“Who does NIS2 apply to?” is the question that has put thousands of new organizations on notice across Europe. The NIS2 Directive dramatically widened the scope of EU cybersecurity rules, and many businesses are now regulated for the first time. This guide explains exactly who is covered, the essential-versus-important distinction, and how to check your own status.

For the full picture, see our complete NIS2 Directive guide.
Essential vs. important entities
NIS2 splits covered organizations into two categories. Essential entities operate in the most critical sectors and face proactive supervision. Important entities are also in scope but subject to lighter, reactive supervision — typically investigated after an incident or concern. Both must meet the same core security and reporting obligations; the difference lies mainly in how they are supervised and in the maximum penalties they face. Determining which category you fall into is an early, important step.
The sectors NIS2 covers
NIS2 covers a wide span of sectors. Highly critical sectors include energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space. Other critical sectors include postal and courier services, waste management, chemicals, food, manufacturing (such as medical devices, computers, and machinery), digital providers (including online marketplaces, search engines, and social platforms), and research. If your organization operates in any of these areas, NIS2 should be on your radar.
The size threshold
In general, NIS2 applies to medium and large organizations in the covered sectors — broadly those with at least 50 employees or annual turnover and balance sheet above defined thresholds. However, size is not the only test: certain entities are included regardless of size because of their critical role, such as some providers of public electronic communications, trust services, and DNS or top-level-domain services. Always check the specific rules in the member states where you operate.
Are you in scope? A quick check
Ask three questions. First, do you operate in one of the NIS2 sectors? Second, are you a medium or large organization — or one of the size-independent categories? Third, do you provide services in the EU? If you answer yes to the sector and size questions and operate in the EU, you are very likely in scope and should begin your NIS2 programme now. Because NIS2 is transposed nationally, confirm the details for each country in which you operate.
In scope? Get compliant faster.
Our NIS2 Toolkit gives essential and important entities the security policies, incident-response procedures, and governance records needed to meet NIS2 — editable in Word and Excel.
Frequently asked questions
Who does NIS2 apply to?
Essential and important entities in critical sectors — such as energy, transport, health, digital infrastructure, banking, and public administration — generally medium and large organizations, with some included regardless of size.
What is the difference between essential and important entities?
Both must meet the same core obligations, but essential entities face proactive supervision and higher maximum penalties, while important entities face lighter, reactive supervision.
Does NIS2 apply to small businesses?
Usually not, since NIS2 generally targets medium and large organizations — but some small entities are included because of their critical role, such as certain communications and trust-service providers.