Who Must Comply With the NIS2 Cybersecurity Regulation?

Someone in your legal team forwarded you an email with "NIS2" in the subject line, you skimmed it for four seconds, and now it's sitting in a folder labeled "deal with later." I get it. Regulation reading is nobody's idea of a fun Tuesday.

But here's the thing. NIS2 isn't one of those directives you can quietly ignore until it goes away. It doesn't go away. It's the EU's biggest cybersecurity shake-up since 2016, and it's already reshaping how tens of thousands of companies across Europe think about risk, incident response, and who picks up the phone when something breaks at 2am.

So let's cut through the legal fog. In this piece, I'm going to walk you through exactly who must comply with the NIS2 cybersecurity regulation, who's exempt, and how to figure out, quickly, which camp you're in. No jargon. No 40-page PDFs. Just the stuff you actually need to know.

First Things First: What Is NIS2, Really?

NIS2, short for the second Network and Information Security Directive (that's Directive (EU) 2022/2555 if you want to sound clever in a boardroom), is the European Union's answer to a simple but uncomfortable question: what happens when a hospital, a power grid, or a bank gets hacked?

The answer, historically, has been "not enough." The original NIS Directive from 2016 tried to fix this, but it had gaps you could drive a truck through. Inconsistent enforcement. Vague scope. Countries interpreting the rules however they liked.

NIS2 closes those gaps. It widens the net, sharpens the teeth, and puts actual consequences behind non-compliance. Think of it as GDPR's tougher, less forgiving cousin, except this one cares about your servers instead of your cookie banners.

So, Who Must Comply With NIS2?

Here's where most people get tripped up. NIS2 doesn't just apply to power plants and government agencies anymore. It's expanded to cover an estimated 160,000+ entities across the EU, up from roughly 10,000 under the original directive. That's not a typo. That's a fifteen-fold jump.

The directive sorts organizations into two buckets: essential entities and important entities. Both are in scope. Both have obligations. The difference mostly comes down to how strictly they're supervised and how big the fines can get if things go sideways.

Essential vs Important Entities: What's the Difference?

Think of it like a nightclub with two lines. Everyone gets in, but the essential entities are the VIPs, watched more closely, checked more often, and treated with a lot less patience if they misbehave.

Category Typically Includes Oversight Level
Essential entities Energy, transport, banking, healthcare, drinking water, digital infrastructure, public administration Proactive supervision, regular audits
Important entities Postal services, waste management, chemicals, food production, manufacturing, digital providers Reactive supervision, checked after an incident or complaint

Both categories face real obligations. Neither gets to shrug and say "we're only important, not essential, so we're fine." That's not how this works.

The Sectors NIS2 Actually Covers

If you're wondering whether your industry made the list, here's the short version. NIS2 covers 18 sectors total, roughly double what the original directive covered.

High-criticality sectors (typically essential entities):

  • Energy (electricity, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking and financial market infrastructure
  • Health (hospitals, labs, pharma manufacturers)
  • Drinking water and wastewater
  • Digital infrastructure (cloud providers, data centers, DNS providers)
  • Public administration
  • Space

Other critical sectors (typically important entities):

  • Postal and courier services
  • Waste management
  • Chemical manufacturing and distribution
  • Food production, processing, and distribution
  • Manufacturing (medical devices, electronics, machinery, vehicles)
  • Digital providers (online marketplaces, search engines, social networks)
  • Research organizations

If you spotted your industry up there, congratulations (or condolences, depending on how prepared you are). If you didn't, don't relax just yet. Keep reading, because scope isn't only about industry.

Does NIS2 Apply to SMEs?

This is probably the question keeping most SME founders up at night, so let's tackle it head-on.

The general rule is that NIS2 applies to medium and large organizations in the sectors listed above. Specifically, that means companies with:

  • 50 or more employees, OR
  • €10 million or more in annual turnover or balance sheet total

If you're a genuinely small operation, say, ten people running a niche logistics tool out of a co-working space in Lisbon, you're likely exempt from NIS2's direct obligations.

But (and this is a big but), there's a catch. NIS2 also drags in smaller companies through a side door: supply chain requirements. If you're a tiny vendor supplying software, hardware, or services to a large essential or important entity, that bigger company is now required to vet your security practices as part of its own compliance. So even if NIS2 doesn't technically apply to you directly, your biggest client might start asking you uncomfortable questions about your firewall setup.

