Abstract network of glowing blue nodes with one small cluster separated from the rest, illustrating NIS2 scope exclusions

NIS2 Exemptions: 8 Routes Out of Scope — and Why Only 4 Actually Remove You from the Directive

“Exempt” is doing three different jobs in most NIS2 guidance, and only one of them means what readers assume it means.

Directive (EU) 2022/2555 holds eight distinct ways an organisation ends up outside some or all of it, five of them inside Article 2 alone. Four remove your entity. Three remove obligations while leaving you in scope, supervised and registrable. One exists only in a recital. Confusing them is how a scope file ends up documenting a conclusion the entity cannot defend.

The Eight Exits, and What Each One Actually Removes

The distinction that matters is not “in or out” but what the provision disapplies. Two organisations can both call themselves exempt and sit in completely different positions — one deregistered, the other still on the national list under Article 3(3) registration duties with a narrow slice of obligations lifted.

Route Provision What it removes Who decides
Below the size threshold Art. 2(1) The entity is never brought into scope Automatic (facts)
Not a “public administration entity” Art. 6(35) The entity type is outside Annex I Automatic (definition)
Public body in national security, defence or law enforcement Art. 2(7) The Directive does not apply Automatic
Excluded from DORA by a Member State Art. 2(10) The Directive does not apply Member State option
National-security activity exemption Art. 2(8) Art. 21 and/or 23 plus Chapter VII, for those activities only Member State option
National-security information limit Art. 2(11) The duty to hand over specific information Claimed case by case
Equivalent sector-specific Union act Art. 4(1) The relevant provisions, including Chapter VII Automatic where equivalence is met
Diplomatic missions; bodies jointly established with a third country Recital 8 Stated as outside scope — non-binding Interpretive

One rule cuts through rows three and five: Article 2(9) provides that paragraphs 7 and 8 “shall not apply where an entity acts as a trust service provider.” A defence contractor that also issues qualified certificates cannot use the national-security route for that activity.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The Four Routes That Remove Your Entity

These four end the analysis. If one applies cleanly, there is no registration, no Article 21 measure set and no incident clock.

1. Size — Article 2(1), the default that catches almost everyone

NIS2 reaches Annex I and II entity types only where they “qualify as medium-sized enterprises” under Article 2 of the Annex to Recommendation 2003/361/EC or exceed those ceilings. Microenterprises (fewer than 10 staff, turnover or balance sheet at or below EUR 2 million) and small enterprises (fewer than 50 staff, EUR 10 million) sit outside by default — the threshold Ireland’s NCSC states in its national FAQ. Three details decide the borderline cases:

  • The upper ceiling is not a menu. Article 2(1) of the Annex reads “fewer than 250 persons and … EUR 50 million, and/or … EUR 43 million”, so exceeding the medium ceilings means 250 or more staff, or turnover above EUR 50 million and a balance sheet above EUR 43 million. A firm on EUR 60 million turnover with a EUR 30 million balance sheet is still medium-sized.
  • Public ownership does not inflate you. NIS2 Article 2(1) states that “Article 3(4) of the Annex to that Recommendation shall not apply” — the rule treating any enterprise 25% publicly controlled as non-SME. A council-owned water utility with 180 staff is sized on its own headcount. Only 3(4) is switched off, so the linked-enterprise rules survive: a 90-person subsidiary of a 4,000-person group is sized on consolidated figures.
  • The door closes slowly both ways. Article 4(2) of the Annex provides that crossing a ceiling “will not result in the loss or acquisition of the status … unless those ceilings are exceeded over two consecutive accounting periods.” One heavy year does not pull you in, and one lean year does not push you out.

Then the override: six points in Article 2(2), plus Articles 2(3) and 2(4), apply regardless of size — electronic communications providers, trust service providers, TLD registries and DNS providers, sole providers of an essential service, entities whose disruption carries public-safety or systemic risk, regionally critical entities, central and regional government, CER critical entities and domain name registration services. Work through those eight provisions before relying on headcount; our five-step scope test and the essential-entity criteria cover what follows.

2. Definition — Article 6(35), the exit nobody reads as an exit

Annex I sector 10 covers public administration entities, and Article 6(35) defines that term as excluding “the judiciary, parliaments or central banks” outright — those three never enter scope through the public-administration route. The definition then sets four cumulative criteria, and the fourth does the most work: the body must have “the power to address to natural or legal persons administrative or regulatory decisions affecting their rights in the cross-border movement of persons, goods, services or capital.” A publicly funded body issuing no such decisions is not a public administration entity for NIS2 purposes, though it may still be in scope through another Annex I or II activity. Our public administration guide covers the government-side mechanics.

