The short answer
NIS2 generally applies when an organisation carries out an activity listed in Annex I or Annex II and qualifies as a medium-sized enterprise or exceeds the medium-sized thresholds under the EU SME definition. This is not a simple “50 employees or €10 million turnover” test: staff, turnover, balance-sheet total and data from partner or linked enterprises may all matter. Some categories are covered regardless of size, while registration and procedural details are determined by national law.
Step 1 — Is your activity on the list?
NIS2 (Directive (EU) 2022/2555) covers activities listed in two annexes. The names matter less than the reach: together they cover much of the economy's backbone.
Annex I — sectors of high criticality
- Energy (electricity, district heating and cooling, oil, gas, hydrogen)
- Transport (air, rail, water, road)
- Banking and financial market infrastructures
- Health (healthcare providers, pharma R&D and manufacturing, critical medical devices)
- Drinking water and waste water
- Digital infrastructure (DNS, TLD registries, cloud, data centres, CDNs, trust services, public electronic communications)
- ICT service management, business-to-business (managed service providers, managed security service providers)
- Public administration
- Space
Annex II — other critical sectors
- Postal and courier services
- Waste management
- Chemicals (manufacture, production, distribution)
- Food businesses engaged in wholesale distribution and industrial production or processing
- Manufacturing of specified categories — see below
- Digital providers (online marketplaces, online search engines, social networking platforms)
- Research organisations
Two clarifications that prevent common over-reading. Food: the annex targets wholesale distribution and industrial production or processing — it does not mean that every restaurant, retailer or small food business is covered. Manufacturing is not a catch-all category: Annex II lists specified manufacturing activities, including medical devices, computers and electronics, electrical equipment, machinery, motor vehicles and other transport equipment. A factory outside the listed categories is not brought into scope by headcount alone.
Step 2 — The size test, done properly
As a general rule, entities carrying out listed activities are covered if they qualify as medium-sized enterprises or are larger under Commission Recommendation 2003/361/EC.
For an autonomous enterprise, 50 or more employees normally takes it beyond the small-enterprise category.
With fewer than 50 employees, exceeding only one €10 million financial threshold does not automatically make the company medium-sized. A company may still qualify as small if either its annual turnover or its annual balance-sheet total remains at or below €10 million.
Data from partner and linked enterprises may need to be included. The rules governing changes of status across consecutive accounting periods may also affect the result.
Do not assess NIS2 scope using turnover alone.
Step 3 — The exceptions that ignore size
Some entities are covered no matter how small they are, including:
- Qualified trust service providers, top-level-domain registries and DNS service providers
- Sole providers in a member state of a service essential to society or the economy
- Entities whose disruption could significantly impact public safety, security or health, or create systemic risk
- Central public administration entities
- Any entity a member state specifically designates
Essential vs important — why the label matters
In-scope entities are classified as essential (broadly: large entities in Annex I sectors, plus the special categories) or important (the rest). The obligations — the Article 21 security measures and Article 23 incident reporting — are the same. What differs is enforcement:
| Essential entities | Important entities | |
|---|---|---|
| Supervision | Proactive — audits and checks can happen before anything goes wrong | Reactive — supervision is triggered after indications of a problem |
| Fines | National maximum fines of at least €10M or 2% of total worldwide annual turnover, whichever is higher | National maximum fines of at least €7M or 1.4% of total worldwide annual turnover, whichever is higher |
In both cases, management bodies must approve and oversee the cybersecurity measures and may be held liable under the applicable national law — this is not delegable to IT.
Legal scope vs supply-chain pressure — keep them apart
An out-of-scope supplier does not become directly subject to NIS2 only because it supplies an in-scope customer. What happens instead: Article 21 obliges in-scope entities to manage the security of their supply chain, so those customers pass security requirements, questionnaires and contract clauses down to suppliers. That is contractual pressure, not legal scope — the obligations, deadlines and penalties of the directive itself do not attach to the supplier. In practice, though, a supplier that cannot demonstrate reasonable security may still lose the contract.
A worked example
A Romanian company with 120 employees that performs industrial food production or processing is likely to meet both the Annex II activity test and the general size test. It would ordinarily be assessed as an important entity unless another classification or national designation applies. The final determination must be made under the Romanian legislation and DNSC procedures.
Romania implementation note
Registration or notification requirements are defined by each member state's national implementation of NIS2 — confirm the applicable procedure, deadlines and competent authority in the country where you operate. What follows is one national example, not the universal EU process:
- Romania transposed NIS2 through OUG 155/2024, subsequently approved and amended.
- DNSC is the relevant national cybersecurity authority.
- Organisations must follow the current identification and registration procedure; the NIS2@RO platform may be used where applicable.
- Incident reporting uses the Romanian national process, including PNRISC.
- Registration is not a one-off event tied to the initial 2025 window: entities that become subject to the requirements later must follow the deadline applicable from the date the legal requirements become applicable to them.
- Current DNSC procedures, orders and deadlines must be checked before relying on any summary — including this one.
Status note: the rules may get lighter, not heavier
The European Commission has proposed simplification amendments to NIS2 (the November 2025 Digital Omnibus package and targeted amendments proposed in January 2026). As of the last-reviewed date these are still proposals in the legislative process — they change nothing about your obligations today, and waiting for them is not a compliance strategy.
What to do next
- Confirm your classification against your national transposition — activity lists, the size assessment and registration duties are national-law details.
- If in scope: the obligations already apply; start with a gap assessment of the Article 21 measures and your reporting readiness.
- If out of scope: check your customer base before relaxing — if your customers are essential or important entities, their contractual requirements are heading your way.
Sources
This article is general information about EU legislation, not legal advice. NIS2 is transposed into national law by each member state, and details — sector lists, registration deadlines, procedures — vary by country. Confirm specifics with your national authority (in Romania: DNSC) or legal counsel. This article reflects the legislation in force on the last-reviewed date; proposed amendments are not treated as adopted law.