Every explainer of Directive (EU) 2022/2555 says that NIS2 divides its entities into essential and important, and most stop there. The division is worth getting right because it is the division between Article 32 and Article 33, between a supervisor that may audit you before anything has gone wrong and one that acts on evidence, and between a fine ceiling of EUR 10 000 000 and one of EUR 7 000 000. It is decided by two articles read in order: Article 2 says whether you are in at all, Article 3 says which kind you are. Both quote a size test from a 2003 Recommendation that is counted in a way most companies get wrong the first time. This article takes the two in order, with the text, and ends where the free scope determination starts.
Article 2: are you an entity of the Directive
Article 2(1) applies the Directive to "public or private entities of a type referred to in Annex I or II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, and which provide their services or carry out their activities within the Union". Three conditions, and the first is the one to check first: being of a type the annexes list. Annex I is the sectors of high criticality, 11 of them, and Annex II the other critical sectors, 7 more; between them they describe 67 types of entity, and a company is in scope by being one of them, not by selling to one. A software company is usually looking at four rows: cloud computing service providers, managed service providers and managed security service providers in Annex I, and providers of online marketplaces, online search engines and social networking platforms in Annex II. The 67 rows are on the scope tool in six languages, verbatim.
The second condition is size. The Recommendation's Annex defines a medium-sized enterprise as one with fewer than 250 staff and either an annual turnover not exceeding EUR 50 million or a balance sheet total not exceeding EUR 43 million; a small enterprise has fewer than 50 staff and a turnover or balance sheet not exceeding EUR 10 million; a microenterprise fewer than 10 staff and EUR 2 million. NIS2 takes medium-sized enterprises and everything larger, so the floor is the small ceiling: 50 staff, or above EUR 10 million in both turnover and balance sheet. Two things about the counting. The Recommendation's Article 3 counts the enterprise together with its partner enterprises and its linked enterprises, so a 30-person subsidiary of a 400-person group is not small. And NIS2 disapplies Article 3(4) of that Annex, the rule that keeps an enterprise held 25 % or more by public bodies out of the SME classes, so a publicly held company is sized like any other.
Article 2(2) then brings some entities in "regardless of their size": providers of public electronic communications networks or services, trust service providers, TLD name registries and DNS service providers, by what they provide; the sole provider in a member state of a service essential for critical societal or economic activities, an entity whose disruption would significantly affect public safety, security or health or induce systemic risk, and an entity critical for its sector at national or regional level, each by an act of the member state; and central government, with regional government after a risk-based assessment. Article 2(3) adds entities identified as critical under Directive (EU) 2022/2557, and Article 2(4) entities providing domain name registration services. A registrar is a category of its own: Article 3(3) lists registrars beside essential and important entities, and their duty is Article 28.
Article 3: essential, or important
Article 3(1) lists the essential entities in seven points, and Article 3(2) makes every other entity of an Annex I or II type important. The seven, quoted:
| Point | The text | Who this is, in practice |
|---|---|---|
| (a) | "entities of a type referred to in Annex I which exceed the ceilings for medium-sized enterprises provided for in Article 2(1) of the Annex to Recommendation 2003/361/EC" | Every large Annex I entity: a cloud or managed service provider with 250 staff or more, or above EUR 50 million turnover and EUR 43 million balance sheet |
| (b) | "qualified trust service providers and top-level domain name registries as well as DNS service providers, regardless of their size" | Three kinds that are essential at any size; a non-qualified trust service provider is important unless large |
| (c) | "providers of public electronic communications networks or of publicly available electronic communications services which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC" | Medium-sized telecoms providers; large ones are essential under (a), small ones important |
| (d) | "public administration entities referred to in Article 2(2), point (f)(i)" | Central government |
| (e) | "any other entities of a type referred to in Annex I or II that are identified by a Member State as essential entities pursuant to Article 2(2), points (b) to (e)" | An entity the state has identified and chosen to make essential rather than important |
| (f) | "entities identified as critical entities under Directive (EU) 2022/2557, referred to in Article 2(3) of this Directive" | Critical entities under the resilience Directive, whatever their sector row |
| (g) | "if the Member State so provides, entities which that Member State identified before 16 January 2023 as operators of essential services in accordance with Directive (EU) 2016/1148 or national law" | Former operators of essential services under the first NIS Directive, where the state keeps them essential |
Read against a software company, the table says three things. An Annex II type is never essential by size: a large manufacturer of machinery, medical devices or electronics, a large marketplace or search engine, is important under Article 3(2) however large it is, unless a state identifies it under (e) or it is a critical entity under (f). An Annex I type is essential by size alone, which puts a cloud, data centre, CDN, managed service or managed security service provider that crosses the medium ceilings into Article 32 supervision with no act of anyone. And the three kinds in point (b) are essential at any size, which is why a two-person DNS provider is an essential entity and a two-person cloud provider is not an entity at all unless a state identifies it.