There are also exceptions to the exception. Some sectors, like DNS providers, trust service providers, and certain telecom operators, are in scope regardless of size, because the risk they pose is considered too critical to leave to a headcount threshold.

A Quick Self-Check: Are You In Scope?

I like simple tests, so here's one. Ask yourself these four questions:

  1. Does my company operate in one of the 18 sectors listed above?
  2. Do I have 50+ employees or €10M+ in annual turnover?
  3. Am I a critical digital infrastructure provider (DNS, cloud, trust services), regardless of size?
  4. Do I supply products or services to a company that's clearly in scope?

If you answered yes to even one of these, it's worth having a proper conversation with your compliance or IT security lead. Sooner rather than later.

What Happens If You're In Scope? A Fast Overview

Once you're confirmed as in scope, NIS2 asks for a handful of concrete things. I won't drown you in Article 21 legalese, but here's the gist:

  • Risk management measures, covering everything from incident handling to supply chain security
  • Incident reporting, with a jarringly tight 24-hour early warning window, followed by a fuller report within 72 hours
  • Governance accountability, meaning your leadership team (yes, you) can be held personally responsible for gaps in cybersecurity oversight
  • Business continuity planning, so you're not scrambling to figure out backups mid-crisis

And the penalties aren't symbolic. Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher. That's GDPR-level money, and regulators across the EU are already signaling they intend to use it.

NIS2 vs GDPR: Quick Comparison

People often lump these two together, and while they're cousins in spirit, they're not the same animal.

NIS2 GDPR
Focus Network and information system security Personal data protection
Who It Targets 18 critical sectors, medium/large organizations Any organization processing EU personal data
Max Penalty Up to €10 million or 2% of global annual turnover Up to €20 million or 4% of global annual turnover
Reporting Window 24 hours (early warning) 72 hours

If you're already GDPR-compliant, you have a head start, but NIS2 is not just GDPR with a new coat of paint. It's a separate obligation with its own teeth.

FAQ: Who Needs to Comply With NIS2?

Does NIS2 apply to small businesses? Generally, no, unless you're in a handful of high-risk categories like DNS or trust services, or you supply a larger company that is in scope. Size thresholds exist, but they're not a guaranteed shield.

What's the real difference between essential and important entities? Mostly the level of regulatory oversight. Essential entities get checked proactively and regularly. Important entities tend to get checked only after something goes wrong. Both face real obligations either way.

Can my company be in scope even if I'm not in one of the 18 sectors? It's uncommon, but it can happen indirectly through supply chain requirements if a large customer needs you to meet certain security standards to keep doing business with them.

Is compliance optional if I think the fines won't apply to me? I wouldn't bet on that. Regulators across the EU are actively enforcing NIS2 in 2026, and "we didn't think it applied to us" isn't holding up well as a legal defense.

Wrapping It Up

Here's the honest truth. NIS2 isn't designed to punish businesses for existing. It's designed to make sure that when something goes wrong (and eventually, something always does), the fallout doesn't spiral into a continent-wide mess. If you run critical infrastructure, handle sensitive services, or even just supply someone who does, this regulation has your name on it somewhere.

The smartest move isn't to panic. It's to get clarity. Figure out where you stand, map your obligations, and build a plan before a regulator, or worse, a breach, forces your hand.

So, where do you land? If you're still unsure whether NIS2 applies to your business, don't leave it to guesswork. Talk to your compliance lead, run the self-check above, and start the conversation this week, not after the next headline about a fine makes you wish you had.

Other News and Events from ViVeTech

July 2, 2026
The Rise of Shadow AI: Balancing Corporate Innovation with Data Protection
Learn more
July 2, 2026
What Your Company Does Not Know About Its Digital Footprint Can Disrupt It
Learn more
July 2, 2026
Why Investing in More Disconnected Security Tools Is No Longer the Answer
Learn more

További híreink és eseményeink

2026-07-03
Shadow AI a munkahelyeken: hogyan támogassuk az innovációt az adatbiztonság feláldozása nélkül?
Olvasson tovább
2026-07-03
Miért nem megoldás többé az egymástól elszigetelt biztonsági eszközök halmozása
Olvasson tovább
2026-07-03
Amit a vállalat nem lát a digitális jelenlétéből, az komoly üzleti kockázatot jelenthet
Olvasson tovább