NIS2 Scope Test: Determine Your Entity Status in 5 Steps — Before Your National Authority Does It for You
Two numbers drive most NIS2 scope analyses: 50 employees and €10 million in annual turnover. Cross either threshold in a listed sector, and most organisations assume they have their answer. They are usually right — and sometimes wrong in ways that are expensive to correct.
What the two-number test misses: whether your corporate group structure consolidates your entity above the threshold when linked enterprises are counted (a logistics subsidiary with 30 staff and a 300-person parent may not be small under EU enterprise law); and which national authority actually supervises you when you operate across borders. Both factors are routinely overlooked in first-pass scope assessments.
This guide structures scope determination as a five-step test, ordered to eliminate the most organisations first. NIS2 (Directive (EU) 2022/2555) [1] places the self-identification obligation on your organisation — national competent authorities will not notify you that you are in scope. [8]
Step 1 — Check Your Sector: Annex I or Annex II?
The gateway question is sector coverage. If your organisation does not operate in a sector listed in Annex I (sectors of high criticality) or Annex II (other critical sectors) of the Directive, NIS2 does not apply regardless of your size. [1]
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Annex I — 11 Sectors of High Criticality [2]
| Sector | Covered entity types |
|---|---|
| Energy | Electricity generators and distributors, gas transmission and distribution operators, oil pipeline and storage operators, hydrogen producers |
| Transport | Airlines, airport management bodies, railway operators, inland waterway and shipping companies, road freight operators |
| Banking | Credit institutions |
| Financial Market Infrastructure | Operators of trading venues, central counterparties |
| Health | Hospitals, EU reference laboratories, pharmaceutical manufacturers (including vaccines), critical medical device makers |
| Drinking Water | Suppliers and distributors of water intended for human consumption |
| Waste Water | Urban and industrial waste water collectors and treaters |
| Digital Infrastructure | Internet exchange points, DNS service providers, TLD registries, cloud computing providers, data centre operators, content delivery networks, trust service providers, public electronic communications network/service providers |
| ICT Service Management (B2B) | Managed service providers (MSPs), managed security service providers (MSSPs) |
| Public Administration | Central and regional government bodies as designated by member states |
| Space | Ground-based infrastructure operators supporting space-based services |
Annex II — 7 Other Critical Sectors [2]
| Sector | Covered entity types |
|---|---|
| Postal and Courier Services | Universal postal service providers, couriers, parcel operators |
| Waste Management | Operators of hazardous and non-hazardous waste collection, processing, and disposal |
| Chemicals | Manufacturers and distributors of dangerous substances under REACH Regulation |
| Food | Industrial food manufacturers, large-scale processors, wholesale distributors |
| Manufacturing | Medical devices; computers and electronics (NACE C26); electrical equipment (C27); machinery and equipment (C28); motor vehicles (C29); other transport equipment (C30) |
| Digital Providers | Online marketplaces, online search engines, social networking service platforms |
| Research Organisations | Universities and dedicated research institutions |
Sector classification follows your primary regulated activity, not supporting functions. A hospital that runs an internal IT service desk falls under health (Annex I), not ICT service management. The sector classification is also not always obvious for technology companies: providers who remotely manage security or IT infrastructure for multiple clients fall under ICT Service Management (B2B) in Annex I — a category that catches many managed service providers who describe themselves as general software vendors. [2]
If your primary activity does not appear in either Annex, NIS2 does not apply. Review the Special Cases section below before concluding exclusion — certain entity types fall under the Directive regardless of sector.
Step 2 — Verify Your Size: The 50+ / €10M+ Threshold
Once sector coverage is confirmed, the scope determination turns on size. NIS2 excludes microenterprises and small enterprises from its general obligations. Size classification uses the thresholds from Commission Recommendation 2003/361/EC, applied through two concurrent tests: headcount measured in annual work units (AWU) and financial metrics. [6]
| Enterprise category | Headcount (AWU) | Financial metric | NIS2 scope |
|---|---|---|---|
| Microenterprise | <10 employees | AND turnover/balance sheet ≤€2M | Excluded (general rule) |
| Small enterprise | <50 employees | AND turnover/balance sheet ≤€10M | Excluded (general rule) |
| Medium enterprise | 50–249 employees | AND turnover ≤€50M or balance sheet ≤€43M | In scope |
| Large enterprise | ≥250 employees | OR turnover >€50M AND balance sheet >€43M | In scope |
The AND/OR distinction matters at the exclusion boundary. To qualify as a small enterprise and remain outside NIS2 scope, you must satisfy both criteria simultaneously: fewer than 50 employees AND financial metrics at or below €10 million. A company with 45 employees but €12 million in annual turnover exceeds the financial threshold. It is classified as a medium-sized enterprise and is in scope if it operates in a listed sector.
What counts in the AWU headcount. Annual work units aggregate full-time-equivalent working time. Part-time employees are counted proportionally. Some contractor and operational staffing arrangements can affect the AWU calculation depending on the degree of integration into the organisation’s management structure. [8] If you are close to the 50-employee threshold, verify your AWU count with your legal or HR function before concluding exclusion.
