All posts

NIS2: How to Tell If You Are In Scope

The directive applies by sector and company size, and it reaches suppliers who never read it. A practical way to work out whether it applies to you.

Published 4 min readBy the Auditly teamDiesen Beitrag auf Deutsch lesenLire cet article en français

NIS2 is the European Union's second Network and Information Security Directive. It replaced the original NIS Directive, widened the range of sectors covered, and made national regulators responsible for enforcing it. Member States were required to transpose it into national law by 17 October 2024; several missed that deadline, which is why the picture still looks uneven depending on which country you operate in.

The question most companies actually need answered is narrower than the directive: does this apply to us, and if so, what does it require.

The two-part test

Scope is decided by sector and by size, and you have to satisfy both.

Sector. The directive lists sectors in two annexes. Annex I covers what it calls sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II covers other critical sectors: postal and courier services, waste management, manufacture and distribution of chemicals, food production and distribution, manufacturing of certain products including medical devices, computers, electronics, machinery and vehicles, digital providers such as online marketplaces, search engines and social platforms, and research organisations.

That list is wider than people expect. "Digital infrastructure" and "ICT service management" pull in cloud providers, data centres, content delivery networks, managed service providers and managed security service providers. A B2B SaaS company that would never describe itself as critical infrastructure may well be an ICT service manager under the directive.

Size. The general rule is the medium-sized enterprise threshold: 50 or more employees, or annual turnover and balance sheet total above EUR 10 million. Above that, entities in Annex I sectors are essential; entities in Annex II sectors are important. The distinction affects supervision rather than obligations - essential entities face proactive supervision, important entities are supervised after the fact.

Size is not an escape hatch. The directive names cases where an entity is in scope regardless of headcount, including sole providers of a critical service in a Member State, providers of public electronic communications networks, trust service providers, and top-level domain registries. Member States may also designate individual entities.

The part that catches companies who are not in scope

NIS2 obliges entities to manage risk in their supply chains. Your customer, if they are in scope, has to assess the security of their suppliers - and that obligation lands on you as a contractual requirement whether or not the directive names your sector.

In practice this arrives as a questionnaire, a set of clauses in a renewal, or a request for evidence of your security practices. Companies that concluded they were out of scope frequently find themselves answering NIS2-shaped questions from customers who are in scope. Being able to answer them well is a commercial advantage before it is a compliance matter.

What it requires

Article 21 sets out the minimum measures, and the list is unsurprising to anyone who has worked with an established framework: risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, policies to assess the effectiveness of the measures, basic cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication.

Two obligations are worth separating out because they carry deadlines and personal consequences.

Incident reporting. A significant incident requires an early warning to the national CSIRT or competent authority within 24 hours, an incident notification within 72 hours, and a final report within one month. Twenty-four hours is short enough that it has to be rehearsed. If nobody knows who makes the call at 02:00 on a Sunday, the deadline is already missed.

Management accountability. Management bodies must approve the risk measures and oversee their implementation, and can be held liable for failures. Members are required to undergo training. This is the provision that moves NIS2 from a security team concern to a board one.

Working out where you stand

Start by writing down which of your activities map to an Annex I or Annex II sector, and check your headcount and financials against the threshold. If the answer is close, treat yourself as in scope; the cost of preparing and being wrong is far lower than the reverse.

If you are in scope, register with the competent authority in your Member State - registration requirements and deadlines vary by country, which is the practical consequence of uneven transposition.

If you are not in scope, work out which of your customers are, because their supply chain obligations will reach you.

Existing certifications help but do not settle it. An ISO 27001 certificate covers a great deal of Article 21, and mapping your existing controls to the article is a reasonable first exercise. It does not cover the reporting deadlines or the management accountability provisions, and NIS2 compliance is not something a certificate demonstrates by itself.

ShareLinkedInXEmail
Keep reading