What the difference is
The measures are the same. Article 21 applies to essential and important entities alike, and for the digital providers of its Article 1 the Implementing Regulation (EU) 2024/2690 fixes the technical detail of those measures and the incident thresholds identically for both. The Article 23 clocks are the same. What differs is supervision, fines and the reading of proportionality.
Supervision of essential entities is ex ante and ex post (Article 32): the competent authority may carry out on-site inspections and off-site supervision, regular and targeted audits, ad hoc audits where a significant incident or infringement justifies them, security scans, and requests for information and evidence, at any time; where its orders are not complied with it may, as a last resort, suspend a certification or authorisation and ask a court to prohibit the management from exercising managerial functions (Article 32(5)). Supervision of important entities is ex post (Article 33): the same instruments, but "where provided with evidence, indication or information that an important entity allegedly does not comply". Fines follow Article 34: for essential entities "a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover" (Article 34(4)), for important entities "a maximum of at least EUR 7 000 000 or of a maximum of at least 1,4 %" (Article 34(5)), whichever is higher in each case, the member state free to set its ceilings above. Both kinds have a management body that must approve the measures, oversee their implementation and can be held liable, and whose members must follow training (Article 20).
The list, the registry and the state
Two registrations follow from the status, and they are different. Article 3(3) required each member state to establish, by 17 April 2025, a list of its essential and important entities and of registrars, from information the entities submit under Article 3(4): name, address and contact details, sector and subsector, and the member states where they provide services. Article 27 is a second, narrower registry, kept by ENISA, for DNS, TLD, registrar, cloud, data centre, CDN, managed service, managed security service, marketplace, search engine and social networking providers, which had to submit their name, sector, addresses, contact details, member states served and IP ranges to their competent authority by 17 January 2025.
Which state's list you are on is Article 26. An entity falls under the jurisdiction of the member state where it is established, except that the digital providers just listed fall under the member state of their main establishment in the Union, "the Member State where the decisions related to the cybersecurity risk-management measures are predominantly taken" (Article 26(2)), and one not established in the Union under the state where it designates its representative (Article 26(3)). The state's act, as communicated to the Commission, is on the transposition register; which of them has one at all, on the day of reading, is its own article.
Four cases a software company gets wrong
A cloud provider with 40 staff and EUR 8 million turnover, independent, is not an entity of the Directive: an Annex I type, below the small ceiling, and none of the size-blind rules applies. It will still be asked, by every essential and important customer, to show the security of the supply chain that Article 21(2)(d) makes those customers manage. The same provider owned by a 300-person group is medium-sized by Article 3 of the Recommendation and important; the same provider with 250 staff is essential.
A machinery manufacturer with 2 000 staff is important, not essential: Annex II, and Article 3(1)(a) reaches Annex I only.
A registrar with no other row is in scope under Article 2(4) at any size, with Article 28 as its duty and a place on the Article 3(3) list and in the Article 27 registry, but it is neither essential nor important unless it is also of an Annex type.
A managed service provider established in the United States with customers in three member states and no establishment in the Union must designate a representative in one of the states where it offers services, and is under that state's law; without one, any of the three may act against it.
The scope determination runs these rules on your answers and writes the result with the articles cited; the NIS2 to ISO 27001 mapping is where the measures of Article 21 go next, and the Article 23 clocks are what the status carries into an incident. Whether NIS2 or the CRA is your law at all comes before both.
Sources
- Directive (EU) 2022/2555 (NIS2), Article 2(1) to (4), Article 3(1) to (4), Article 20, Article 21(1) and (2), Article 26(1) to (3), Article 27, Article 28, Articles 32 to 34, Annexes I and II, read on EUR-Lex in six languages.
- Commission Recommendation 2003/361/EC, Annex, Articles 2 and 3.
- Commission Implementing Regulation (EU) 2024/2690, Article 1.
This is not legal advice. The member state's act may add to the Directive's categories under Article 2(2)(b) to (e), Article 2(5) and Article 3(1)(g), and the determination of the state is the one that counts.