Before concluding you are excluded by size, work through Step 4. A subsidiary that appears small on a standalone basis may be reclassified once its parent group’s consolidated figures are applied under the group aggregation rules.
Step 3 — Classify Your Entity: Essential or Important?
Once in scope, the Directive assigns every entity to one of two categories based on sector (Annex I vs Annex II) and size. Both essential and important entities must implement the same security measures under Article 21. The classification determines the supervisory regime and the applicable penalty ceiling, not the content of the obligations. [1]
| Factor | Essential entity | Important entity |
|---|---|---|
| Sector | Annex I (high criticality) | Annex I or Annex II |
| Typical size | Large (≥250 employees or >€50M turnover) | Medium (50–249 employees, €10–50M turnover) |
| Also included regardless of size | Qualified trust service providers, DNS providers, TLD registries, medium-sized ECN/PECS providers, entities designated by member states [3] | Annex I or II entities not meeting essential criteria |
| Supervisory model | Proactive ex ante: regular audits, on-site inspections, random security checks [2] | Reactive ex post: investigations triggered by evidence of non-compliance [2] |
| Maximum fine | €10 million or 2% of global annual turnover (whichever is higher) [2] | €7 million or 1.4% of global annual turnover (whichever is higher) [2] |
The supervisory model difference is operationally significant. Essential entities should maintain audit-ready documentation continuously, because proactive inspections can occur without a triggering incident. Important entities face regulatory scrutiny primarily when evidence of non-compliance emerges — typically through incident notification or a third-party report.
Article 21 security obligations are identical for both categories. Risk analysis, incident handling, business continuity, supply chain security, access controls, authentication, and vulnerability management are all required under the same framework regardless of entity class. The classification determines enforcement intensity, not what you are required to implement.
National competent authorities may also designate additional entities as essential where they are the sole provider of a service in a member state, or where disruption would cause significant systemic risk. [3] Check your national transposition law for any sector extensions beyond the Annex I/II baseline — several member states have expanded scope beyond the Directive minimum.
Step 4 — Apply the Group Aggregation Test (Article 3(4))
If your organisation is part of a corporate group, the size threshold in Steps 2 and 3 is not assessed on your standalone figures. NIS2 Article 3(4) requires that size calculations follow Commission Recommendation 2003/361/EC, which consolidates corporate group data. [7] A subsidiary that appears small on its own may be reclassified once its parent group’s figures are applied.
The Recommendation defines two types of inter-enterprise relationship, each with its own consolidation rule:
Partner enterprises (one entity holds between 25% and 50% of the capital or voting rights of another, without majority control): The entity must add a proportionate share of the partner’s headcount and financial data to its own. If your company holds 30% of a partner entity, you add 30% of that entity’s employees to your own AWU count for NIS2 size purposes.
Linked enterprises (majority ownership, or dominant control through voting rights or the contractual right to appoint the majority of management): Data is fully consolidated at 100%. The chain extends recursively — linked enterprises of your linked enterprises also count in full. [7]
A worked example. EU Logistics GmbH is a German courier subsidiary with 28 employees and €4M in annual turnover, fully owned by its Dutch parent Noord Freight BV (310 employees, €38M turnover). On a standalone basis, EU Logistics GmbH falls below the 50-employee threshold and would appear to be excluded from NIS2 scope.
Under linked-enterprise consolidation: 28 + 310 = 338 consolidated employees. EU Logistics GmbH is reclassified as a large enterprise. As a courier operator in the postal and courier services sector (Annex II), it is now in scope as an important entity. Its parent, Noord Freight BV, is also in scope in the same sector.
This is the structural trap that catches organisations whose initial self-assessment used only standalone figures. [8] The rationale is consistent: a small entity under majority control of a large group can draw on that group’s resources for compliance purposes and cannot claim disproportionate burden on the basis of standalone size alone.
One available exemption. A member state may allow a group entity to be assessed on its standalone figures if it can demonstrate that its network and information systems are operationally independent from the rest of the group. This is a narrow affirmative exemption requiring documentary evidence — it is not assumed from the fact of separate legal personality. [7]
Step 5 — Resolve Jurisdiction: Which Member State Supervises You? (Article 26)
For organisations with operations in more than one EU member state, Article 26 [5] determines which national competent authority has primary supervisory jurisdiction and which national implementation of NIS2 governs your compliance programme.
The general rule is that an entity falls under the jurisdiction of the member state where it is established. For organisations with a single-country presence, this is straightforward.
Entities established in multiple member states fall under the jurisdiction of each member state for the activities carried out in its territory. This means registration with each relevant national competent authority and compliance with each national transposition law — including any requirements that exceed the Directive minimum.
Special single-jurisdiction rule for cross-border digital service providers. The following entity types fall under the jurisdiction of the single member state where they have their main establishment in the EU [2]: cloud computing providers, DNS service providers, TLD registries, content delivery networks, managed service providers, managed security service providers, online marketplaces, search engines, and social networking platforms.
