NIS2 Compliance by Sector
NIS2 does not apply to every organisation the same way. See which obligations under the NIS2 Directive (EU) 2022/2555 apply to your sector — and which specialised templates you need for compliant documentation.
Which sectors fall under NIS2?
The NIS2 Directive distinguishes two categories of entities with different levels of obligation — based on both sector and company size.
Sectors of high criticality. Large entities here count as essential entities (ex-ante supervision, fines up to €10M / 2%):
- Energy (electricity, gas, oil, district heating, hydrogen)
- Transport (air, rail, water, road)
- Banking & financial market infrastructure
- Health
- Drinking water & waste water
- Digital infrastructure (data centres, cloud, DNS, IXPs)
- Public administration (central government)
- Space
Other critical sectors. Entities here count as important entities (ex-post supervision); the same Article 21 obligations apply in full:
- Postal & courier services
- Waste management
- Chemicals (manufacture, production, distribution)
- Food (production, processing, distribution)
- Manufacturing (electronics, machinery, vehicles, medical devices)
- Digital providers (online marketplaces, search engines, social platforms)
- Research organisations
Important: Whether an entity is an essential or important entity depends not only on the sector (Annex I/II) but also on company size. Essential = large entities (≥ 250 staff, or > €50M turnover and > €43M balance sheet) in Annex I sectors, plus certain size-independent entities (e.g. qualified trust service providers, DNS/TLD operators). Important = medium entities (≥ 50 staff, or > €10M turnover) — including medium-sized entities in Annex I sectors — and entities in Annex II sectors.
Sector-Specific
Sector-specific compliance packs
Our sector-specific policy packs contain every template you need for NIS2-compliant documentation in your industry.
Manufacturing Pack
22 specialised templates for machinery, electronics and production companies. OT/ICS/SCADA-specific, aligned to IEC 62443.
Energy Pack
24 specialised templates for energy suppliers, grid operators and critical infrastructure. IEC 62351- and NCCS-compliant.
All sectors at a glance
Check which sector applies to your organisation. The Complete Toolkit covers every sector.
| Sector | Annex | Available pack |
|---|---|---|
| Energy | Annex I | Energy Pack → |
| Manufacturing & production | Annex II | Manufacturing Pack → |
| Transport | Annex I | Complete Toolkit → |
| Health | Annex I | Complete Toolkit → |
| Chemicals & food | Annex II | Complete Toolkit → |
| Digital services & infrastructure | Annex I/II | Complete Toolkit → |
Cross-sector NIS2 requirements
Regardless of sector, every entity in scope must demonstrably implement and document these Article 21 measures:
Risk analysis and security measures across all network and information systems.
Report significant incidents to your national CSIRT within 24 / 72 hours.
Document and enforce security requirements for suppliers and service providers.
Management must approve the measures and is personally liable for compliance.
Frequently asked questions about NIS2 sectors
Start with the right sector pack
Choose the pack for your industry — or get the Complete Toolkit for full NIS2 coverage.
