is a directive, not a regulation, so the binding rules are your Member State’s transposition — the result flags every point where national law can widen scope or add duties.

Who it binds

Three routes into scope

An organisation is in scope if any one of these applies. Most enter through sector plus size; the third route is the one that catches organisations off guard.

  • Annex I

    High-criticality sectors

    Energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space. Large entities here are essential; medium-sized entities are important, subject to the named regardless-of-size cases and national provisions (Article 3).

  • Annex II

    Other critical sectors

    Postal and courier services, waste management, chemicals, food, manufacturing of certain products, digital providers, and research. Medium-or-larger entities here are important.

  • Art. 2(2)

    Regardless of size

    Certain entities are covered whatever their size — providers of public electronic communications and public DNS, TLD registries, trust service providers, and sole or critical national providers, among others.

Essential vs. important

The split that sets your regime

Both classes carry the same Article 21 security measures and Article 23 reporting duties. What differs is supervision and the ceiling on penalties.

Proactive supervision

Essential entity

Regular and targeted audits, on-site inspections, and security scans can be initiated without a prior incident. Administrative fines reach up to €10 million or 2% of total worldwide annual turnover, whichever is higher.

Reactive supervision

Important entity

Supervision follows evidence of a possible breach rather than a routine schedule. Administrative fines reach up to €7 million or 1.4% of total worldwide annual turnover, whichever is higher.

What follows a positive verdict

The duties scope brings with it

Being in scope is the trigger for a defined set of obligations. The assessment lists the ones your verdict activates; the headline duties are these.

  • Risk-management measures

    The ten minimum measures of Article 21(2) — including incident handling, business continuity, supply-chain security, and the use of cryptography — proportionate to your risk.

  • Incident reporting

    A staged timeline under Article 23: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.

  • Registration

    Registration with the competent authority or CSIRT, with certain entity types (DNS, TLD, cloud, data centres, CDNs and others) registered centrally by ENISA under Article 27.

  • Management accountability

    Management bodies must approve the risk measures and oversee their implementation, can be held liable, and have to follow cybersecurity training under Article 20.

An ISO/IEC 27001 ISMS can contain policies and records relevant to some NIS2 Article 21(2) measures. Its scope and evidence still need checking against the duties that apply to your entity under national law.

Review the ISO/IEC 27001 evidence crosswalk

How NIS2 meets the product frameworks

How operator requirements can affect manufacturers

See the manufacturer-side frameworks

NIS2 addresses operators, while the CRA addresses products and IEC 62443 covers relevant product and development-process security practices. Under Article 21(2)(d), an in-scope operator must manage supply-chain security, which may lead it to request evidence from manufacturers. The evidence requested depends on the customer, product and applicable requirements.

If you supply an essential or important entity, its supplier-security process may create customer requirements for product and process evidence. CRA conformity work and relevant IEC 62443 practices can help you respond, but do not by themselves determine what each NIS2-regulated buyer will require.

Get in touch

Find out whether NIS2 reaches you, and as what

NIS2 catches some organisations directly and many more through their customers. Tell us your sector and where you sit in the supply chain, and we will come back with whether it applies, in what role, and what that obligates.

We reply within two working days.

Full contact details
consulting@readinessnavigator.com
Book a 30-minute call

Opens our scheduling page in a new tab — pick a slot that suits you.

Useful in a first message

  • Your sector, headcount, and turnover — the thresholds that decide essential vs. important status.
  • Which EU member states you operate in, since national transpositions differ.
  • Whether a customer is passing NIS2 obligations to you contractually rather than by direct scope.

Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.