NIS2 compliance guide for public administration -- central government and regional authorities scope and Article 21 obligations

Which Public Administration Bodies Are Exempt from NIS2? Recital 8 and Article 6(35) Explained — Plus Article 21 Obligations for Ministries and Regional Authorities

Most NIS2 guidance for public sector teams opens with Article 21 and works backwards. This guide does the opposite — because for government bodies, the first question isn’t what you must do, it’s whether you’re in scope at all. The answer depends on two legally distinct mechanisms that almost no published guidance explains clearly: the definitional exclusion in Article 6(35), which removes courts, parliaments, and central banks from scope before the directive even applies, and the functional exclusion in Article 2(7), which carves out national security, defence, and law enforcement activities entirely. Once you understand which side of those lines your organisation sits on, the Article 21 implementation path becomes considerably clearer.

This guide covers central government ministries, agencies, and the regional authorities that fall within Annex I Section 10 of the directive. It maps all ten Article 21 measures to government-specific implementation challenges, explains the Article 20 governance obligations that apply to ministers and permanent secretaries, and addresses the Article 34(7) enforcement regime — which is materially different for public entities than for commercial operators.

The Four Mechanisms That Remove Government Bodies from NIS2 Scope

NIS2 uses two operative provisions and two interpretive tools to determine which government bodies fall outside its reach. Understanding all four prevents both over-compliance and under-compliance.

Mechanism 1 — The definitional exclusion (Article 6(35)). The directive’s definition of “public administration entity” explicitly excludes three categories of institution: the judiciary, parliaments, and central banks. This is not a carve-out from scope — it is a prior filter that prevents these institutions from qualifying as “public administration entities” in the first place. A court processing judicial decisions, a national parliament legislating, or a central bank conducting monetary policy is, by definition, outside Annex I Section 10, regardless of the cybersecurity risks those systems might present.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Mechanism 2 — The functional exclusion (Article 2(7)). The directive does not apply to public administration entities that carry out their activities “in the areas of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences.” This covers intelligence services, police forces, border control agencies, prosecution services, and defence ministries where those domains are the primary activity.

Mechanism 3 — The partial exemption (Article 2(8)). Where an entity carries out some activities in national security, public security, defence, or law enforcement — but not exclusively — member states may exempt it from Articles 21 or 23 only with regard to those specific activities. The entity remains in scope for everything else it does. If the body operates exclusively in excluded areas, member states may additionally exempt it from Articles 3 and 27 (the registration and classification requirements). One constraint: this exemption cannot apply where the entity acts as a trust service provider — those activities remain in NIS2 scope regardless.

Mechanism 4 — The “predominantly” interpretive standard (Recital 8). Recital 8 of the directive clarifies that the functional exclusions apply to entities “whose activities are predominantly carried out” in the excluded areas. Entities with only marginal involvement in national security or law enforcement remain in scope. This interpretive standard governs the hard cases of mixed-function bodies.

Exclusion mechanism Legal basis Applies to Result
Definitional Article 6(35) Judiciary, Parliament, central banks Not “public administration entities” — fully outside Annex I scope
Functional (full) Article 2(7) National security, defence, law enforcement (primary activity) Fully outside NIS2
Functional (partial) Article 2(8) Mixed-function bodies with some security activities Exempt for security activities only; in scope for the rest
Interpretive standard Recital 8 All government bodies with some security involvement “Predominantly” = excluded; “marginally” = in scope

Who Is in Scope: Central Government, Ministries, and Agencies

Once excluded entities are set aside, the in-scope population for public administration is defined by Annex I Section 10 of the directive, which covers two distinct categories.

Section 10(a) — Central government entities. This covers public administration entities of the central government as defined by a member state in accordance with national law. It includes most ministries and their executive agencies, central regulators, and government departments not falling within one of the four exclusion mechanisms above.

Section 10(b) — Regional-level entities. These are public administration entities at regional level, but only where the member state has determined through risk assessment that those entities have an impact on critical societal or economic activities. Regional scope is not automatic — it follows a national designation decision.

Central government entities under Section 10(a) are treated as essential entities regardless of size. The standard medium-sized enterprise threshold — 50 or more employees, or annual turnover exceeding €10 million — that governs entry into NIS2 scope for most other sectors does not apply to central government. A ministry with 15 staff is as firmly in scope as one with 15,000.

