---
title: "NIS2 FAQ: scope, Article 21 controls, incident reporting, and penalties"
canonical_url: "https://www.sorena.io/artifacts/eu/nis2-directive/faq"
source_url: "https://www.sorena.io/artifacts/eu/nis2-directive/faq/items/page/2"
author: "Sorena AI"
description: "NIS2 FAQ on entity scope, essential and important classification, Article 21 measures, Article 23 reporting, national implementation, and evidence."
published_at: "2026-05-09"
updated_at: "2026-07-25"
keywords:
  - "NIS2 FAQ"
  - "EU NIS2 Directive"
  - "essential entities"
  - "important entities"
  - "Article 21 cybersecurity measures"
  - "Article 23 incident reporting"
  - "NIS2 penalties"
  - "Article 21"
  - "Article 23"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# NIS2 FAQ: scope, Article 21 controls, incident reporting, and penalties

NIS2 FAQ on entity scope, essential and important classification, Article 21 measures, Article 23 reporting, national implementation, and evidence.

*Artifact Guide* *EU*

## NIS2 FAQ Scope, controls, reporting, and evidence

Answers to recurring NIS2 questions about entity scope, essential versus important classification, Article 21 cybersecurity risk-management measures, Article 23 incident reporting, management-body accountability, registration, and penalties.

Use the cited EU and ENISA sources to turn each answer into an auditable decision record before assigning control owners or reporting workflows.

Use this FAQ to decide whether an entity is covered, which tier applies, what Articles 20, 21, and 23 require, and what evidence to keep. Directive (EU) 2022/2555 sets the EU baseline. National implementing law and authority guidance determine the local registration, notification, supervision, enforcement, and procedural details, so record the relevant legal entity, country, sector, service, size facts, special-case rule, and authority route.

## Definitions

### NIS2 Article 21 cybersecurity risk-management measures

**Term:** Article 21

Article 21 requires essential and important entities to take appropriate and proportionate technical, operational, and organisational measures to manage risks to their network and information systems and to prevent or minimise incident impacts. It sets an all-hazards baseline covering ten areas, including incident handling, continuity, supply-chain security, secure development, effectiveness testing, training, cryptography, access control, asset management, and authentication or secure communications where appropriate.

**Why it matters here:** Article 21 is the controlling NIS2 provision for the control baseline discussed on this page. Implementation must reflect the entity's risk exposure, size, incident likelihood and severity, societal and economic impact, applicable national law, and any binding implementing rules.

Sources:

- [Directive (EU) 2022/2555 (NIS2), Article 21](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io)

### NIS2 Article 23 reporting obligations

**Term:** Article 23

Article 23 requires essential and important entities to notify their CSIRT or, where applicable, competent authority of significant incidents without undue delay. It defines the significance test and the staged reporting sequence: a 24-hour early warning, an incident notification generally due within 72 hours, requested intermediate reports, and a final report or ongoing-incident progress route. A trust service provider has 24 hours for the incident notification when the significant incident affects its trust services.

**Why it matters here:** Article 23 controls the incident thresholds, deadlines, report content, recipient communications, cross-border information, and follow-up discussed in this FAQ. National implementing law determines the local authority, channel, form, and procedure.

Sources:

- [Directive (EU) 2022/2555 (NIS2), Article 23](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io)

### Computer security incident response team

**Term:** CSIRT

A CSIRT is a Member State-designated computer security incident response team responsible for specified sectors, subsectors, or entity types. NIS2 requires CSIRTs to meet operational requirements and assigns tasks such as monitoring and analysing incidents, giving alerts and assistance, responding to incidents, and supporting coordinated vulnerability disclosure.

**Why it matters here:** Article 23 notifications go to the CSIRT or, where applicable, the competent authority. The correct national route depends on the entity, sector, jurisdiction, and Member State implementation.

Sources:

- [Directive (EU) 2022/2555 (NIS2), Articles 10, 11, and 23](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io)

## Browse sub-FAQ modules

### [Are managed service providers in scope of NIS2?](/artifacts/eu/nis2-directive/faq/managed-service-provider-scope.md)

NIS2 scope answer for managed service providers and managed security service providers, including service definition, size-cap checks, entity status, and jurisdiction evidence.

- 3 items

### [NIS2 24-hour early warning: what to send and when](/artifacts/eu/nis2-directive/faq/24-hour-early-warning.md)

Under NIS2 Article 23, covered essential and important entities submit an early warning within 24 hours of becoming aware of a significant incident.

- 3 items

### [NIS2 72-hour incident notification FAQ](/artifacts/eu/nis2-directive/faq/72-hour-incident-notification.md)

NIS2 incident-notification deadline, required initial assessment, evidence, follow-up, and the 24-hour trust-service-provider exception.

