secria.eu

which sectors fall under the NIS2 directive

Eleven high-risk sectors, seven below

NIS2 works with a list of sectors, divided across two annexes. Annex I names the sectors with the highest risk: energy, transport, banking, drinking water, wastewater, digital infrastructure, government, healthcare, space and a few others. Organisations in these sectors can, depending on their size, be designated as essential entities. Annex II names sectors considered important: postal and courier services, waste management, chemicals, food, production of certain goods, digital providers and research. Both annexes are reflected in the Cybersecurity Act, the Dutch implementation of the directive.

Sector is not the only criterion. Within those sectors, the size of the organisation also matters — the number of employees and annual turnover play a role in determining whether something is classified as essential, important, or not affected at all. In addition, there is a group that does not appear in the annexes but is nonetheless affected by the consequences: suppliers to an essential or important entity, who receive security questionnaires and contract requirements through their customer's duty of care without being subject to obligations themselves. Anyone who wants to know what exactly changes due to the national law will find there the translation of these annexes into the Dutch text. Financial institutions are an exception: they fall under a different European regulation and not under NIS2.

What this is based on: the annexes of the directive

The sector classification follows from the annexes to Directive (EU) 2022/2555, which define the scope of the duty of care and the reporting obligation — the ten measures in Article 21(2) apply to those within that scope. The Cybersecurity Act adopts this classification for the Dutch situation, with the NCSC as the source for guidance on the practical aspects of the duty of care and reporting obligation. Anyone who, after this sector list, wants to check whether their own organisation actually falls under it can investigate further via the check of whether a company falls under NIS2, and anyone in doubt between the two statuses within the annexes will find the explanation in the difference between an essential and an important entity.

What you concretely need to do

The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.

View the subscription First the free NIS2 check

This is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.

Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.