NIS2 Directive: To whom does it apply?

Direttiva NIS2 Soggetti

The NIS2 Directive covers a wide spectrum of sectors and types of entities in the EU, with the goal of strengthening Cyber Security across the Union. If you want to understand if your organization falls within the scope, the first step is to verify your sector of activity and company size.

Here is an overview of the entities subject to the Directive’s regulations:

Essential and Important Entities

The NIS2 Directive classifies entities based on their potential impact on essential services and social functions. Two main categories are defined:

  • Essential Entities: These are entities whose disruption would have a significant impact on essential services and social functions. This category includes large entities operating in specific sectors, such as energy, transport, health, and financial market infrastructures.
  • Important Entities: This classification includes entities considered important for specific sectors, but whose disruption would not have the same widespread impact as essential entities. Typically, this category includes medium-sized companies operating in sectors such as postal and courier services, waste management, and digital service providers.
๐Ÿ”ด NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

The NIS2 Directive explicitly lists the sectors and sub-sectors subject to its cybersecurity regulations. These are divided into “highly critical sectors” and “other critical sectors,” based on their importance to the overall functioning of the EU. Here is a summary:

Highly critical sectors

  • Energy: Includes electricity, district heating and cooling, oil, gas, and hydrogen.
  • Transport: Covers air, rail, water, and road transport.
  • Banking
  • Financial market infrastructures
  • Health: Includes the manufacture of pharmaceutical products, including vaccines.
  • Drinking water
  • Waste water
  • Digital infrastructure: Includes internet exchange points, DNS service providers, top-level domain (TLD) name registries, cloud computing service providers, data center service providers, content delivery networks (CDN), trust service providers, and providers of public electronic communications networks and publicly available electronic communications services.
  • ICT service management: Includes managed service providers and managed security service providers.
  • Public administration
  • Space

Other critical sectors

  • Postal and courier services
  • Waste management
  • Chemical industry
  • Food
  • Manufacturing of medical devices, computers and electronics, machinery and equipment, motor vehicles, trailers and semi-trailers, and other transport equipment
  • Digital service providers: Includes online marketplaces, online search engines, and social networking service platforms.
  • Research organizations

Considerations on size thresholds

Although specific size thresholds are not detailed in these sections of the sources, it is important to note that all medium and large companies operating in the listed sectors are generally subject to NIS2 regulations. This represents a significant change compared to NIS1, which focused on a limited number of designated operators. If your organization operates in one of these sectors, it is advisable to carefully verify your scope of application: the path to compliance with the NIS2 Directive starts with this initial assessment.

Additional considerations on the NIS2 Directive

The NIS2 Directive grants Member States a certain degree of flexibility in identifying the entities subject to its regulations.

  • Entities with a high-risk profile: Member States have the discretion to identify smaller entities with a high security risk profile that should be included, even if they do not meet the typical size requirements.
  • Entities providing domain name registration services: Regardless of size, entities providing these services fall within the scope of the NIS2 Directive.

Exemptions from the NIS2 Directive

Although the NIS2 Directive aims for comprehensive cybersecurity coverage, it provides for some exemptions.

  • National and public security activities: Entities operating in sectors such as national security, public security, defense, and law enforcement may be exempted from some obligations of the NIS2 Directive.
  • Entities providing services exclusively to Public Administration: Entities providing services exclusively to Public Administration bodies indicated in the Directive may also be exempted.
  • Entities exempted under the DORA Regulation: Entities already exempted under the Digital Operational Resilience Act (DORA) for the financial sector are not subject to the requirements of the NIS2 Directive.

Alignment with specific sectoral legislation

The NIS2 Directive emphasizes alignment with existing and future Union sectoral legislation. In cases where such legislation provides for cybersecurity risk management measures or incident reporting requirements with equivalent or more stringent effects than the NIS2 Directive, the specific sectoral legislation prevails. A relevant example is the relationship between the NIS2 Directive and the DORA Regulation in the financial sector.

To delve deeper into the complete regulatory framework, you can consult the official NIS2 Directive document or read what the main objective of the NIS2 Directive is. If your organization is already in the registration phase, you can find practical information on how the ACN list works and the deadlines for NIS2 subjects.

Frequently asked questions about the application of the NIS2 Directive

  • Are small businesses always excluded from the NIS2 Directive?
  • Generally, yes: NIS2 applies to medium and large enterprises operating in the covered sectors. However, Member States may include smaller entities if they present a high-risk profile, and some categories โ€” such as domain name registration service providers โ€” fall within the scope regardless of size.
  • Do suppliers and subcontractors of a NIS2-subject entity also need to comply?
  • The Directive does not impose direct obligations on supply chain suppliers, but subject entities are required to manage risks related to their ICT suppliers. In practice, this often translates into contractual security requirements that suppliers must meet to continue operating with NIS2 subjects.
  • How do you concretely verify if your organization falls within the NIS2 scope?
  • The first step is to check if the sector of activity is among those listed in the Directive’s annexes, then check if the size thresholds are met (at least 50 employees or 10 million euros in turnover for medium-sized enterprises). In Italy, the ACN manages the registration process and provides operational guidance for self-assessment.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In