The short answer
NIS2 reaches you if all three of these are true:
Unless you are on one of the routes where size never mattered. That is where most "am I in scope" articles fall down. They print the list of covered industries, mention that it is for medium and larger businesses, and let you assume a small company is safe. Sometimes that is right. Sometimes the law says the size test does not apply to you at all.
The rest of this page walks the three questions, the bit of the size rule almost everyone reads backwards, and the point where the law stops being a checklist and starts asking for judgement.
First: do you do business in the EU?
This is the question that comes first, and the one people skip — because most NIS2 writing is aimed at readers who are obviously European.
NIS2 only applies to businesses that provide services or operate inside the EU. Being in a covered industry while doing no EU business is not enough. The three conditions are joined by and, not or.
If you have no EU operations and sell nothing into the EU, NIS2 does not reach you. That is a genuine answer and we are glad to give it.
If you are based outside the EU but sell into it, a separate rule decides whether NIS2 catches you — and it names the business types directly:
- DNS providers, top-level domain registries, and domain name registration services
- cloud computing, data centres, content delivery networks
- managed service providers and managed security service providers
- online marketplaces, search engines and social networking platforms
If you are on that list and you sell into the EU, you are caught — and you also have to appoint someone in an EU country to represent you.
The actual words, if you want to check us
Article 2(1) applies NIS2 to businesses of a type listed in Annex I or II that meet the size test "and which provide their services or carry out their activities within the Union."
Article 26(1)(b) lists the service types above; Article 26(3) requires those not established in the Union, but offering services within it, to designate a representative in a Member State.
Second: is your business one of the kinds NIS2 covers?
NIS2 has two lists. Which list you are on mostly affects how closely you get watched later, not whether you are caught.
Energy · transport · banking · financial market infrastructure · health · drinking water · waste water · digital infrastructure · IT service management · public administration · space
Post and courier · waste management · chemicals · food · some manufacturing · online marketplaces, search engines and social platforms · research
Both lists break down further, and several of the headings are narrower in the law than they sound in a summary. Two of them do a lot of work for software businesses. "Digital infrastructure" and "IT service management" cover cloud computing, data centres, content delivery networks, managed services and managed security services — which surprises founders who think of themselves as ordinary SaaS.
Being on a list does not by itself put you in scope. It puts you on the list where the next question gets asked.
The actual words, if you want to check us
Annex I — "sectors of high criticality": energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration, space. Annex II — "other critical sectors": postal and courier services, waste management, manufacture and distribution of chemicals, production and distribution of food, manufacturing, digital providers, research. Read the annex entries themselves, not a paraphrase of them — the sub-categories are where the detail lives.
Third: are you big enough?
NIS2 only reaches businesses above a certain size. So the question to answer is the opposite of the one people expect: are we small enough to be out?
You are small — and out on this test — if both of these are true:
You only need one of the two money figures to stay at or under €10 million. So a business turning over €12 million with an €8 million balance sheet is still small — still out.
Plenty of NIS2 checklists shorten this to "50 staff or €10 million turnover." That version sweeps in businesses the law does not actually reach.
Normally, if public bodies hold 25% or more of a business, it loses its small-business status and gets treated as bigger than it is. NIS2 switches that rule off.
So a part publicly-owned business keeps the size limit it would otherwise lose. That matters to university spin-outs, municipal companies, and anything with a state investment fund on the share register.
One thing to watch. If your business is part of a wider group — a parent company, or an investor holding a large share — the group's numbers can count towards yours. If you are comfortably under both limits on your own, this rarely changes the answer. If you are close to either one, your accountant already has the combined figures, and that is the number that decides it.
The actual words, if you want to check us
Article 2(1) catches businesses "which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article." Under that Recommendation an enterprise is small if it has fewer than 50 staff and its annual turnover or annual balance sheet total does not exceed €10 million.
Article 2(1) then closes: "Article 3(4) of the Annex to that Recommendation shall not apply for the purposes of this Directive." Article 3(4) is the provision that strips SME status from an enterprise 25% or more held or controlled by public bodies — so NIS2 disapplies it. The partner and linked-enterprise rules in Articles 3(1)–(3) still apply.
