Is your company in scope of NIS2? How to find out
By Michal Lampe Sørensen · 6 min read · 17 May 2026
Contents
Kort fortalt
NIS2 gælder for organisationer i 18 sektorer (bilag I + II) med mindst 50 ansatte eller 10 mio. EUR omsætning. Væsentlige enheder (energi, sundhed, finans) har strengere krav end vigtige (digitale leverandører, fødevarer). Under tærsklen er I formelt fri, men supply chain-kontrakter trækker mange SMV'er ind alligevel.
The short answer
You are in scope if all three apply:
- •You operate in one of the 18 sectors in NIS2 Annex I or Annex II
- •You have 50+ employees OR EUR 10M in annual revenue or balance sheet
- •You deliver services in the EU market (this includes local subsidiaries of foreign groups)
If any of these doesn't apply, you're formally not in scope, but read section 5 on the supply chain trap before concluding anything.
Still unsure? Take our quick NIS2 self-check, 6 questions, 2 minutes, no email required.
Essential vs important entities
NIS2 splits organisations into two categories with different obligations. The classification is a combination of sector (Annex I/II) and company size.
Essential entities
Large companies with more than 250 employees or over EUR 50M in revenue, operating in Annex I sectors: energy, transport, healthcare, drinking water, wastewater, digital infrastructure, public administration, and space.
- •Proactive supervision by the competent authority
- •Fines of up to EUR 10M or 2% of global revenue (whichever is higher)
- •Incident reporting: early warning within 24 hours, formal notification within 72 hours, final report within 1 month
Important entities
All Annex II entities above the size threshold, plus mid-sized companies (50-249 employees) in Annex I. Annex II covers postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research.
- •Reactive supervision, typically only on suspicion of a breach
- •Fines of up to EUR 7M or 1.4% of global revenue
- •Same reporting deadlines as essential entities
A mid-sized SMB in an Annex I sector (say, a private clinic) is typically important, not essential, that matters for the fine cap and supervision intensity. The Article 21 requirements themselves are the same for both.
The 18 sectors, are you among them?
The sectors are broader than most realise. Many private clinics, food producers, and digital suppliers are in scope without thinking of themselves as "critical infrastructure".
Annex I, candidates for essential or important entity status
- •Healthcare, including private clinics and laboratories (verify against NIS2's definition of healthcare provider)
- •Banking and finance, financial entities are primarily regulated by DORA (Regulation 2022/2554), not NIS2. DORA is lex specialis
- •Drinking water and wastewater, municipal utilities and private operators
- •Digital infrastructure. DNS, IXP, TLD registry, cloud providers above the threshold, datacentres
- •Public administration, municipalities, regions, central authorities
Annex II, important entities
- •Postal and courier services, everyone offering tracked transport
- •Food, production, processing, distribution
- •Manufacturing, medical devices, electronics, machinery, motor vehicles
- •Digital providers, online marketplaces, search engines, social networks
- •Research institutions
The full list is in the NIS2 directive annexes. Rule of thumb: if you're unsure, assume you're in scope and let the opposite be your burden of proof.
Size criteria, and the exceptions
The primary threshold is mid-sized company: either 50+ employees or EUR 10M in revenue OR balance sheet.
Exceptions where smaller companies are still in scope:
- •Sole providers, if you are the only provider of a critical service in your country, you're in scope regardless of size
- •Providers of public electronic communications, all sizes
- •Trust service providers (eIDAS), all sizes
- •DNS, TLD registries, registrars, all sizes
- •Public administration, all municipalities and regions in scope regardless of size
If you're a small company (under 50 employees) in one of the annex sectors but don't fit any of the exceptions above, you are formally not directly in scope. But that doesn't mean NIS2 is irrelevant, supply chain requirements still reach you indirectly.
The supply chain trap, why many SMBs are caught indirectly
Article 21(2)(d) in NIS2 requires supply chain security. Organisations in scope must assess and manage the security of their suppliers.
