The CRA's 24-hour reporting duty has applied since 11 September 2026. Check whether it reaches you

Size ceilings read from the Official Journal on 4 October 2026

NIS2 for small companies: are you in scope?

Usually not by size. A few services are in at any size, and customers who are in scope will ask about your security either way.

Short answer
Usually not

NIS2 starts at medium size. A company with fewer than 50 staff is small unless its turnover and its balance sheet total both exceed €10M, and a small company is outside unless a rule below brings it in at any size.

Who it is for
A company of fewer than 50 people, counted with its partner and linked enterprises, whose service is a type NIS2's annexes list.
What to do
Check the list below, write the determination down with its date, and keep your security records ready for your customers' supplier questions.

The size line

SizeDefinition
Micro OutsideFewer than 10 staff, and turnover or balance sheet at most €2M
Small OutsideFewer than 50 staff, and turnover or balance sheet at most €10M
Medium In, if the type is listedFewer than 250 staff, and turnover at most €50M or balance sheet at most €43M
Large In, if the type is listed250 staff or more, or turnover above €50M and balance sheet above €43M

Article 2 of the Annex to Recommendation 2003/361/EC, read 4 October 2026. NIS2 Article 2(1) takes medium-sized enterprises and larger.

In scope at any size

If one of these is true, size does not matter:

  • We provide a public electronic communications network or a publicly available electronic communications service (Article 2(2)(a)(i))
  • We are a trust service provider under Regulation (EU) No 910/2014 (Article 2(2)(a)(ii))
  • We are a top-level domain name registry or a DNS service provider (Article 2(2)(a)(iii))
  • We provide domain name registration services (Article 2(4))
  • Our member state has identified us as the sole provider of a service essential for critical societal or economic activities (Article 2(2)(b))
  • Our member state has identified us under Article 2(2)(c) to (e): a disruption of our service would significantly affect public safety, security or health, or induce systemic risk, or we are critical for our sector at national or regional level
  • We are identified as a critical entity under Directive (EU) 2022/2557 (Article 2(3))

Run the scope check

What reaches you anyway

Customers that are essential or important entities must secure their supply chain. Article 21(2)(d) asks them for:

“supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”

Article 21(3) adds that they weigh each direct supplier's vulnerabilities and security practices. That is where the supplier questionnaire and the contract clauses come from.

StandardOS keeps the policies, the risk register and the evidence those questions are answered from.

This is StandardOS's reading of the Directive, with the article cited. Your member state's law decides how it applies to you.

Questions

Does our group count?
Yes. The Recommendation counts the enterprise together with its partner and linked enterprises, so a small subsidiary of a large group is not small.
We crossed the line this year. Are we in now?
Not from one year. Under Article 4(2) of the same Annex, the status changes only when a ceiling is exceeded, or fallen below, over two consecutive accounting periods.
Can our member state bring us in?
Yes. A member state can identify a smaller entity under Article 2(2)(b) to (e), for example as the sole provider of an essential service, and it would tell you.

Keep the records your customers ask for

No card to start · cancel in-app anytime

This page in:DeutschFrançaisNederlandsEspañolDansk