The Article 6(35) definition sets four qualifying criteria that must all be satisfied before a body qualifies as a “public administration entity” at all:

  1. It serves general interest needs without an industrial or commercial character
  2. It has legal personality, or the authority to act on behalf of another body with legal personality
  3. It is primarily State-financed and subject to public-sector management oversight
  4. It holds the power to issue administrative decisions affecting rights in the cross-border movement of persons, goods, services, or capital

The fourth criterion is often overlooked. A State-funded body that provides internal IT services to other agencies — but lacks statutory authority to issue binding administrative decisions affecting cross-border economic activity — may not satisfy this criterion. Legal teams should verify all four against the body’s constituting legislation before assuming scope inclusion.

Regional Authorities: In Scope Only After Member State Risk Assessment

Regional governments occupy an intermediate position in the NIS2 framework. They are potentially in scope under Annex I Section 10(b) — but only if the member state has determined through risk assessment that their disruption would significantly impact critical societal or economic activities. This is a national policy decision, not an automatic classification.

In practice, the “significant impact” test favours designation of regional authorities delivering services with high disruption consequences: emergency management coordination, regional hospital network administration, major transport infrastructure oversight. Regional cultural or tourism agencies are less likely to meet the threshold.

For local-level entities — municipalities, district councils — Article 2(5) gives member states discretionary power to extend NIS2, but there is no obligation to do so. Most member states focused initial transposition on central and regional government, deferring local-level inclusion. Ireland’s National Cyber Security Centre confirms that the local authority position depends on national designation rather than any automatic rule.

If your organisation operates at regional level, the correct step is to consult your national competent authority’s designation guidance. This cannot be resolved from the NIS2 text alone. For a fuller overview of how scope operates across all sectors, see the NIS2 scope and entity classification guide.

Mixed-Function Bodies: The Article 2(8) Partial Exemption in Practice

The most complex scope questions arise for bodies that perform both ordinary government functions and activities touching national security, law enforcement, or public security. Article 2(8) handles these cases — but it works differently from how most compliance guidance presents it.

Article 2(7) uses the phrase “carry out their activities” in the excluded areas — not “are occasionally involved in.” An interior ministry that administers immigration policy, social cohesion grants, and civil registration — but also houses a border intelligence unit — does not automatically qualify for the full Article 2(7) exclusion. The primary activity determines default scope status, informed by Recital 8’s “predominantly” standard.

Where a mixed-function body is in scope overall, Article 2(8) allows a member state to exempt it from Articles 21 or 23 obligations only with regard to the specific national security or law enforcement activities. This is an activity-level exemption, not an entity-level one. The body must still comply with NIS2 for everything else it does.

Two constraints apply. First, if the body operates exclusively in excluded areas, the member state may additionally exempt it from Articles 3 and 27 (registration and classification). Second, any activities performed as a trust service provider cannot be exempted under Article 2(8) even if the entity otherwise qualifies — trust service obligations survive regardless.

Classification: Why Central Government Is Always Essential

Under Article 3(1) of NIS2, public administration entities of the central government falling within Annex I Section 10(a) are classified as essential entities automatically — without any size assessment or further designation step. There is no mechanism to reclassify them as important entities.

Essential entity status has significant downstream consequences beyond the higher penalty ceiling. Under Article 32, essential entities face proactive supervision: competent authorities may conduct scheduled inspections, targeted security audits, and reviews of security policies without waiting for an incident to occur. For important entities under Article 33, supervision is primarily reactive, triggered by evidence of non-compliance. Government IT teams accustomed to internal audit cycles need to prepare for external proactive inspection visits.

Essential entity status also triggers the Article 27 registration requirement. Registration is a precondition for proper supervisory classification and oversight. Most member states opened registration windows in 2024 or 2025. To understand how essential entity obligations differ from those of important entities, see the NIS2 requirements guide.

All 10 Article 21 Measures: Government-Specific Implementation Notes

Article 21(2) requires both essential and important entities to adopt an “all-hazards approach” across ten risk management measure categories. Public administration entities face specific implementation challenges for several of these that differ substantially from commercial operator experience.