- 3 items

### [NIS2 entity classification FAQ](/artifacts/eu/nis2-directive/faq/essential-vs-important-entities.md)

Plain-English FAQ comparing NIS2 essential entities and important entities, with Article 3 classification rules, shared Article 21 and 23 duties, supervision differences, and evidence to keep.

- 3 items

### [NIS2 Member State Transposition: What Teams Must Check](/artifacts/eu/nis2-directive/faq/member-state-transposition.md)

How to handle NIS2 Member State transposition: use Article 41 as the EU baseline, then verify national law, authority routing, registration, and incident-reporting details.

- 3 items

### [NIS2 size-cap rule: when medium and large entities are in scope](/artifacts/eu/nis2-directive/faq/size-cap-rule.md)

Plain-language FAQ on the NIS2 size-cap rule: medium and large Annex I or II entities, SME thresholds, regardless-of-size exceptions, and evidence to keep.

- 4 items

Browse all indexed questions: [/artifacts/eu/nis2-directive/faq/items](/artifacts/eu/nis2-directive/faq/items.md)

## All FAQ items

*Page 2 of 2. Showing 4 of 19 items.*

### [What is the NIS2 size-cap rule?](/artifacts/eu/nis2-directive/faq/size-cap-rule.md#what-is-the-nis2-size-cap-rule)

*Module: [NIS2 size-cap rule: when medium and large entities are in scope](/artifacts/eu/nis2-directive/faq/size-cap-rule.md)*

Article 2(1) of NIS2 applies the directive to public or private entities of a type listed in Annex I or Annex II when they qualify as medium-sized enterprises under Recommendation 2003/361/EC, or exceed the medium-sized-enterprise ceilings, and provide services or carry out activities in the Union.

- Start with the sector: confirm the entity is in Annex I or Annex II before you apply any size test.
- Check annual work units and the financial alternative together: fewer than 250 staff and either turnover no higher than EUR 50 million or balance-sheet total no higher than EUR 43 million.
- Aggregate partner-enterprise data in proportion to the ownership or voting interest and add 100 percent of linked-enterprise data where the Recommendation requires it.
- Confirm that the entity provides services or carries out activities in the Union.
- Escalate small or micro entities when a regardless-of-size rule, critical-entity designation, domain-name-registration-service rule, or Member State rule may apply.

Sources for this answer:

- [Directive (EU) 2022/2555 (NIS2)](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Article 2(1) sets the default NIS2 scope test for Annex I and Annex II entities that are medium-sized or exceed the medium-sized-enterprise ceilings.
- [Commission Recommendation 2003/361/EC on SME definitions](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32003H0361&ref=sorena.io) - Defines the employee, turnover, and balance-sheet ceilings that NIS2 references for the size-cap test.
- [European Commission - NIS2 Directive overview](https://digital-strategy.ec.europa.eu/en/policies/nis2-directive?ref=sorena.io) - Commission overview summarizing NIS2 as applying risk-management and incident-notification duties to medium-sized and large entities in covered sectors.

### [Which employee, turnover, and balance-sheet thresholds should teams check?](/artifacts/eu/nis2-directive/faq/size-cap-rule.md#which-employee-turnover-and-balance-sheet-thresholds-should-teams-check)

*Module: [NIS2 size-cap rule: when medium and large entities are in scope](/artifacts/eu/nis2-directive/faq/size-cap-rule.md)*

Recommendation 2003/361/EC defines the SME category as enterprises with fewer than 250 persons and annual turnover not exceeding EUR 50 million and/or an annual balance-sheet total not exceeding EUR 43 million. Within that category, a small enterprise has fewer than 50 persons and turnover and/or balance-sheet total no higher than EUR 10 million, and a microenterprise has fewer than 10 persons and turnover and/or balance-sheet total no higher than EUR 2 million. The default NIS2 gate is medium-sized or larger, so do not treat every enterprise inside the overall SME ceiling as covered.

- Calculate annual work units and keep the latest approved annual turnover and balance-sheet total.
- Classify the enterprise as autonomous, partner, or linked and retain the ownership, voting-rights, and consolidation evidence used for aggregation.
- Record whether the two-consecutive-accounting-period rule affects a recent crossing of a ceiling.
- Do not exclude an entity from the NIS2 medium-size test solely because public bodies control 25 percent or more; NIS2 expressly disapplies that Recommendation rule.
- Map the entity to the relevant Annex I or Annex II sector and the covered service it actually provides.
- Explain why the entity is medium-sized, exceeds the medium-sized-enterprise ceilings, or is escalated as a small or micro special case.
- Keep the reviewer, approval date, source citation, and reassessment trigger with the decision record.