For these entities, main establishment is determined by a three-step test applied in priority order: [5]
- Where cybersecurity risk-management decisions are predominantly made — the member state where the CISO or equivalent function is located and where the board approves the organisation’s cybersecurity strategy
- Where cybersecurity operations are physically carried out — the location of security operations centres, if step 1 is unclear or the function is distributed
- Where the entity has the highest number of EU employees — the tie-breaker of last resort
Non-EU entities providing in-scope services in the Union must designate a representative established in one of the member states where they provide services. That member state’s competent authority then exercises jurisdiction over the entity’s NIS2 obligations. [5] A US-based managed service provider with EU enterprise clients may be required to comply with NIS2 and register through an EU representative if its service constitutes managed service provision under Annex I.
Special Cases — Entities In Scope Regardless of Size
Certain entity types fall under NIS2 independently of their headcount or turnover by virtue of the critical nature of their services. [3] These organisations must comply with Article 21 obligations and register with their national competent authority even if they have fewer than 50 employees:
- Qualified trust service providers
- DNS service providers
- Top-level domain (TLD) name registries
- Domain name registration service providers
- Public electronic communications network or service providers
- Entities that are the sole provider of a service essential to a member state
- Entities whose disruption would cause significant cross-border systemic risk
- Critical entities identified under Directive (EU) 2022/2557 (CER Directive)
For these entities, Steps 2 and 4 (size and group aggregation tests) are not scope gates. In-scope status follows from the nature of the service, not the size of the organisation.
After the Scope Test — Registration and What Happens Next
Confirming NIS2 scope triggers immediate obligations on a fixed timeline.
Registration. EU member states were required to establish and maintain lists of essential and important entities from 17 April 2025, with biennial reviews thereafter. [4] Entities must self-register with their national competent authority, providing: organisation name, contact details, relevant sector and subsector classification, and the member states where they provide services. Changes to this information must be notified within two weeks.
Self-identification is not optional. National competent authorities do not contact organisations to inform them of NIS2 applicability. The obligation to assess, determine scope, and register rests entirely on the entity. Waiting for regulatory outreach is not a compliant approach — and in most member states, enforcement is already underway following the October 2024 transposition deadline. [8]
Security obligations apply from the date of national transposition, not from the date of registration. If your member state transposed NIS2 in October 2024, Article 21 risk management measures have been a legal obligation since that point. A baseline risk assessment is the standard first operational step after scope confirmation, followed by review of your NIS2 compliance checklist against the full Article 21 measure set.
Key Takeaways
Run the five tests in sequence: sector check first to filter out non-applicable organisations; size threshold second as the primary scope gate; entity classification third to understand supervisory exposure; group aggregation fourth — never skip this if you are part of a corporate group; jurisdiction last to determine which national authority you register with and which national law applies.
Any positive result at a given step confirms scope. Exclusion requires clearing all applicable gates. For a detailed breakdown of what essential vs important entity status means for management liability under Article 20 and ongoing audit obligations, see our essential vs important entities guide.
Frequently Asked Questions
My company operates in both an Annex I sector and an Annex II sector. Which classification applies?
Classification follows the higher-criticality designation. Activities in an Annex I sector result in essential or important entity status under Annex I criteria, regardless of concurrent Annex II activity. Assessment is conducted per legal entity, not per business unit. Check your national transposition law — some member states apply entity-wide scope determinations across all of a legal entity’s regulated activities.
We have 45 employees but €12 million in annual turnover. Are we in scope?
Yes, if you operate in a listed sector. The small enterprise exclusion requires satisfying both criteria: fewer than 50 employees AND financial metrics at or below €10 million. Your €12 million turnover exceeds the financial threshold, classifying your organisation as medium-sized regardless of headcount. You are in NIS2 scope as an important entity (or potentially essential, depending on your Annex I sector and the group aggregation outcome).
We are a US company providing cloud services to EU enterprise clients. Does NIS2 apply?
Potentially yes. Cloud computing providers are listed in Annex I under digital infrastructure and fall under Article 26’s single-jurisdiction rule based on their main EU establishment. If your service qualifies as cloud computing provision, you must designate an EU representative under Article 26. That member state’s competent authority exercises jurisdiction over your NIS2 obligations. The analysis depends on your specific service architecture and the contractual nature of your EU operations.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Directive (EU) 2022/2555 (NIS2 Directive), EUR-Lex: eur-lex.europa.eu
- European Commission, NIS2 Directive FAQs: digital-strategy.ec.europa.eu
- NIS2 Directive, Article 3 — Essential and Important Entities: nis-2-directive.com
- NIS2 Directive, Article 3 — Registration obligations and entity lists (see [3])
- NIS2 Directive, Article 26 — Jurisdiction: nis-2-directive.com
- NCSC Ireland, NIS2 FAQ: ncsc.gov.ie
- Arthur Cox LLP, NIS2 & SME Guidelines: arthurcox.com
- Addleshaw Goddard LLP, NIS2 — Are You Really Out of Scope?: addleshawgoddard.com
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
