Two networks merging into one, illustrating NIS2 scope aggregation in mergers and acquisitions

NIS2 in Mergers and Acquisitions: The 20-Point Due Diligence Checklist to Run Before You Sign

Search the NIS2 Directive for the word merger and you will find nothing. Search all 46 operative articles for takeover, change of control, successor, subsidiary or parent undertaking and you will find nothing either. The single occurrence of the word acquisition sits in Article 21(2)(e), where it means buying IT systems, not buying companies.

That silence is not an exemption. It means every transactional consequence of NIS2 is derived rather than stated — and the most important derivation is that a deal can put a company inside the Directive on completion day, with none of the grace period that organic growth would earn it. This guide sets out the derivation, then gives you the 20 items to work through before you sign.

Why the Directive’s Silence Is the Problem

NIS2 regulates entities, not transactions. Nothing in it is triggered by a share purchase agreement. What a deal changes is the inputs to tests that the Directive does contain, and those tests then produce different answers than they did the day before completion.

Four provisions carry almost all of the transactional weight:

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

  • Article 2(1) pegs scope to the EU’s SME definition, which aggregates corporate groups.
  • Article 3(4) requires in-scope entities to notify changes to their registered details within two weeks.
  • Article 26 decides which Member State supervises an entity, using a test that integration planning can move.
  • Article 34 calculates the turnover limb of maximum fines on the undertaking to which the entity belongs — not on the entity alone.

None of these mentions M&A. All four behave differently the morning after completion.

Pre-Deal: Does This Acquisition Create New NIS2 Obligations?

Start here, because everything else is conditional on it. Article 2(1) applies NIS2 to entities of a type listed in Annex I or II which “qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises” in that Article [1]. So NIS2 scope runs through the EU’s SME definition, and the SME definition is explicitly group-aware.

The ceilings themselves are the familiar ones: fewer than 250 staff and turnover at or below €50 million and/or a balance sheet at or below €43 million [10]. The part that decides deals is Article 6(2) of the same Annex, which adds 100 percent of the data of any enterprise linked directly or indirectly to the entity, while partner enterprises aggregate proportionally to the percentage interest in capital or voting rights, whichever is greater [10].

“Linked” is defined at Annex Article 3(3) and is broader than a majority shareholding. It covers a majority of voting rights, a right to appoint or remove a majority of the board, a right to exercise dominant influence under contract or the articles, and control of a majority of votes under a shareholders’ agreement [10]. Germany’s competent authority, the BSI, states the consequence plainly: headcount and turnover relate to the whole undertaking, including linked enterprises [11].

So the deal structure, not the target’s payroll, decides the answer:

Deal structure SME Annex treatment Effect on the target’s scope test
Majority acquisition, or board-appointment rights Linked enterprise (Art. 3(3)) Buyer’s full headcount and financials added at 100%. A 40-person target inside a 900-person group is sized at 940.
Minority stake of 25% or more, no control Partner enterprise (Art. 3(2)) Aggregated pro rata. A 30% stake adds 30% of the investor’s figures — often not enough to cross a ceiling.
Minority stake below 25% Neither Target stays autonomous and is sized on its own data.
Buyer is a public body taking 25% or more Annex Art. 3(4) disapplied by NIS2 Public ownership alone does not strip SME status for NIS2 purposes. See below.

That last row is a genuine quirk worth knowing. Annex Article 3(4) normally says an enterprise cannot be an SME if public bodies control 25 percent or more of its capital or voting rights [10]. Article 2(1) of NIS2 switches that rule off in one sentence: “Article 3(4) of the Annex to that Recommendation shall not apply for the purposes of this Directive” [1]. Germany reproduces the carve-out in section 28(4) BSIG [12]. In practice, a sovereign fund, state development bank or municipal holding taking a 25 percent stake does not by itself drag the target into NIS2, whereas the same stake would remove SME status under other EU programmes. Whether that owner’s own figures aggregate is then a separate question answered by the partner and linked tests above.

The Grace Period That Does Not Apply to Your Deal

Here is the finding that most cyber due diligence misses entirely.

Annex Article 4(2) gives growing companies a buffer: crossing a ceiling “will not result in the loss or acquisition of the status of medium-sized, small or microenterprise unless those ceilings are exceeded over two consecutive accounting periods” [10]. Read alone, that suggests a newly acquired target has roughly two financial years before NIS2 bites.

