What are the size thresholds for falling within the scope of the NIS2 Directive?

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive introduces a significant change compared to its previous version by incorporating size thresholds as a key criterion for determining whether an entity falls within its scope. Sources indicate a two-tier approach: a general size threshold based on company size and a more flexible approach that considers factors beyond size.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.
  • General Size Threshold: Article 2 of the NIS2 Directive establishes the general rule for inclusion based on size. Entities generally fall within the scope of the directive if they meet one of the following criteria:
    • Medium-sized Enterprise: Classified as a medium-sized enterprise pursuant to Article 2(1) of the Annex to Recommendation 2003/361/EC.
    • Exceeding Medium-sized Enterprise Thresholds: Exceeding the maximum thresholds for medium-sized enterprises, as established in Article 2(1) of the Annex to Recommendation 2003/361/EC.
  • Beyond Size: Flexibility for Member States: Although size is a primary factor, the NIS2 Directive recognizes that even smaller entities could pose a significant cybersecurity risk. It grants Member States the discretion to include entities that do not meet the general size threshold based on specific criteria:
    • High-Risk Profile: Member States may identify smaller entities with a high-risk profile and subject them to the obligations of the NIS2 Directive. The criteria for determining a high-risk profile are not explicitly defined in the provided texts, suggesting that Member States may have some margin of autonomy in defining such criteria.
    • Essential Entities: Article 2(2)(b)-(e) allows Member States to designate certain entities as “essential entities,” even if they do not meet the general size thresholds. This designation depends on whether disruptions to the services offered by the entity could have a significant impact on the maintenance of critical societal or economic activities. Factors for making this determination include:
      • The entity is the sole provider in a Member State of a service considered essential for the maintenance of vital societal or economic functions.
      • The possibility that disruptions to the services offered by the entity could have a substantial impact on public security, public health, or national security.
      • The possibility that disruptions to the services offered by the entity could lead to a significant systemic risk, particularly in sectors where such disruptions could have cross-border implications.
  • Specific Cases Regardless of Size: Certain entities, regardless of their size, automatically fall within the scope of NIS2:
    • Critical Entities: Article 2(3) establishes that the Directive applies to all entities designated as “critical entities” under Directive (EU) 2022/2557. This implies that critical infrastructure and entities essential for national security or essential services are covered by NIS2 regardless of their size.
    • Domain Name Registration Services: Article 2(4) mandates that the Directive applies to all entities providing domain name registration services, regardless of size. This underscores the critical role of domain name registration in cybersecurity and the importance of ensuring that these entities comply with robust security standards.

In summary, while NIS2 introduces a general size threshold based on the definition of a medium-sized enterprise, it allows Member States some flexibility to include smaller entities based on risk profiles or if they are considered providers of essential services. Furthermore, certain critical entities and domain name registration service providers are covered regardless of their size. If your organization falls within any of these perimeters, a structured NIS2 Directive compliance path helps identify applicable obligations and plan necessary measures — including the ACN registration list deadlines that NIS2 subjects must meet.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In