NIS2: all pages and articles

Directive (EU) 2022/2555 · Article 2, Article 3, Article 26

Is your company under NIS2, and is it essential or important?

Five questions, each with the article it comes from, and the annexes as the Directive lists them in your language. The result is a written determination you can file: whether you are an entity of the Directive, which kind, which member state's law and which act, what applies to you directly, and where to start. Nothing you type leaves this page.

Which type of entity in Annex I or II are you?

The Directive lists types of entity by sector; a company is in scope by being one of them, not by being a supplier to one. Pick the row that describes what you provide. A software company that runs its product as a service is usually a cloud computing service provider; one that operates customers' systems is a managed service provider.

How large is the company?

Sizes as the Annex to Recommendation 2003/361/EC defines them, counted for the enterprise with its partner and linked enterprises. The Directive's Article 2(1) takes medium-sized enterprises and larger.

Does one of the size-blind rules apply?

Article 2(2) to (4) bring some entities in whatever their size. The first four are decided by what you provide; the next two need an act of your member state, which will have told you; the last is a status under the critical entities Directive.

Where is the company established?

Article 26 gives every entity one member state. For cloud, data centre, content delivery, managed service, managed security, marketplace, search engine and social networking providers it is the main establishment in the Union, the place where the cybersecurity decisions are predominantly taken; a provider not established in the Union designates a representative in a state where it offers services (Article 26(3)).

The determination

Answer the first three questions and the determination is written here.

Essential or important: the rules, read in orderThe transposition register, state by stateNIS2 mapped to ISO 27001The Article 23 clocks beside the CRA's