It does not. The European Commission’s official User guide to the SME definition addresses the point directly: Article 4.2 exists so that growing firms “are not penalised with loss of SME status unless they exceed the relevant thresholds for a sustained period”, and therefore it “does not apply in the case of enterprises that exceed the relevant SME thresholds as a result of a change in ownership following a merger or acquisition, which is usually not considered temporary and not subject to volatility”. Such enterprises “need to be assessed on the basis of their shareholder structure at the time of the transaction, not at the time of closure of the latest accounts”, and so “the loss of SME status may be immediate” [10].

The practical contrast is stark. A 45-person company that hires its way to 60 staff keeps small-enterprise status — and stays below the size cap — until it has exceeded the ceiling in two consecutive accounting periods. The same 45-person company acquired by a 900-person group is assessed on its shareholder structure at the transaction date instead, and is sized at 945 from that date. There is no two-year runway to plan into. Compliance obligations that the diligence team treated as a year-two integration workstream are live from completion.

The 20-Point NIS2 Compliance Due Diligence Checklist

Work through these in order. Items 1 to 4 determine whether the rest matter at all.

# Check What a good answer looks like
A. Scope and classification
1 Is the target’s activity of a type listed in Annex I or II, on the facts rather than on its registered business line? A written mapping of each operating activity to a named Annex entry, including activities the target treats as incidental.
2 Re-run the size test with post-completion aggregation: linked at 100%, partners pro rata (Annex Art. 6(2)). A worked calculation on the post-deal group, not the target’s standalone accounts.
3 Does any size-independent trigger in Article 2(2) to 2(4) apply, regardless of the arithmetic? Explicit consideration of trust services, DNS and TLD, public electronic communications, sole-provider status and CER critical-entity designation.
4 If in scope, is the target essential (Art. 3(1)) or important (Art. 3(2))? The classification, because it decides whether supervision is ex ante or ex post.
B. Registration and filings
5 Is the target already registered with the competent authority in every Member State where it should be? Dated registration confirmations, not an assertion that it “should be covered”.
6 Are the registered details still accurate — name, address, contacts, IP ranges, sectors, Member State list? A current extract, reconciled against the deal’s post-completion reality.
7 Which change-notification deadline applies after completion: two weeks or three months? An owner named for the filing and a diarised date. See the table below.
C. Article 21 evidence
8 Documented evidence against each of the ten measures in Article 21(2)(a) to (j). Approved, dated, version-controlled documents — not draft policies or slideware.
9 Supply chain security under Article 21(2)(d): is there a classification of direct suppliers with security requirements flowed into contracts? A supplier register that distinguishes direct from indirect, since 21(2)(d) reaches direct relationships.
10 Evidence under Article 21(2)(f) that the measures’ effectiveness has actually been assessed. Test results and remediation records, with dates.
11 Any self-identified non-compliance the target has recorded but not yet remediated. A remediation log. Article 21(4) makes this a live duty, not a backlog.
D. Jurisdiction and integration
12 Which Member State has jurisdiction under Article 26, and will the deal move it? An answer that survives the buyer centralising security decisions. See below.
13 Does the target rely on an independence argument to stay out of scope, and does its Member State recognise one? Named national provision, or an acknowledgement that no such carve-out exists there.
E. Enforcement and incident history
14 Open supervisory or enforcement action: warnings, binding instructions, orders, monitoring officers (Art. 32(4)). Full correspondence with the competent authority, not a summary.
15 Any suspension of certification or authorisation, or any prohibition on a manager, under Article 32(5). Confirmation either way in writing, given the deal-blocking potential.
16 Complete Article 23 incident history: early warnings, notifications, final and progress reports. The filings themselves. Prior infringements are an aggravating factor under Article 32(7)(c).
F. Contractual and post-close
17 Warranties covering scope status, registration, Article 21 measures and incident history. Warranties drafted to the specific provisions, not a generic “compliance with laws” catch-all.
18 Indemnity for pre-completion non-compliance, sized against the post-completion fine base. A number derived from Article 34’s turnover limb applied to the buyer’s group.
19 On a carve-out, will retained services become a direct supplier relationship under Article 21(2)(d)? Transitional services agreements drafted with the supply chain measure in mind.
20 A day-one plan: board approval, registration filings, remediation clock, reporting lines. Named owners and dates, agreed before signing rather than after.

