What are the specific sectors and types of entities covered by the NIS2 Directive?

Direttiva NIS2 Frequently Asked Questions

Here is a breakdown of the specific sectors and types of entities covered by the NIS2 Directive.

Sectors and Entities Covered by the NIS2 Directive

The NIS2 Directive classifies entities into two main groups: those operating in highly critical sectors and those in other critical sectors. If you want to understand the main objective of the NIS2 Directive before diving into the details of the scope, you can start there.

Highly critical sectors

These sectors are considered essential for the functioning of the economy and society and are therefore subject to more stringent cybersecurity requirements. Highly critical sectors, along with their subsectors and examples of specific entity types, are listed in Annex I of the official text of the NIS2 Directive. These sectors include:

  • Energy: This sector includes electricity, district heating and cooling, oil, gas, and hydrogen. Examples of covered entities include electricity suppliers, transmission system operators, producers, and operators of oil and gas pipelines and storage facilities.
  • Transport: This sector covers air, rail, water, and road transport. Covered entities include airlines, airport operators, railway companies, shipping companies, port authorities, and traffic management operators.
  • Banking: This sector covers credit institutions as defined by financial regulations.
  • Financial market infrastructures: Includes entities such as trading venues and central counterparties, which are crucial for the functioning of financial markets.
  • Health: Includes healthcare providers and, in particular, entities involved in the production of pharmaceutical products, including vaccines.
  • Drinking water: Covers entities involved in the supply and distribution of drinking water.
  • Waste water: Includes entities responsible for the collection, treatment, and disposal of waste water.
  • Digital infrastructure: This sector covers a wide range of entities providing crucial digital services, including Internet exchange points, DNS service providers, top-level domain (TLD) name registries, cloud computing service providers, data centers, content delivery networks (CDNs), trust service providers, and providers of public electronic communications networks and services.
  • ICT service management: Includes managed service providers and managed security service providers, highlighting the importance of cybersecurity for outsourced IT services.
  • Public administration: Covers public administration entities at both central and regional levels, as defined by individual Member States.
  • Space: Includes operators of ground-based infrastructure that support space-based services, emphasizing the growing reliance on space assets.
🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

Other critical sectors

While considered less critical than the sectors listed above, these sectors are still subject to the cybersecurity requirements set out by the NIS2 Directive. Examples include:

  • Postal and courier services
  • Waste management
  • Chemicals
  • Food
  • Manufacturing of various products, including medical devices, computers, electronics, machinery, motor vehicles, trailers, and other transport equipment
  • Digital providers, such as online marketplaces, online search engines, and social networking platforms
  • Research organizations

Entities not specifically listed in Annex I or II

In addition to the listed sectors, the NIS2 Directive covers:

  • Entities providing domain name registration services: These entities are covered regardless of their size.
  • Entities identified as critical under Directive (EU) 2022/2557: Although not specifically listed in Annex I or II, these entities fall within the scope of NIS2 due to their criticality as determined by other regulations.

Size threshold

The NIS2 Directive introduces a size threshold to determine whether an entity in a covered sector is subject to its requirements. Generally, the directive applies to medium and large enterprises in the specified sectors. However, Member States have the flexibility to identify and include smaller entities with high security risk profiles.

Entities excluded from certain provisions

It is important to note that some entities are excluded from some, but not all, provisions of the NIS2 Directive. For example, financial entities subject to Regulation (EU) 2022/2554 are exempt from the cybersecurity risk management and reporting obligations under the NIS2 Directive because DORA already addresses these aspects. However, these financial entities are still considered in the context of large-scale cybersecurity incidents and national response plans.

The NIS2 Directive aims to create a more robust and harmonized cybersecurity landscape across the EU by imposing obligations on a wide range of entities operating in critical sectors. The directive’s comprehensive approach recognizes the interconnected nature of today’s digital world and the potential for cascading impacts resulting from cybersecurity incidents. If your organization falls into one of the described sectors, the first concrete step is to verify the scope of application with the support of ISGroup’s NIS2 compliance path.

For organizations that have yet to complete registration, it is also useful to consult the guidance from ACN on the NIS2 list and deadlines for obligated entities.

Frequently asked questions about the NIS2 scope

  • How do I know if my company falls within the NIS2 scope?
  • You must verify two conditions: that the sector in which you operate is included in Annex I or II of the directive, and that your organization exceeds the expected size thresholds (generally medium and large enterprises). However, Member States may extend the obligation to smaller entities with high risk profiles, so it is advisable to carry out a specific assessment.
  • Are small businesses always excluded from NIS2?
  • Not necessarily. The general rule excludes micro and small enterprises, but there are exceptions: for example, domain name registration service providers are subject to the directive regardless of their size. Furthermore, each Member State may include smaller entities that present a significant security risk.
  • What happens if my organization operates in multiple sectors, some covered and some not?
  • In this case, the principle of prevalence applies: if a significant part of the activity falls within a sector covered by NIS2, the entire organization is generally subject to the obligations for that part. It is advisable to analyze individual operating units and verify on a case-by-case basis, also in accordance with the guidance of the competent national authority.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In