When size doesn't matter at all
Some businesses are covered however small they are. Some of these are clear-cut. Some are not, and that difference is the most important thing on this page.
The clear-cut ones
Size is irrelevant if you are:
- a provider of public communications networks or services
- a trust service provider — digital signatures, certificates, timestamps
- a top-level domain registry or a DNS provider
If you are one of these, a two-person operation is in scope on the same terms as a national telecoms company. There is no threshold to fall below. The same goes for central government bodies, and regional ones where the country decides they count.
The judgement ones
Four more routes catch a business of any size — but none of them is a threshold you can check yourself against. Each applies where:
You are the sole provider in an EU country of a service that country depends on.
Disruption could significantly affect public safety, security or health.
Disruption could set off knock-on failures elsewhere.
You are important enough, where you are, that the country treats you as critical.
Read those again and notice what they are not. There is no headcount, no euro figure, no list to check yourself against. "Significant", "knock-on" and "important enough" are judgements — and in practice they are judgements a national authority makes, against its own criteria, about your particular service.
They are aimed at the business that is the only supplier of something a country cannot manage without — a hospital network, a national carrier, the one company running a piece of critical infrastructure.
If you read those four and thought "that is obviously not us", that is very likely the right answer. You do not need anyone to confirm it for you.
And if one of them genuinely might fit, the people who decide it are your national cyber security authority. They publish guidance and they take questions — it is something you can ask, not something you have to buy an opinion on.
Countries can also choose to extend NIS2 further, to local government and to schools and universities doing critical research. Whether yours has is a question about your country's law, not about you.
The actual words, if you want to check us
Article 2(2)(a) covers, regardless of size, providers of public electronic communications networks or publicly available electronic communications services, trust service providers, and top-level domain name registries and DNS service providers. Article 2(2)(f) covers public administration entities at central level, and regional level where a Member State so determines.
Article 2(2)(b)–(e), verbatim: the entity is "the sole provider in a Member State of a service which is essential for the maintenance of critical societal or economic activities"; disruption "could have a significant impact on public safety, public security or public health"; disruption "could induce a significant systemic risk"; or the entity "is critical because of its specific importance at national or regional level."
Article 2(5): Member States may extend the Directive to public administration entities at local level, and to education institutions, in particular where they carry out critical research activities.
The parts no form can answer
Worth saying plainly, because this is where automated scope checkers do worst.
A tool can tell you reliably that you run DNS, or that you have 300 staff in a covered industry, or that you do no EU business at all. Those are facts about you, matched against a rule with a clear edge.
No tool can tell you whether losing your service would "set off knock-on failures elsewhere." Anything that answers that with a yes or a no is not reading the law. It is guessing, and dressing the guess up as a result.
Our scope checker treats those four judgement routes as flags, never answers. Pick one and the result moves to needs a closer look, and says in plain language why. It will not upgrade itself to "NIS2 applies", and it will not let a judgement call quietly cancel a clear answer you already have from the industry and size questions.
The same works the other way. Where we cannot settle the size question from what you have told us, the answer is needs a closer look — never no. A gap in what we know is not evidence that you are out of scope.
We would rather give you fewer answers you can rely on, and be specific about the one or two things still worth checking, than hand you a confident verdict on something the law leaves to a national regulator.
The law you actually follow is your own country's
NIS2 is a directive. That means it does not bind you directly — each EU country writes it into its own national law, and that national law is what applies to you. It is why "NIS2 compliance" is a slightly misleading phrase for a business operating in more than one country.
National versions follow the same structure, but they differ in the details: which authority supervises you, how and when you have to register, and the shape of particular exemptions. If you operate in several EU countries, expect the substance to be broadly the same and the paperwork to vary.
NIS2 also splits businesses into essential and important. That mostly decides how closely you are watched, and what the maximum fine is. It does not change whether you are in scope.
So it applies. What do you actually have to do?
Three things, and the third is the one that changes behaviour.