What Changes on Completion Day

Four things move at once, and none of them wait for integration to finish.

The fine ceiling re-prices. Article 34(4) requires Member States to provide for fines on essential entities of “a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher”; Article 34(5) sets €7 000 000 or 1,4 percent for important entities [8]. The turnover base is the undertaking the entity belongs to. A standalone target with €20 million of turnover sits near the euro floor. Inside a €2 billion group, the percentage limb dominates. Note the construction carefully: “a maximum of at least” sets a floor for the national ceiling, so a Member State may transpose a higher maximum — which is why NIS2 penalty levels have to be checked nationally. These are ceilings a regulator may reach, not amounts it will impose — Article 34(1) and (3) require fines to be proportionate and to take account of the Article 32(7) factors.

Board liability attaches to your directors. Article 20(1) requires management bodies to approve the entity’s Article 21 measures, oversee implementation, and provides that they “can be held liable for infringements by the entities of that Article” [6]. The liability is tied to Article 21 specifically, not to the Article 23 reporting duties. Directors appointed at completion inherit an approval duty over measures they have not yet seen, which is the practical core of management-body accountability under Article 20.

A remediation clock starts. Article 21(4) provides that an entity finding it does not comply “takes, without undue delay, all necessary, appropriate and proportionate corrective measures” [5]. Diligence findings are therefore not only a price argument. Once the entity is in scope and the buyer controls it, documented knowledge of a gap engages a legal duty to fix it.

The registration clock starts, and its length depends on entity type.

Obligation Legal basis Deadline
Notify changes to registered details (general in-scope entities) Art. 3(4), second sub-paragraph Without delay, and in any event within two weeks of the date of the change [2]
Notify changes to registry details (DNS, cloud, data centre, CDN, MSP, MSSP, marketplaces, search, social) Art. 27(3) Without delay, and in any event within three months of the date of the change [3]; Germany transposes the same three months at section 34(2) BSIG [14]
Germany: changes to registered details Section 33(5) BSIG Two weeks, running from knowledge of the change [13]
Germany: first registration after qualifying Section 33(1) BSIG Three months after first or renewed qualification as an in-scope entity [13]

The two-week versus three-month split catches groups out, because the shorter deadline applies to the ordinary industrial and services entities that make up most deal flow, while the longer one applies to the digital infrastructure providers people assume are more heavily regulated. Germany’s transposition also runs its two-week clock from knowledge of the change rather than from the change itself — a small, entity-favourable divergence, and a reminder that these deadlines are national.

Integration Decisions That Change Scope

Two integration choices have direct regulatory consequences, and both are usually made by people who never see the compliance analysis.

Centralising security decisions can move the regulator. For most entities Article 26(1) assigns jurisdiction to the Member State of establishment. For the digital infrastructure categories, Article 26(1)(b) instead uses main establishment, defined at Article 26(2) as the Member State “where the decisions related to the cybersecurity risk-management measures are predominantly taken”, falling back to where cybersecurity operations are carried out, then to the establishment with the highest Union headcount [4]. Moving risk decisions to a group CISO in another Member State can therefore move which authority supervises the entity.

Integrating the target’s IT can create scope — in some Member States. Recital 16 states that, to avoid disproportionate outcomes, Member States “are able to take into account the degree of independence an entity enjoys in relation to its partner or linked enterprises” when applying Annex Article 6(2), specifically independence “in terms of the network and information systems that that entity uses in the provision of its services” [9]. Two cautions. This is a recital, so it is interpretive rather than binding, and it grants an option that each Member State chooses whether to exercise. Germany did exercise it: section 28(4) sentence 2 BSIG provides that partner and linked enterprise data are not aggregated where the entity is independent of them as regards the nature and operation of its IT systems, components and processes [12]. Where that option is in force, migrating an acquired business onto group infrastructure can be the step that removes its independence argument. Recital 16 also states its own limit — it leaves unaffected the obligations of partner and linked enterprises that are themselves in scope.

The inverse applies on a carve-out. A service delivered internally is governed by the entity’s own Article 21 measures. Spin the unit out and retain the service, and it becomes a relationship with a direct supplier, squarely inside Article 21(2)(d) and its requirement at Article 21(3) to take account of vulnerabilities specific to each direct supplier [5]. Divestment converts an internal control problem into a documented supply chain security obligation.

