secria.eu

how do I know if my company falls under NIS2

Sector, size and supply chain role together determine the answer

Whether a business is covered by the NIS2 Directive depends on three things combined: the sector in which it operates, the size of the organization and the role it plays in the supply chain of other businesses. Any business in a sector listed in Annex I or II — think of energy, transport, digital infrastructure, healthcare and a range of other sectors — and above the specified size thresholds, falls under the Directive itself, as an essential entity or an important entity. An overview of those sectors can be found on the page about which sectors fall under the NIS2 directive, and the distinction between the two categories is explained on the page about what is the difference between an essential entity and an important entity.

A business that does not itself operate in a named sector or falls below the size thresholds is not automatically outside the picture. As soon as it supplies to an organization that is itself subject to obligations, it comes into view through the supply chain, because that obligated organization must assess its suppliers. That explains why businesses that at first glance have nothing to do with the Directive nonetheless receive security questionnaires and contractual requirements. Financial institutions are a separate exception to this: they fall under a different European regulation, DORA, and not under NIS2 — what applies to that sector is set out on the page about does NIS2 or DORA apply to my bank or insurance company.

What this is based on: sector and supply chain provisions in the Directive

The classification of sectors and the size criteria come from the NIS2 Directive itself, with the security obligations that follow developed in Article 21 and the associated reporting obligation in Article 23; the Dutch implementation runs through the Cybersecurity Act, and the NCSC provides guidance on how that security obligation and reporting obligation work in practice. The supply chain mechanism — whereby obligated organizations must assess their suppliers — also follows from that security obligation provision.

What you concretely need to do

The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.

View the subscription First the free NIS2 check

This is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.

Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.