Does my business fall under NIS2?
Two things determine it: your sector and your size. But there is a third group that falls outside it and still gets the requirements.
Sector and size, in that order
NIS2 is a European directive on the security of network and information systems. It designates eighteen sectors, divided across two annexes. Annex I includes sectors of high criticality: energy, transport, healthcare, drinking water, digital infrastructure, government. Annex II includes the remaining critical sectors, such as postal services, waste, chemicals, food, industry and digital service providers.
If your sector is not listed, you do not fall under it. If it is listed, your size counts. From approximately fifty employees or ten million euro in turnover, you are medium-sized and the obligations apply. If you are larger than two hundred and fifty employees or fifty million in turnover and are in Annex I, you are an essential entity and are subject to prior supervision. The rest are important entities: the same duty of care, but supervision only if there is cause.
The third group, and it is the largest
The vast majority of organisations that deal with this do not fall under it themselves. They supply to someone who does. The directive requires regulated organisations to assess the security of their suppliers, and they do this with questionnaires and contractual requirements.
For you, that means no registration obligation, no reporting obligation and no fine. But it does mean a customer who wants an answer, and who will contract elsewhere if you cannot provide one. In practice, that affects more businesses and faster than the law itself.
Exceptions you must not miss
Even below the threshold, you can be regulated. If you are the sole provider of a service in a Member State, or if failure of your service would have major societal consequences, your supervisor can still designate you. Providers of public electronic communications and trust services fall under it regardless of their size.
The reverse also applies to something. Banks and financial markets fall in practice under DORA, the digital resilience regulation for the financial sector. That takes precedence as a special regime. If you recognise yourself in that, seek advice on it.
Frequently asked questions
Will I be notified if I fall under it?
No, and that is the pitfall. No letter will arrive. You must determine it yourself and register yourself with the supervisor.
What if I get it wrong?
Wrongly thinking you do not fall under it is the most expensive scenario: fines go up to ten million euro or two per cent of global turnover, and management is personally liable. If you are in doubt, assume you do and have it checked.
Does this also apply to my overseas establishment?
The directive applies throughout the EU, but obligations arise through the national law of each country, and those are not equally advanced everywhere. You register yourself in the country where you are established; with multiple establishments, that can be in multiple places.
This is explanation, not advice about your own situation. secria.eu does not assess your organization and does not provide assurance.