3. Article 2(7) — the automatic public-sector exclusion

The text is unqualified: the Directive “does not apply to public administration entities that carry out their activities in the areas of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences.”

Recital 8 is non-binding interpretive material, but it is the only guidance on how far that reaches, and it narrows the route three ways. It indicates the exclusion should apply where activities are “predominantly” in those areas, that bodies “only marginally related” to them should not be excluded, and — the line worth quoting to any regulator claiming the route — that “entities with regulatory competences are not considered to be carrying out activities in the area of law enforcement.” Supervising a market is not law enforcement.

4. Article 2(10) — the only entity-named exclusion, and it is borrowed

Article 2(10) states that the Directive “does not apply to entities which Member States have exempted from the scope of Regulation (EU) 2022/2554 in accordance with Article 2(4) of that Regulation.” Follow the chain: DORA Article 2(4) lets Member States exclude the institutions named in Article 2(5), points (4) to (23), of Directive 2013/36/EU — a closed list of national promotional banks and cooperative lenders including Kreditanstalt für Wiederaufbau, Caisse des dépôts et consignations, Cassa depositi e prestiti, Bank Gospodarstwa Krajowego and Irish credit unions. Two conditions sit outside the entity’s control: it must fall inside points (4) to (23), and its Member State must have exercised the option — which DORA requires that state to notify to the Commission, which “shall make that information publicly available”. The evidence for this route is a public act, not an internal assessment.

The trap. DORA Article 2(3) separately excludes six categories from DORA itself, including small insurance intermediaries, occupational pension institutions with 15 or fewer members and Article 3(2) alternative investment fund managers. Article 2(10) cites only Article 2(4). Falling outside DORA under 2(3) buys nothing under NIS2 — those entities exit only if they are below the size threshold. Our DORA and NIS2 comparison maps the overlap.

The Four That Leave You In Scope

Each of these is routinely called an exemption. None removes the entity from the Directive.

Article 2(8) — partial, discretionary, activity-bounded. Member States “may exempt specific entities” carrying out national-security-type activities, or providing services exclusively to Article 2(7) bodies, from Article 21 or 23 “with regard to those activities or services”, with Chapter VII supervision lifted for the same slice. Only where an entity’s activities are exclusively of that type may a Member State also lift Articles 3 and 27, the registration duties. Ireland’s NCSC states the practical limit: exemptions “do not apply to general cybersecurity obligations, such as safeguarding critical networks and reporting incidents.”

Article 2(11) — an information shield. Obligations “shall not entail the supply of information the disclosure of which would be contrary to the essential interests” of national security, public security or defence. That limits what leaves the building during a supervisory request or an incident notification. Article 21 measures and Article 23 timelines continue to apply.

Article 4 — displacement, not exit. Where a sector-specific Union act imposes requirements “at least equivalent in effect”, Article 4(1) disapplies “the relevant provisions of this Directive, including the provisions on supervision and enforcement laid down in Chapter VII” — the provisions, not the Directive. DORA Article 1(2) is explicit that it “shall be considered a sector-specific Union legal act for the purposes of Article 4” in relation to financial entities “identified as essential or important entities pursuant to national rules transposing Article 3” of NIS2. The identification survives the displacement; that is the premise the sentence is built on. Article 4(1) adds that where a sector act does not cover all entities in a sector, NIS2 “shall continue to apply to the entities not covered”.

Recital 8’s unlisted cases. Recital 8 states that public bodies “jointly established with a third country in accordance with an international agreement” are excluded, and that the Directive does not apply to Member States’ diplomatic and consular missions in third countries or to systems on mission premises or operated for third-country users. No article carries either statement. Recitals explain intent and do not create or remove obligations, so treat both as a reading of Article 2(7) and confirm the position with the national competent authority.

What COM(2026) 13 Would Change — and What It Would Not

On 20 January 2026 the Commission published COM(2026) 13, a proposal amending NIS2 for simplification and alignment with the proposed Cybersecurity Act. It is a proposal, not law. Two genuine new exits are on the table. Article 2(2)(a)(iii) would be replaced with “top-level domain name registries” alone, an effect the explanatory memorandum describes as “removal of micro- and small-sized DNS service providers from the scope” — they would fall back to the ordinary size test. And Annex II point 3 would be retitled “Manufacture and production of chemicals”, with coverage re-tied to REACH registration duties under Article 6 and notification duties under Article 7(2) of Regulation (EC) No 1907/2006, so a pure distributor carrying neither duty would drop out.