Measure Art. 21(2) Government-specific consideration
Risk analysis & security policy (a) Must cover both classified and unclassified systems; national security systems outside NIS2 scope cannot be ignored in the risk accounting for in-scope systems they connect to
Incident handling (b) Article 23 early warning runs to the national CSIRT; cross-agency incident coordination procedures need explicit documentation beyond internal IT protocols
Business continuity (c) Emergency planning obligations under national crisis management law overlap with NIS2 BCP requirements but do not substitute for the NIS2 documentation trail
Supply chain security (d) Public procurement rules apply; security requirements must be in technical specifications, not award criteria, to avoid non-discriminatory tendering conflicts
System acquisition & maintenance (e) Legacy government systems with long procurement cycles create patching exposure; formal risk-acceptance documentation required for systems that cannot be updated
Effectiveness assessment (f) Supreme audit institutions may conduct NIS2 effectiveness reviews; under Art.32(4)(c) the competent authority can order a security audit at the entity’s own expense
Cyber hygiene & training (g) Article 20(2) mandates training for the management body specifically; civil service training procurement must account for NIS2 requirements across all staff tiers
Cryptography & encryption (h) National cryptographic standards may be stricter than the NIS2 minimum; comply with whichever sets the higher bar
Access control & HR security (i) Security clearance processes reduce but do not eliminate NIS2 access control requirements; joiner/mover/leaver procedures must apply across all civil service roles
MFA & secure communications (j) Cross-agency communication systems — government email infrastructure, emergency communication lines — must meet the secure communications standard in Article 21(2)(j)

Supply chain security under Article 21(2)(d) deserves particular attention. Public procurement law requires transparent, non-discriminatory supplier selection. NIS2 demands entity-specific risk assessment of each direct supplier’s vulnerabilities. The workable solution is to define minimum security requirements in technical specifications — standards every compliant bidder must meet — rather than as scored award criteria. This avoids discriminatory tendering while still generating the documented supplier assessment NIS2 requires. For the full treatment, see the NIS2 public administration supply chain guide.

For incident handling and the Article 23 reporting obligations, including the 24-hour early warning and 72-hour CSIRT notification timelines, the NIS2 public administration incident response guide covers the notification chain in detail.

Article 20 Governance: Minister and Management Board Accountability

Article 20(1) requires management bodies of essential and important entities to formally approve the cybersecurity risk-management measures taken under Article 21 and to oversee their implementation. Management bodies can be held liable for infringements of Article 21.

For public administration entities, “management body” typically means the minister or secretary of state and the permanent secretary or secretary-general of the department. The directive contains a specific carve-out for this: Article 20(1) states its application is “without prejudice to national law as regards the liability rules applicable to public institutions, as well as the liability of public servants and elected or appointed officials.”

This carve-out means that the personal liability mechanism in Article 32(5) — which allows competent authorities to temporarily ban named executives of private-sector essential entities from management roles — may not apply to ministers or civil servants in the same way. The member state’s own constitutional and civil service law governs personal accountability for public officials.

What Article 20 does unambiguously require from government management, regardless of the personal liability rules:

  • Documented formal approval of the entity’s cybersecurity risk-management framework and all Article 21 measures
  • Regular cybersecurity training for management body members per Article 20(2)
  • Demonstrable active oversight of implementation — not delegation of the entire programme to IT leadership without management engagement

Practically, government departments need records showing that ministerial or secretary-general approval was obtained — board papers, signed approval documents, or meeting records showing the security posture was reviewed. Undocumented verbal approval will not withstand an Article 32 proactive supervisory inspection.

Penalties and Enforcement Under Article 34(7)

Enforcement against public administration entities follows a materially different track from enforcement against commercial operators, and Article 34(7) reflects this deliberately.

For commercial essential entities, Article 34(4) sets maximum fines of €10,000,000 or 2% of total worldwide annual turnover. For public administration entities, Article 34(7) takes a different approach: “each Member State may lay down the rules on whether and to what extent administrative fines may be imposed on public administration entities.” This is a discretionary rather than mandatory framework. Member states decide whether their national implementation includes financial penalties for government bodies at all.

The rationale is practical: fining a government ministry means transferring public funds between parts of the state treasury. The supervisory measures that drive meaningful behavioural change in government are the operational enforcement powers under Article 32(4), which apply regardless of whether the member state has activated financial penalties:

Enforcement measure Legal basis Application to government
Binding instructions with deadline Art.32(4)(d) Competent authority mandates specific remediation; non-compliance is itself an infringement
Security audit order Art.32(4)(c) Independent audit at entity’s own expense; applies to government entities
Compliance notification Art.32(4)(e) Formal notice that non-compliance will escalate to further supervisory action
Suspension of authorisations Art.32(4)(h)–(i) Applies where the government body holds service licences or certifications

For government compliance teams, the realistic enforcement exposure is reputational damage from published supervisory findings and the operational cost of mandated remediation programmes — not a financial fine the treasury absorbs. Build the compliance programme to withstand an Article 32 inspection. For the full penalty regime across entity types, see the NIS2 penalties and enforcement guide.