Once the deal completes, these decisions become a sequencing problem with legal deadlines attached: the registration update is due within two weeks under Article 3(4), and it cannot be filed until the jurisdiction question is answered. Our companion guide sets out the Day-1 to Day-90 NIS2 integration sequence for merged entities, including how to resolve a genuine conflict between two entities’ existing controls.

What You Cannot Get Before Signing

You cannot get a regulator to confirm the answer. The BSI states that it does not issue a binding determination of whether an individual entity is or is not in scope, cannot carry out a legal assessment of an individual case, and recommends that entities obtain external legal advice where the position remains unclear after self-assessment [11].

That has a direct drafting consequence. Because no authority will underwrite the scope conclusion before completion, scope risk has to be allocated between the parties rather than resolved by a third party — through warranties on the facts the analysis depends on, and an indemnity sized against the post-completion fine base. Items 17 and 18 of the checklist are not boilerplate; they are the mechanism that carries the uncertainty the regulator will not remove.

Frequently Asked Questions

Does an acquisition transfer the target’s NIS2 obligations to the buyer? No, and the framing is misleading. Obligations attach to the entity. In a share purchase the entity persists and its obligations persist with it, including the aggravating weight of any prior infringements under Article 32(7)(c) [7]. What changes is the group the entity belongs to, which is what re-prices the Article 34 turnover limb.

Our target has 40 employees. Is it really in scope? Possibly, and its own headcount will not tell you. If the acquisition makes it a linked enterprise, Annex Article 6(2) adds 100 percent of the group’s data [10]. Run item 2 of the checklist on the post-deal structure.

We are buying a non-EU company that sells into the EU. Does NIS2 apply? Article 2(1) covers entities that provide services or carry out activities within the Union [1]. For the Article 26(1)(b) categories, an entity not established in the Union that offers services there must designate a representative, and falls under the jurisdiction of that representative’s Member State [4].

How long do we have to register after completion? Under the Directive, changes to already-registered details are due within two weeks (Article 3(4)) or three months for Article 27 registry entities [2][3]. First-time registration deadlines are set nationally — Germany allows three months from first or renewed qualification [13].

Can we keep the target out of scope by keeping its IT separate? Only where the Member State has exercised the Recital 16 option, as Germany has in section 28(4) BSIG [9][12]. It is a real argument in those jurisdictions and no argument at all elsewhere, so confirm the national position before relying on it.

Before You Sign

The Directive’s silence on M&A is not a gap to be exploited; it is a set of consequences that arrive without being announced. Three of them deserve to be on the deal timetable rather than the integration plan: scope can change on completion day because the two-year SME grace period does not survive a change of ownership, the maximum fine exposure attached to the target is recalculated against the buyer’s group turnover, and a two-week notification deadline may already be running while the parties are still congratulating each other.

Run the 20 items before signing. The ones that change the price are in sections A, E and F. The ones that change the integration plan are in section D — and those are the ones that get decided by default if nobody raises them.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Directive (EU) 2022/2555, Article 2 — Scope
  2. Directive (EU) 2022/2555, Article 3 — Essential and important entities
  3. Directive (EU) 2022/2555, Article 27 — Registry of entities
  4. Directive (EU) 2022/2555, Article 26 — Jurisdiction and territoriality
  5. Directive (EU) 2022/2555, Article 21 — Cybersecurity risk-management measures
  6. Directive (EU) 2022/2555, Article 20 — Governance
  7. Directive (EU) 2022/2555, Article 32 — Supervisory and enforcement measures in relation to essential entities
  8. Directive (EU) 2022/2555, Article 34 — General conditions for imposing administrative fines
  9. Directive (EU) 2022/2555, Recital 16
  10. European Commission, User guide to the SME definition (includes the Annex to Recommendation 2003/361/EC)
  11. Bundesamt für Sicherheit in der Informationstechnik, "NIS-2-FAQ (allgemein)" (bsi.bund.de)
  12. BSIG section 28 — Besonders wichtige Einrichtungen und wichtige Einrichtungen
  13. BSIG section 33 — Registrierungspflicht
  14. BSIG section 34 — Besondere Registrierungspflicht für bestimmte Einrichtungsarten
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: