What is the first practical step in a NIS2 applicability test?
Identify the legal entity and map each service or activity to Annex I or Annex II. Only then apply the , size-independent triggers, and Article 3 essential or important classification.
Decide whether an entity, service, or planned EU operation falls within NIS2 before assigning cybersecurity and reporting work.
Use the test to map Annex I or Annex II sector coverage, size and size-independent triggers, essential or important classification, Member State jurisdiction, and the evidence needed for review.
Structured answer sets in this page tree.
Cited legal and guidance references.
Test one legal entity and service at a time. Confirm that the activity matches an Annex I or Annex II entity type in the Union, calculate whether the entity is medium-sized or larger, check every size-independent path, and then classify it as essential or important. Also identify the Member State with jurisdiction and whether an equivalent sector-specific EU law displaces only the overlapping NIS2 provisions. Keep the result as a cited scope record for registration, controls, reporting, and management oversight.
Start with the legal entity and the service or activity being tested. NIS2 applies to public or private entities of a type listed in Annex I or Annex II that provide services or carry out activities within the Union and meet the applicable size or special-case criteria.
Do not classify only by brand, group name, or product category. The record should identify the contracting or operating entity, the Member States where the service is provided, the sector and subsector, and the network and information systems that support the service.
The sector map is the core of the applicability test. Annex I covers sectors of high criticality such as energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, and space. Annex II covers other critical sectors such as postal and courier services, waste management, chemicals, food, manufacturing categories, digital providers, and research organisations.
Use the defined entity types inside each annex, not only the sector heading. For example, the digital-infrastructure section distinguishes DNS service providers, TLD registries, cloud computing service providers, data centre service providers, content delivery network providers, trust service providers, and public electronic communications providers.
For most Annex I and Annex II entity types, Article 2 starts with the : the Directive applies where the entity qualifies as a medium-sized enterprise under the Annex to Commission Recommendation 2003/361/EC, or exceeds the ceilings for medium-sized enterprises, and provides the relevant services or activities in the Union.
A medium-sized enterprise has fewer than 250 staff and annual turnover not above EUR 50 million and/or an annual balance-sheet total not above EUR 43 million. Calculate staff as annual work units. Add partner-enterprise data in proportion to the ownership or voting interest and add 100% of linked-enterprise data unless already consolidated. Crossing or falling below a ceiling normally changes SME status only after two consecutive accounting periods. NIS2 disapplies the Recommendation's Article 3(4) public-body ownership rule, so public ownership at or above 25% does not by itself prevent use of the SME calculation for this test.
The size calculation is not the end of the test. Article 2 applies regardless of size to listed cases, including providers of public electronic communications networks or publicly available electronic communications services, trust service providers, TLD registries and DNS service providers, sole providers of an essential service in a Member State, entities whose service disruption could have specified public-safety, systemic, or national or regional importance effects, certain public administration entities, critical entities under Directive (EU) 2022/2557, and entities providing domain name registration services.
After scope is established, Article 3 determines whether the entity is essential or important. Essential entities include large Annex I entities, qualified trust service providers, TLD registries, DNS service providers, medium-sized providers of public electronic communications networks or publicly available electronic communications services, central government public administration entities, Member State-identified essential entities under specific Article 2 triggers, critical entities under the CER Directive, and, where a Member State so provides, entities previously identified as operators of essential services.
Important entities are the in-scope Annex I or Annex II entities that do not qualify as essential. Member States may also bring local public administration and education institutions into scope. Article 2 excludes specified public-administration activity in national security, public security, defence, and law enforcement, and permits narrower exemptions for certain entities or services connected to those activities. If facts or national-law choices are missing, classify the test as blocked rather than forcing an essential or important label.
The applicability record should identify the authority path before implementation. As a rule, an entity falls under the jurisdiction of the Member State where it is established. Article 26 instead uses the service Member State for public electronic communications providers, the establishing Member State for public administration, and the Union main establishment for the listed cross-border digital and ICT providers. A listed provider with no Union establishment must designate a representative in a Member State where it offers services.
Article 3 required Member States to establish lists of essential and important entities and domain name registration service providers by 17 April 2025 and to review them at least every two years. Article 27 separately required specified digital and ICT providers to submit registry information by 17 January 2025. Article 3 changes are due without delay and within two weeks; Article 27 changes are due without delay and within three months. National mechanisms and instructions determine the actual submission route.
Finally, apply Article 4 provision by provision. If a sector-specific Union act imposes risk-management measures or significant-incident notification requirements that are at least equivalent in effect, the corresponding NIS2 provisions and their supervision and enforcement provisions do not apply to the covered entity. NIS2 continues to apply to entities or duties the sector-specific act does not cover.
Identify the legal entity and map each service or activity to Annex I or Annex II. Only then apply the , size-independent triggers, and Article 3 essential or important classification.
Yes. Article 2 applies regardless of size to several categories, including certain public electronic communications providers, trust service providers, TLD registries, DNS service providers, critical entities under Directive (EU) 2022/2557, entities providing domain name registration services, and other listed special cases.
Keep the legal entity, service, Member States, exact Annex row, annual work units, turnover and balance-sheet data, partner and linked-enterprise calculation, size-independent trigger analysis, essential or important classification, Article 26 jurisdiction path, any Article 4 sector-specific-law analysis, registration facts, source URLs, reviewer, approver, and reassessment triggers.
Sorena can help convert the NIS2 applicability facts on this page into cited intake questions, owner assignments, authority-registration evidence, and reassessment workflow.
Ask questions tied to cited sources about NIS2 scope, Annex I and II sectors, size-cap rules, essential or important classification, jurisdiction, and evidence.
Review a NIS2 applicability test, registration evidence gap, or next-step workflow with Sorena.
"medium-sized enterprises"
"establish a list of essential and important entities"
"Technical Implementation Guidance"
"under the jurisdiction of the Member State"
"wider scope, clearer rules and stronger supervision tools"
"technical and methodological requirements"