A set of security measures, sized to your business. The law names the minimum: handling incidents, backups and business continuity, supply chain security, patching and vulnerability handling, encryption, access control and multi-factor authentication, basic security training — and, easy to miss, checking whether your own measures are actually working.
For a significant incident: an early warning within 24 hours of realising, a fuller report within 72 hours with your first assessment of how bad it is, and a final report within a month. If it is still running at the month mark, you send a progress update and the final report a month after it is resolved.
Management has to approve the security measures, oversee them, and can be held personally liable if the business gets it wrong. They also have to do training. This is the bit that moves cybersecurity from "something IT handles" to a board-level duty — and it is why NIS2 conversations tend to escalate past the IT team.
The actual words, if you want to check us
Article 21(2) lists ten minimum categories, (a)–(j), including incident handling; business continuity, backup management and crisis management; supply chain security; security in acquisition, development and maintenance including vulnerability handling and disclosure; policies to assess the effectiveness of the measures; basic cyber hygiene and training; cryptography and encryption; human resources security, access control and asset management; and multi-factor authentication.
Article 23 sets the deadlines: early warning "without undue delay and in any event within 24 hours"; incident notification "within 72 hours"; final report "not later than one month after the submission of the incident notification". Article 20 requires management bodies to approve and oversee the measures, states they "can be held liable for infringements", and requires them to follow training.
What getting it wrong costs
Each EU country has to make these fines available:
Those are maximums, not standard penalties. One detail worth knowing: the percentage is calculated on the whole group you belong to, not just your company. For a small subsidiary of a large group, the percentage is the number that matters.
In practice, the first enforcement most businesses meet is not a fine at all. It is a duty to register, a request from a regulator, or a customer's procurement questionnaire asking which category you fall into and who supervises you. Not knowing is its own problem, well before anyone is fined.
The actual words, if you want to check us
Article 34(4) — essential entities: a maximum of at least €10,000,000 or 2% of the total worldwide annual turnover of the undertaking in the preceding financial year, whichever is higher. Article 34(5) — important entities: at least €7,000,000 or 1.4%, whichever is higher. Article 32 governs supervision of essential entities, including on-site inspections and random checks; Article 33 applies to important entities and is triggered "when provided with evidence, indication or information" of non-compliance.
Finding out where you actually stand
Almost every business we talk to has already guessed at this. The guess is usually one of two shapes: we are too small for it, or we had better assume it all applies. Both are expensive. The first because it is sometimes wrong for a reason you would have spotted in ten minutes. The second because it buys work nobody needed.
Our scope checker replaces the guess with an answer. It asks a short set of plain-language questions and tells you whether GDPR, NIS2 and the EU AI Act reach your business.
- It will tell you a rule does not apply, and say what decided it — for NIS2, whether it was EU activity, the industry lists, or the size line. "Not in scope" is a real answer and we are glad to give it.
- It will tell you when it does not know, instead of rounding to the comfortable answer.
- It will not decide a judgement call for you. Those four routes come back flagged, with the reason spelled out, so you can judge whether they describe you.
It is free, and every answer comes with the reasoning that produced it, in plain language.
Everything cited on this page
- NIS2 Article 2(1) — who it applies to: the size test, the EU-activity requirement, and the disapplication of Article 3(4) of the Annex to Recommendation 2003/361/EC
- NIS2 Article 2(2)(a)–(f) — businesses covered regardless of size
- NIS2 Article 2(5) — the option for countries to extend it to local government and education
- NIS2 Annex I and Annex II — the two lists of covered sectors
- NIS2 Article 20 — management approval, oversight, liability and training
- NIS2 Article 21 — the security measures
- NIS2 Article 23 — incident reporting and its deadlines
- NIS2 Articles 26(1) and 26(3) — who is caught from outside the EU, and the representative duty
- NIS2 Articles 32 and 33 — supervision of essential and important businesses
- NIS2 Article 34(4) and 34(5) — fines
- Commission Recommendation 2003/361/EC, Annex, Articles 2 and 3 — the small-business definition, and the ownership rule NIS2 switches off