Sources for this answer:

- [Commission Recommendation 2003/361/EC on SME definitions](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32003H0361&ref=sorena.io) - Primary source for annual work units, employee and financial ceilings, reference periods, autonomous, partner and linked-enterprise aggregation, and the two-consecutive-accounting-period status rule.
- [Directive (EU) 2022/2555 (NIS2)](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - NIS2 Article 2 references the Recommendation's medium-enterprise test and expressly excludes only Article 3(4) of its Annex, the public-body-control rule.

### [Which NIS2 entities can be covered regardless of size?](/artifacts/eu/nis2-directive/faq/size-cap-rule.md#which-nis2-entities-can-be-covered-regardless-of-size)

*Module: [NIS2 size-cap rule: when medium and large entities are in scope](/artifacts/eu/nis2-directive/faq/size-cap-rule.md)*

The size cap is not the end of the NIS2 scope analysis. Article 2(2) applies NIS2 regardless of size to certain Annex I or Annex II entities, including providers of public electronic communications networks or publicly available electronic communications services, trust service providers, top-level domain name registries, DNS service providers, sole providers of essential services in a Member State, entities whose disruption could significantly affect public safety, public security, or public health, entities whose disruption could induce significant systemic risk, nationally or regionally critical entities, and certain public administration entities.

- Check electronic communications, trust-service, TLD registry, DNS, and domain-name-registration-service roles first.
- Check whether the entity is a sole essential provider, creates a public-safety or public-health impact, creates systemic risk, or has national or regional criticality.
- Check whether the entity is identified as a critical entity under Directive (EU) 2022/2557.
- Check local public administration, education, and Member State implementation rules before treating a small or micro entity as out of scope.

Sources for this answer:

- [Directive (EU) 2022/2555 (NIS2)](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Article 2(2), Article 2(3), and Article 2(4) list regardless-of-size scope rules and Article 2(5) permits some Member State extensions.
- [European Commission - NIS2 Directive overview](https://digital-strategy.ec.europa.eu/en/policies/nis2-directive?ref=sorena.io) - Commission policy page for NIS2 sector scope, obligations, and Member State transposition context.

### [What evidence should prove a NIS2 size-cap decision?](/artifacts/eu/nis2-directive/faq/size-cap-rule.md#what-evidence-should-prove-a-nis2-size-cap-decision)

*Module: [NIS2 size-cap rule: when medium and large entities are in scope](/artifacts/eu/nis2-directive/faq/size-cap-rule.md)*

A size-cap record should let legal, finance, security, and compliance reviewers reproduce the conclusion. Keep the source rule, annual-work-unit calculation, accounts, ownership and aggregation analysis, sector mapping, financial alternative used, exception checks, and national-law route together.

- Keep the Article 2 rule and the exact sector or exception that made the entity in scope.
- Attach the Recommendation 2003/361/EC evidence for annual work units, turnover, balance-sheet total, and the accounting period used.
- Include autonomous, partner, linked-enterprise, ownership, and consolidation evidence so reviewers can reproduce every aggregation.
- Record the Article 3(4) public-body-control disapplication and any Article 4(2) two-period status analysis that affects the result.
- Record the Annex I or Annex II mapping, covered service description, operating country, and any Member State routing note.
- Name the decision owner, reviewer, approval date, and the trigger that will force a reassessment.

Sources for this answer:

- [Directive (EU) 2022/2555 (NIS2)](https://eur-lex.europa.eu/eli/dir/2022/2555/oj?ref=sorena.io) - Binding source for NIS2 scope, essential and important entity classification, and regardless-of-size rules.
- [Commission Recommendation 2003/361/EC on SME definitions](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32003H0361&ref=sorena.io) - Primary source for the employee, turnover, and balance-sheet thresholds used in the size-cap evidence file.

## FAQ Pagination

- Canonical index (page 1): [/artifacts/eu/nis2-directive/faq/items](/artifacts/eu/nis2-directive/faq/items.md)
- Page 1 rule: `/page/1` is intentionally not generated; use the canonical index markdown URL.
- Current page: 2 of 2

Pages: [1](/artifacts/eu/nis2-directive/faq/items.md) | [2](/artifacts/eu/nis2-directive/faq/items/page/2.md)

[Previous page](/artifacts/eu/nis2-directive/faq/items.md)

*Recommended next step*

*Placement: before sources*

## Record NIS2 scope, controls, reporting, and evidence

Sorena can help turn NIS2 FAQ answers into cited decisions, owner assignments, Article 21 control evidence, Article 23 incident workflow checks, and reusable review triggers.

- [Open Research Copilot for NIS2](/solutions/research-copilot.md): Ask questions tied to cited sources about NIS2 scope, obligations, reporting, penalties, and evidence using the cited sources on this page.
- [Talk through NIS2 implementation](/contact.md): Review your NIS2 scope decisions, Article 21 control evidence, Article 23 reporting workflow, and unresolved national implementation questions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/nis2-directive/faq/items/page/2.md