What this means if you supply in-scope customers
- •Contract requirements, large customers will require you to document your own security at a NIS2-equivalent level
- •Questionnaires, expect 50-100 questions about your security measures
- •Audit rights, many contracts give the customer the right to audit you
- •Sub-processor approval, your own subcontractors also need to be at the right level
A concrete example
You supply SaaS to a bank. The bank is an essential entity under NIS2 and is obliged to assess your security. They will require from you:
- •Documented MFA and access controls
- •Incident reporting within 24 hours
- •Encryption of data in transit and at rest
- •Backup and business continuity plan
The requirements match Article 21 one-to-one. You're not directly in scope of the law, only of the contract, but the practical burden is the same.
What do you do now?
Three concrete next steps depending on where you stand. Most member states now have NIS2 in force and supervision running, so there is no longer time to wait. Denmark is used below as a worked example: the law took effect there on 1 July 2025 and supervision has been active since early 2026.
If you're likely directly in scope
- •Register with your national authority if you haven't already (in Denmark that is virk.dk, where the deadline was 1 October 2025)
- •Contact your sector authority (in Denmark: the Health Data Authority, the Energy Agency, the Agency for Digital Government, or SAMSIK)
- •Read our article on Article 21 and start the documentation
- •Assess your current Microsoft 365 licence against the requirements
If you supply in-scope customers
- •Expect supply chain requirements in your next contract negotiation
- •Prepare a standardised security response you can reuse across customers
- •Consider whether your licence tier is high enough
If you're unsure
- •Take our 2-minute NIS2 self-check for a quick verdict
- •Get a lawyer to do a formal scope assessment, cheaper than assuming wrong
- •Read the full Article 21 mapping in our whitepaper
Next in the series: Which Microsoft 365 licence meets NIS2?, we compare Business Premium, E3, and E5 against the Article 21 requirements concretely.
Skip the theory, take the self-check
Answer 6 questions about your sector, size, and supply chain. Get a verdict on whether you're an essential entity, important entity, or out of scope, plus which Microsoft 365 licence covers you.
Start the NIS2 self-checkFrequently asked questions
When did NIS2 take effect?+
NIS2 entered into force on 16 January 2023, and member states had until 17 October 2024 to write it into national law. Several were late, so the date that binds you is the one in your own country, not the EU deadline. In Denmark the law took effect on 1 July 2025 with registration due by 1 October 2025, and supervision has been active since early 2026. Check your national implementation and registration route with your sector authority.
Are small companies (under 50 employees) completely exempt from NIS2?+
As a general rule, yes, the directive targets mid-sized and large organisations. But there are exceptions: sole providers of critical services, providers of public electronic communications, trust services (eIDAS), DNS operators, and public administration are in scope regardless of size. Plus, anyone supplying an in-scope customer is reached indirectly via supply chain requirements.
What's the difference between NIS2 and GDPR?+
GDPR protects personal data and privacy. NIS2 ensures cyber resilience and the security of network and information systems. They overlap technically, both require strong access controls and incident reporting, but the purpose and authorities differ. GDPR is enforced by your national data protection authority. NIS2 is enforced sector by sector by the competent authorities in your country, coordinated nationally and supported by a national CSIRT. In Denmark, for example, that means Datatilsynet for GDPR, sector authorities such as the Health Data Authority and the Energy Agency for NIS2, coordinated by SAMSIK, with the Centre for Cybersecurity (CFCS) as national CSIRT. Incidents involving personal data breaches must be reported both under NIS2 (sector authority) and under GDPR Article 33 (Datatilsynet, 72 hours).
Do we need to register under NIS2?+
Yes, organisations in scope must register with the relevant national authority. Where and by when depends on your country. Denmark is a worked example below. The registration deadline was 1 October 2025. The supervisory structure is sector-based: the Danish Energy Agency (energy), Danish Health Data Authority (healthcare), Danish Transport Agency (transport), Danish Agency for Digital Government (cloud, DNS, datacentres, trust services), Danish FSA (finance, though primarily regulated by DORA), Danish EPA (drinking water). SAMSIK coordinates across sectors and is the competent authority for state entities and municipalities. Find your specific supervisory authority via samsik.dk or digst.dk. Outside Denmark, start with your national cybersecurity agency.