A Six-Step Compliance Roadmap for Public Administration Entities

This roadmap applies to central government entities confirmed to be in scope. Regional authorities subject to member state risk-based designation should complete Step 1 before proceeding.

  1. Confirm scope status. Apply the four exclusion mechanisms above. Verify against national competent authority guidance that your body is designated in scope. Review the national transposition law for any additional public administration-specific provisions. The NIS2 compliance checklist provides a starting structure once scope is confirmed.
  2. Register with the competent authority under Article 27. Registration is a precondition for proper classification. Most member states opened registration windows in 2024 or 2025. Unregistered bodies remain legally in scope and subject to proactive supervision, with failure to register constituting its own infringement.
  3. Conduct a formal risk assessment per Article 21(2)(a). Government bodies with existing ISO 27001 programmes or national security baseline frameworks should assess whether those frameworks satisfy the NIS2 all-hazards approach. The NIS2 risk assessment guide covers the methodology options and gap analysis approach.
  4. Obtain management body sign-off under Article 20(1). Document formal approval by the minister or secretary-general. Create records adequate for proactive supervisory inspection: meeting minutes, signed approval documents, or board papers showing the security posture was reviewed.
  5. Implement all 10 Article 21 measures. Prioritise incident handling (Art.21(2)(b)) and access control (Art.21(2)(i)) if starting from minimal documentation — these are the measures most commonly assessed in early compliance inspections. ENISA’s June 2025 Technical Implementation Guidance provides practical evidence examples across all 13 security domains.
  6. Train management and staff. Article 20(2) mandates cybersecurity training for management body members specifically. Civil service training procurement must account for NIS2 requirements. Staff communication about new obligations is required but does not substitute for the mandatory management-body training.

Frequently Asked Questions

Does NIS2 apply to EU institutions such as the European Commission or European Parliament?

No. The NIS2 Directive applies to entities in EU member states. EU institutions operate under separate EU cybersecurity legal frameworks and are not subject to NIS2.

Our ministry handles both civilian policy and classified defence procurement. Must we comply with NIS2?

Most likely yes — for the civilian policy functions at minimum. Article 2(7) excludes entities carrying out activities in defence, but Article 2(8) allows member states to exempt only the specific defence-related activities. The civilian functions would typically remain in scope. Confirm with your national competent authority which specific activities qualify for an Article 2(8) exemption in your jurisdiction.

Can a central government entity be reclassified as an important entity?

No. Article 3(1) classifies central government bodies within Annex I Section 10(a) as essential entities automatically. There is no reclassification mechanism available. Regional entities designated under Section 10(b) may be classified as essential or important depending on member state implementation.

What happens if a ministry fails to register under Article 27?

Failure to register is itself an infringement of the directive regardless of whether Article 21 measures have otherwise been implemented. Competent authorities can issue binding instructions requiring registration and may treat unregistered status as an aggravating factor in any subsequent enforcement action.

Do local councils need to comply with NIS2?

Only if the member state has exercised its Article 2(5) discretion to extend NIS2 to local-level public administration entities. This varies by jurisdiction — check the national transposition law in your country.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS2 Directive, Article 6: Definitions — nis-2-directive.com. Article 6(35) definition of public administration entity.
  2. NIS2 Directive, Article 2: Scope — nis-2-directive.com. Articles 2(6), 2(7), 2(8), and Recital 8.
  3. NIS2 Directive 2022/2555, Article 2 — nis2resources.eu. Article 2(2)(f) and 2(5) coverage for regional and local entities.
  4. NIS2 Directive, Article 21: Cybersecurity Risk-Management Measures — nis-2-directive.com.
  5. NIS2 Directive, Article 20: Governance — nis-2-directive.com. Article 20(1) public institution carve-out.
  6. NIS2 Directive, Article 34: Administrative Fines — nis-2-directive.com. Article 34(7) public administration discretion.
  7. National Cyber Security Centre Ireland, NIS2 FAQ — ncsc.gov.ie. National competent authority guidance.
  8. ENISA NIS2 Technical Implementation Guidance — enisa.europa.eu. Published June 2025.
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: