NIS2 by Sector

NIS2 Compliance by Sector

NIS2 does not apply to every organisation the same way. See which obligations under the NIS2 Directive (EU) 2022/2555 apply to your sector — and which specialised templates you need for compliant documentation.

Which sectors fall under NIS2?

The NIS2 Directive distinguishes two categories of entities with different levels of obligation — based on both sector and company size.

Annex I sectors — highest criticality

Sectors of high criticality. Large entities here count as essential entities (ex-ante supervision, fines up to €10M / 2%):

  • Energy (electricity, gas, oil, district heating, hydrogen)
  • Transport (air, rail, water, road)
  • Banking & financial market infrastructure
  • Health
  • Drinking water & waste water
  • Digital infrastructure (data centres, cloud, DNS, IXPs)
  • Public administration (central government)
  • Space
Annex II sectors — other critical sectors

Other critical sectors. Entities here count as important entities (ex-post supervision); the same Article 21 obligations apply in full:

  • Postal & courier services
  • Waste management
  • Chemicals (manufacture, production, distribution)
  • Food (production, processing, distribution)
  • Manufacturing (electronics, machinery, vehicles, medical devices)
  • Digital providers (online marketplaces, search engines, social platforms)
  • Research organisations

Important: Whether an entity is an essential or important entity depends not only on the sector (Annex I/II) but also on company size. Essential = large entities (≥ 250 staff, or > €50M turnover and > €43M balance sheet) in Annex I sectors, plus certain size-independent entities (e.g. qualified trust service providers, DNS/TLD operators). Important = medium entities (≥ 50 staff, or > €10M turnover) — including medium-sized entities in Annex I sectors — and entities in Annex II sectors.

Sector-Specific

Sector-specific compliance packs

Our sector-specific policy packs contain every template you need for NIS2-compliant documentation in your industry.

Annex II

Manufacturing Pack

€349

22 specialised templates for machinery, electronics and production companies. OT/ICS/SCADA-specific, aligned to IEC 62443.

Annex I — highest priority

Energy Pack

€349

24 specialised templates for energy suppliers, grid operators and critical infrastructure. IEC 62351- and NCCS-compliant.

All sectors at a glance

Check which sector applies to your organisation. The Complete Toolkit covers every sector.

Sector Annex Available pack
Energy Annex I Energy Pack →
Manufacturing & production Annex II Manufacturing Pack →
Transport Annex I Complete Toolkit →
Health Annex I Complete Toolkit →
Chemicals & food Annex II Complete Toolkit →
Digital services & infrastructure Annex I/II Complete Toolkit →

Cross-sector NIS2 requirements

Regardless of sector, every entity in scope must demonstrably implement and document these Article 21 measures:

Risk management

Risk analysis and security measures across all network and information systems.

Incident reporting

Report significant incidents to your national CSIRT within 24 / 72 hours.

Supply chain

Document and enforce security requirements for suppliers and service providers.

Management liability

Management must approve the measures and is personally liable for compliance.

Frequently asked questions about NIS2 sectors

How do I find out if my organisation is in scope?

Use our free Readiness Check, or check your NACE code and company size against the thresholds (50 staff / €10M turnover). If your sector appears in Annex I or II and you meet the size threshold, you are very likely in scope.

What is the difference between essential and important entities?

The classification depends on sector and company size. Essential entities are large entities (≥ 250 staff, or > €50M turnover and > €43M balance sheet) in Annex I sectors, plus certain size-independent entities (e.g. qualified trust service providers, DNS/TLD operators); they face ex-ante supervision and fines up to €10M or 2% of global annual turnover. Important entities are medium entities (≥ 50 staff, or > €10M turnover) — including medium-sized Annex I entities — and entities in Annex II sectors; they face ex-post supervision and fines up to €7M or 1.4%, but must implement the same measures.

Are there sector-specific requirements?

Yes. While the Article 21 measures apply across all sectors, additional sector standards apply depending on industry: IEC 62443 for manufacturing, IEC 62351 for energy, and the Network Code on Cybersecurity for grid operators. Our sector packs incorporate these standards.

Start with the right sector pack

Choose the pack for your industry — or get the Complete Toolkit for full NIS2 coverage.