What looks like a third exit is not one. Article 3(1)(a) would change from the medium-sized ceilings to the “small mid-cap” ceilings — under Recommendation (EU) 2025/1099, enterprises that are not SMEs, employ fewer than 750 persons and have turnover at or below EUR 150 million or a balance sheet at or below EUR 129 million. That reclassifies a large band of entities from essential to important: it changes the supervisory regime and the penalty ceiling, and removes nobody from scope. The proposal also moves traffic the other way, adding European Digital Identity Wallet and European Business Wallet providers to Article 2(2)(a) and, through a new Article 2(3a), operators of strategic dual-use infrastructure, all regardless of size. Article 2(1) and Articles 2(6) to 2(11) are untouched, so every route above survives the proposal as drafted.

How to Document the Exemption You Are Relying On

An exemption you cannot evidence on the day an authority asks is indistinguishable from non-compliance. What each role needs to hold differs:

Role What to hold on file
Compliance officer A dated scope memo naming the provision relied on, the supporting facts and the evidence source — re-tested at each accounting-period close
SME owner or director Two consecutive periods of annual-work-unit headcount and accounts, plus a documented walk-through of the six Article 2(2) points and Articles 2(3) and 2(4)
CISO or IT security manager Where Article 4 is relied on, the mapping of which NIS2 provisions the sector act displaces; where Article 2(8) is relied on, the activity boundary and what sits outside it
Board A minuted record that scope was assessed, by whom and when — a scope conclusion is a management decision, and it is the first one an authority tests

Two routes cannot be evidenced internally at all. Article 2(10) reliance depends on the Commission’s publication of Member State exclusions under DORA Article 2(4), confirmed with your national supervisor. Article 2(8) reliance depends on the national transposing law, because the option exists only where a Member State legislated it — check the national act, not the Directive. If the analysis lands you in scope, the Article 21 compliance checklist is the shortest route to a defensible file, and the small-business plan covers the case with no dedicated security hire.

Frequently Asked Questions

We have 30 employees. Are we exempt? By default, yes — small enterprises sit outside Article 2(1). But the size rule is a default, not a shield. Six points in Article 2(2) plus Articles 2(3) and 2(4) apply regardless of size, and several of them (sole provider of an essential service, regional criticality, systemic risk) are decided by your Member State rather than by you.

We are exempt under DORA. Does that put us outside NIS2? Only if the exemption came from DORA Article 2(4) and your Member State exercised it. DORA’s own Article 2(3) exclusions — small insurance intermediaries, small occupational pension institutions, Article 3(2) fund managers — are not referenced by NIS2 Article 2(10) and carry no NIS2 effect.

We dropped below 50 staff last year. Do our obligations end now? No. Under Article 4(2) of the Annex to Recommendation 2003/361/EC, status changes only where the ceilings are crossed over two consecutive accounting periods — and an entity stays on the national list until the competent authority updates it.

Key Takeaways

  • Only four routes remove your entity from NIS2: the Article 2(1) size threshold, the Article 6(35) definition, the Article 2(7) public-sector exclusion and the Article 2(10) DORA cascade.
  • Articles 2(8) and 2(11) and Article 4 lift obligations while leaving the entity in scope, identified and registrable.
  • Article 2(9) cancels the national-security routes for any entity acting as a trust service provider.
  • Falling outside DORA under its Article 2(3) has no NIS2 effect — Article 2(10) reaches only DORA Article 2(4).
  • Size status changes only over two consecutive accounting periods, so scope decisions are visible about a year ahead in both directions.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. European Union — Directive (EU) 2022/2555 (NIS2), Articles 2, 3, 4 and 6(35), and Recitals 8 and 9. EUR-Lex.
  2. European Commission — Recommendation 2003/361/EC on the definition of micro, small and medium-sized enterprises, Annex Articles 2, 3, 4(2) and 5. EUR-Lex.
  3. European Union — Regulation (EU) 2022/2554 (DORA), Articles 1(2), 2(3) and 2(4). EUR-Lex.
  4. European Union — Directive 2013/36/EU (CRD), Article 2(5), points (4) to (23), consolidated text. EUR-Lex.
  5. European Commission — Proposal for a Directive as regards simplification measures and alignment with the Cybersecurity Act, COM(2026) 13, 20 January 2026.
  6. European Commission — Recommendation (EU) 2025/1099 of 21 May 2025 on the definition of small mid-cap enterprises. EUR-Lex.
  7. National Cyber Security Centre Ireland — NIS2 FAQ.
  8. Covington (Global Policy Watch) — European Commission Proposes Targeted Amendments to NIS2, January 2026.
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: