Who Needs to Comply With NIS2? A Sector-by-Sector Guide

Understand who NIS2 applies to, how Essential and Important Entities are classified, and what organisations need to do to strengthen cybersecurity compliance and operational resilience.

PUBLISHED:

See more TechGraph stories in your search results.
Google Add TechGraph on Google

Cybersecurity failures can interrupt far more than an internal IT system. They can delay medical care, disrupt transport, halt manufacturing, affect public services, and expose customers to serious consequences. That is why NIS2 compliance has become a board-level responsibility across Europe.

The difficult part is determining whether the directive applies to a specific organization. Scope depends on the sector, service type, organization size, national implementation, and the impact a disruption could create.

- Advertisement -

Why NIS2 Has a Wider Reach Than NIS1

NIS2 replaced the original NIS Directive with a broader framework designed for a more connected economy. It applies to more sectors, strengthens supervision, and places clearer cybersecurity responsibilities on organizational leadership.

Compliance Is Driving Security Investment

Regulatory expectations are already shaping how organizations fund cybersecurity. ENISA found that 70% of surveyed organizations identified regulatory compliance as the main driver of cybersecurity investment. The same research found that these investments also strengthened risk management, detection, response, and recovery.

This shift matters because NIS2 is not limited to policy writing. Organizations need to show that security measures are operating in real life, including during supplier failures, ransomware events, access-control problems, and recovery scenarios.

Leadership Cannot Treat Cybersecurity as an IT-Only Issue

Management bodies are expected to approve cybersecurity risk-management measures and oversee their implementation. In practice, that means leadership needs visibility into major risks, control gaps, incident escalation, and the organization’s ability to meet reporting obligations.

Technical teams still manage daily security work, but they should not carry the full burden alone. Board members and senior leaders need a practical understanding of risk ownership, evidence requirements, and the possible operational impact of an incident.

How to Determine Whether NIS2 Applies to You

A scope review should start with the organization’s actual services, not simply the sector label it uses in marketing or internal reporting. Some organizations support essential functions indirectly through managed services, technology, specialized manufacturing, or supply-chain operations.
Start With Your Services and Sector

Organizations reviewing the nis2 requirements should map their legal entities, EU locations, customers, digital services, operational technology, and critical dependencies. This assessment should identify whether the organization provides a service listed in Annex I or Annex II of the directive.

A company may need a closer review if its systems support hospitals, utilities, transport operators, public authorities, or financial institutions. A service does not have to be famous or consumer-facing to create a significant operational dependency.

Apply the Size and Criticality Test

As a general rule, medium-sized and large entities in covered sectors should assess their NIS2 status. The test may involve employee numbers, turnover, balance-sheet totals, and relationships with linked or partner enterprises, especially for corporate groups.

Small organizations are not always excluded. Some providers, including certain digital infrastructure and trust services, may be covered regardless of size. Member States may also designate smaller entities when their disruption could affect public safety, health, security, or essential services.

NIS2 Sectors and Entity Classifications

The directive places entities into Essential and Important categories. Both categories must follow core cybersecurity and incident-reporting duties, but the supervisory approach can differ. National law determines how the classifications are applied in each Member State.

Essential Entities and Highly Critical Sectors

Essential Entities generally include larger organizations in Annex I sectors. These sectors include energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.

The category can also include specific entities regardless of the usual size threshold, such as qualified trust service providers, top-level domain registries, and DNS service providers. Essential Entities may be subject to proactive supervision, including audits, inspections, information requests, and security scans.

- Advertisement -

Important Entities and Other Critical Sectors

Important Entities usually include covered organizations that do not meet the conditions for Essential Entity classification. Annex II includes postal and courier services, waste management, chemicals, food production and distribution, certain critical-product manufacturing, digital providers, and research organizations.

Relevant manufacturers can include organizations producing medical devices, computers, electronic and optical products, electrical equipment, machinery, motor vehicles, trailers, and other transport equipment. Digital providers may include certain online marketplaces, search engines, and social-networking platforms.

Core NIS2 Requirements for Covered Organizations

Once scope is confirmed, the focus should move from classification to execution. A compliance program should connect technical controls, operational resilience, supplier governance, leadership oversight, and evidence collection rather than treating them as separate projects.

Risk Management and Operational Resilience

Covered entities must take appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risks. Key areas include incident handling, business continuity, crisis management, supply-chain security, vulnerability management, access control, encryption, workforce security, and control-effectiveness reviews.

The required measures should reflect the organization’s risks and role. A manufacturer with industrial control systems, for example, may need strong asset visibility, segmented networks, tested recovery plans, and carefully managed vendor access. A cloud or managed-service provider may need deeper identity controls, monitoring, service resilience, and tenant protections.

Incident Reporting and Management Accountability

For significant incidents, NIS2 establishes a staged reporting model that generally includes an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. National rules determine the responsible authority, reporting channel, and any additional details.

Management bodies must also oversee the security program. Organizations should define how incidents are classified, who escalates them internally, who communicates with authorities, and how legal, operational, technical, customer, and insurance teams work together during an event.

Preparing for Scope Changes and Cross-Border Rules

NIS2 is an EU directive, which means Member States implement it through national law. Organizations operating across borders cannot assume that one assessment or one reporting process will cover every country in which they provide services.

Track National Implementation and Proposed Changes

The European Commission proposed targeted NIS2 amendments in January 2026 to improve clarity and reduce administrative burden. Its impact assessment explains the proposed simplification and alignment measures, including their potential effect on smaller and mid-sized organizations.

A proposal is not the same as enacted law. Organizations should distinguish carefully between the existing directive, the national law currently in force, regulator guidance, and changes that are still moving through the legislative process.

Review Cross-Border Services Separately

A group operating across several EU countries may face different competent authorities, registration processes, reporting channels, and supervisory approaches. The same business may also provide several services that fall into different sectors or classifications.

Document each legal entity, qualifying service, and jurisdiction. This makes it easier to explain why a particular classification was reached and prevents a compliance gap from being hidden inside a complicated group structure.

Build a Practical NIS2 Readiness Roadmap

A strong NIS2 program does not begin by purchasing tools. It begins by identifying the organization’s services, risks, existing controls, missing evidence, and accountable owners. This approach helps teams prioritize work that reduces genuine operational exposure.

Start With a Documented Gap Assessment

Map assets, privileged accounts, suppliers, critical processes, recovery capabilities, incident procedures, and reporting responsibilities. Then compare those findings with the organization’s legal obligations and risk profile. Prioritize gaps that could lead to service disruption, unsafe operations, prolonged downtime, or unclear incident escalation.

Do not rely on a policy that has never been tested. Backups, recovery procedures, tabletop exercises, supplier controls, access reviews, and incident playbooks need evidence that they have been used, reviewed, and improved.

Turn Everyday Work Into Compliance Evidence

Evidence should be created during normal operations, not collected in a rush after an incident. Keep records of risk assessments, management approvals, training, access reviews, supplier evaluations, security testing, vulnerability remediation, backup tests, exceptions, and accepted risks.

This approach makes audits and regulatory questions easier to manage. It also gives leadership a more accurate picture of whether controls are actually working. NIS2 compliance should be treated as an ongoing governance process, not a one-time certification exercise.

Frequently Asked Questions About NIS2

Does NIS2 apply to every company in a covered sector?

No. Sector is only one part of the assessment. The organization’s size, service type, jurisdiction, criticality, and specific exceptions also matter. Each company should compare its activities with the directive’s annexes and the national law implementing NIS2.

Are small businesses exempt from NIS2?

Many small and microenterprises fall outside the general size threshold, but exceptions exist. Some digital infrastructure and trust-service providers may be covered regardless of size, while national authorities may designate smaller entities when their services create significant risk.

Can one corporate group have different NIS2 classifications?

Yes. Separate entities or business units may operate in different sectors, provide different services, or fall under different national rules. Each qualifying activity should be assessed before the group creates a consolidated NIS2 compliance plan.

Do organizations outside the EU need to consider NIS2?

Possibly. Some non-EU organizations offering covered services in the Union may have obligations, including appointing an EU representative. European customers may also require security controls contractually, even if the supplier is not directly regulated.

What is the difference between NIS2 and DORA?

NIS2 is a cross-sector cybersecurity directive, while DORA establishes digital operational resilience requirements for defined financial entities and ICT third-party providers. Organizations affected by both frameworks should map the overlap before assigning controls, owners, and incident-reporting responsibilities.

Final Thoughts on NIS2 Scope and Readiness

NIS2 reaches well beyond traditional critical infrastructure. Its scope includes digital infrastructure, managed ICT services, health, transport, financial services, public administration, manufacturing, postal services, waste, chemicals, food, online platforms, research, and connected supply-chain activities.

The right starting point is a documented scope assessment based on actual services, organization size, EU presence, and national law. Once scope is clear, leaders can strengthen the controls that matter most, establish reliable incident procedures, and build the evidence needed to demonstrate ongoing compliance.

Stay ahead of the curve, every day.

A daily briefing covering news, interviews, and the trends driving the world forward. Curated for readers who want news, not noise.

We don’t spam! Read our privacy policy for more info.

- Advertisement -
Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

Top Gainers · Global

View all
NamePriceChange
1810Xiaomi HK$25.96 +9.72%
ORCLOracle $142.35 +4.91%
PANWPalo Alto Networks $417.87 +4.86%
COLPALColgate-Palmolive India ₹1,817.80 +4.73%
APOLLOHOSPApollo Hospitals ₹8,027.50 +4.72%

Latest Stories

Scalefusion Launches Veltar Vulnerability Management for Endpoint Security

Veltar Vulnerability Management connects vulnerability detection with Scalefusion UEM, allowing security and IT teams to assess endpoint risks and move towards remediation within the same workflow.

Where Driver Dollars Are Really Going

Owning a motor vehicle involves a wide variety of...

How is the extensive use of AI causing cyber threats?

At times, when artificial intelligence is involved in routine...

What Will Happen to Your Home After a Divorce?

Divorce can affect nearly every part of a person’s...

Why AI Adoption Fails in Enterprises; and What Leaders Can Do Differently

Artificial Intelligence has become a boardroom priority. Organisations across...

Related Articles

Scalefusion Launches Veltar Vulnerability Management for Endpoint Security

Veltar Vulnerability Management connects vulnerability detection with Scalefusion UEM, allowing security and IT teams to assess endpoint risks and move towards remediation within the same workflow.

Where Driver Dollars Are Really Going

Owning a motor vehicle involves a wide variety of ongoing costs that go far beyond initial purchase prices and fuel. Every year, vehicle owners spend substantial amounts of money maintaining performance, preserving aesthetic appeal, and repairing unexpected damage. Understanding where these funds flow provides...

How is the extensive use of AI causing cyber threats?

At times, when artificial intelligence is involved in routine procedures without even being noticed,...

What Will Happen to Your Home After a Divorce?

Divorce can affect nearly every part of a person’s life, including where they live...

Nebius Acquires AI Inference Startup Inferize

Inferize will join Nebius Token Factory, bringing technology designed to reduce model loading times and idle GPU capacity as Nebius expands its production AI inference capabilities.

What Does India’s First Tokenised Bond Pilot Mean for the Debt Market?

India has successfully completed its first tokenised bond issuances, marking a major step for Demat 2.0. While the pilot proves tokenised bonds can operate within the existing financial system, the next challenge is whether the technology can improve liquidity, trading and broader participation in the debt market.

AI Observability: Who Is Monitoring What AI Systems Actually Do?

AI is constantly evolving from doing what it is told to doing what it...

The Grid Shift: NGE Energy’s Sudharman Ezhil on Rethinking How India Builds Solar

Speaking with TechGraph, Sudharman Ezhil, Director and CEO of NGE Energy, discussed how India’s...

Everything About UPI, Teen Patti Variations, and Andar Bahar Tables in 2026

UPI payment methods enable fast deposits at trusted Indian online games featuring Teen Patti variations and Andar Bahar tables. Learn hand rankings, winning odds, side bets, and withdrawal times for secure gaming.

The Grid Shift: NGE Energy’s Sudharman Ezhil on Rethinking How India Builds Solar

Speaking with TechGraph, Sudharman Ezhil, Director and CEO of NGE Energy, discussed how India’s...

Everything About UPI, Teen Patti Variations, and Andar Bahar Tables in 2026

UPI payment methods enable fast deposits at trusted Indian online games featuring Teen Patti variations and Andar Bahar tables. Learn hand rankings, winning odds, side bets, and withdrawal times for secure gaming.

Serhiy Tokarev’s Roosh Ventures Enters Sifted’s Top 50 Ranking

Sifted Ranking: Serhiy Tokarev’s Venture Fund Roosh Ventures Enters the Top 50

How Is AI Creating a New Workplace Divide?

Artificial intelligence is changing the workplace faster than any technology we have witnessed in...

How Digital Payments Fuel India’s IPL Cricket Boom

Anyone who has watched an Indian Premier League (IPL) match in a crowded café...

Why AI Adoption Fails in Enterprises; and What Leaders Can Do Differently

Artificial Intelligence has become a boardroom priority. Organisations across industries are investing in AI to improve customer experience, strengthen operations, and drive growth. Yet,...

Serhiy Tokarev’s Roosh Ventures Enters Sifted’s Top 50 Ranking

Sifted Ranking: Serhiy Tokarev’s Venture Fund Roosh Ventures Enters the Top 50

How Is AI Creating a New Workplace Divide?

Artificial intelligence is changing the workplace faster than any technology we have witnessed in...

The Modern Laundry: Pressmate.in CEO Bajrang Saharan on Standardising India’s Fabric Care Industry

Bajrang Saharan said Indian consumers are increasingly prioritising garment safety and service consistency over the convenience of a nearby cleaner.

The Modern Laundry: Pressmate.in CEO Bajrang Saharan on Standardising India’s Fabric Care Industry

Bajrang Saharan said Indian consumers are increasingly prioritising garment safety and service consistency over the convenience of a nearby cleaner.

The Biggest Insurance Mistakes Indian Families Continue to Make

Buying insurance in India has never been easier. In just a few taps on...

How Causal AI Could Change Financial Decision Making

Every senior finance leader who has sat through more than one board cycle has...

Why India needs AI-powered climate resilience at the local governance level

India does not have one climate typology. It has more than 290 days of...