NIS2 widens EU cybersecurity obligations from a small group of critical operators to entire sectors of the economy, and many organisations still do not know whether they fall inside the scope. Once the national transposition law applies to you, the duties are not optional, and accountability sits with the management body rather than with the IT department. This guide explains the scope criteria, the substance of the obligations, and where the binding text can be checked.
What is NIS2?
NIS2 is Directive (EU) 2022/2555, in force since January 2023, which replaces the first NIS Directive ((EU) 2016/1148) and requires EU member states to impose cybersecurity risk-management, governance and incident-reporting duties on entities in defined sectors.
The legal form matters for how you read it. NIS2 is a directive, not a regulation: it does not bind companies directly. What binds you is your member state's transposition law, which must meet the directive's minimum level but may go further — additional sectors, stricter thresholds, additional reporting channels. In Germany the transposition instrument is the NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), which amends the BSI-Gesetz. Practically, two texts are relevant to any scope question: the directive for the concepts, the national law for the obligations that actually apply to you.
Who is affected by NIS2?
NIS2 affects organisations that operate in one of the sectors listed in Annexes I and II of Directive (EU) 2022/2555 and that reach at least medium-enterprise size under the EU size-cap rule, plus a number of entity types that fall in scope regardless of their size.
The sector test
The directive splits sectors into two annexes. The split does not change the security requirements — it changes the default classification and therefore the supervisory regime.
| Annex I — sectors of high criticality | Annex II — other critical sectors |
|---|---|
| Energy, transport, banking, financial market infrastructures | Postal and courier services, waste management |
| Health, drinking water, waste water | Chemicals: manufacture, production, distribution |
| Digital infrastructure (incl. cloud computing services, data centre services, CDNs, DNS, TLD registries) | Food: production, processing, distribution |
| ICT service management (business-to-business) | Manufacturing (e.g. medical devices, electronics, machinery, motor vehicles) |
| Public administration entities, space | Digital providers (online marketplaces, search engines, social networks), research |
The annexes are more granular than this summary. Before drawing a conclusion, read the annex entries themselves and the corresponding list in your national law, because member states may add sectors or entity categories.
The size test
Scope generally starts at medium-enterprise size, as defined in Commission Recommendation 2003/361/EC. That recommendation puts medium-sized enterprises at 50 or more staff, or an annual turnover or balance sheet total above EUR 10 million; large enterprises begin at 250 or more staff, or turnover above EUR 50 million together with a balance sheet total above EUR 43 million. Verify the exact figures against the recommendation and your national law before applying them, and note that partner and linked enterprises are counted in, so a small subsidiary of a large group may not qualify as small.
| Classification | Typical basis | Supervision |
|---|---|---|
| Essential entity | Large enterprise in an Annex I sector, plus specific categories named in the directive | Proactive (ex ante): audits and inspections without prior suspicion |
| Important entity | Medium-sized enterprise in an Annex I sector; medium and large enterprises in Annex II sectors | Reactive (ex post): supervision on indication of non-compliance |
Entities in scope regardless of size
The size-cap rule has exceptions. The directive brings certain entity types into scope irrespective of headcount or turnover, including DNS service providers, top-level domain name registries, trust service providers, and providers of public electronic communications networks or publicly available electronic communications services. It also allows member states to capture entities that are the sole provider of a service essential to societal or economic activity, entities whose disruption could have significant systemic risk, and defined parts of public administration. Which of these your member state has actually implemented, and how, is a question for the national law.
graph TD
A["Does your organisation operate in a sector listed in Annex I or Annex II of Directive (EU) 2022/2555?"] -->|No| B["Not directly in scope. Check whether national law adds sectors."]
A -->|Yes| C["Are you a DNS provider, TLD registry, trust service provider, provider of public electronic communications, or a sole provider of an essential service?"]
C -->|Yes| D["In scope regardless of size."]
C -->|No| E["Do you reach at least medium-enterprise size under the EU size-cap rule?"]
E -->|No| F["Usually out of scope, unless your member state designates you individually."]
E -->|Yes| G["Annex I sector and a large enterprise?"]
G -->|Yes| H["Likely an essential entity, subject to proactive supervision."]
G -->|No| I["Likely an important entity, subject to reactive supervision."]
There is a second, indirect route into the requirements. NIS2 makes supply chain security an explicit duty of the entities it covers, so organisations outside the scope regularly receive security questionnaires, contractual clauses and evidence requests from customers who are inside it. Being out of scope does not mean being unaffected.
What does NIS2 actually require?
NIS2 requires in-scope entities to implement appropriate and proportionate technical, operational and organisational risk-management measures, to report significant incidents on a fixed timeline, to register with the competent national authority, and to have the management body approve those measures and supervise their implementation.
Article 21(2) of the directive lists ten themes that the measures must cover as a minimum. They are written as objectives, not as product requirements — there is no prescribed tool for any of them.
| Theme (Art. 21(2)) | What it usually means in practice |
|---|---|
| Risk analysis and security policies | Documented method, documented decisions, periodic review |
| Incident handling | Defined detection, response and escalation process |
| Business continuity | Backup management, disaster recovery, crisis management |
| Supply chain security | Supplier assessment, contractual security clauses, evidence |
| Acquisition, development, maintenance | Vulnerability handling and disclosure across the lifecycle |
| Effectiveness assessment | Testing and measurement of the measures, not just their existence |
| Cyber hygiene and training | Baseline practices and role-appropriate awareness training |
| Cryptography | A policy on the use of cryptography and, where appropriate, encryption |
| Personnel, access control, asset management | Joiner/mover/leaver, least privilege, asset inventory |
| Authentication and secured communications | Multi-factor authentication, secured voice, video, text and emergency communications |
Two governance points are easy to overlook. Article 20 requires management bodies to approve the risk-management measures, oversee their implementation and undergo training themselves; member states must provide that managers can be held liable for breaches of that duty. And registration is a separate obligation from the security measures: national law sets a window in which in-scope entities must register with the competent authority, in Germany the Bundesamt für Sicherheit in der Informationstechnik (BSI). That window is short, so confirm it early rather than after your first audit.
What are the reporting deadlines after an incident?
NIS2 sets a staged reporting timeline for significant incidents under Article 23: an early warning within 24 hours, a fuller incident notification within 72 hours, and a final report within one month, submitted to the CSIRT or the competent authority.
| Stage | Deadline from becoming aware | Content |
|---|---|---|
| Early warning | 24 hours | Whether the incident is suspected to be unlawful or malicious, possible cross-border impact |
| Incident notification | 72 hours | Initial assessment, severity and impact, indicators of compromise where available |
| Intermediate report | On request | Status updates requested by the authority |
| Final report | 1 month after the notification | Detailed description, root cause, mitigation applied, cross-border effects |
"Significant" is defined by effect, not by attack technique: broadly, an incident that has caused or is capable of causing severe operational disruption or financial loss for the entity, or considerable damage to other natural or legal persons. For several digital infrastructure and digital provider categories, a Commission implementing regulation adopted in 2024 sets more detailed technical requirements and quantified incident thresholds. If your organisation falls into one of those categories, read that implementing act rather than relying on the general wording.
What does NIS2 mean for your infrastructure?
Nothing in NIS2 dictates an architecture. What it dictates is that you can explain and evidence your architecture. In most environments the gap is not the technology but the documentation and the testing: backups that exist but were never restored, an asset inventory that stops at the hypervisor, MFA on the VPN but not on the admin console, logs retained for a week.
The supply chain duty deserves particular attention if you run on external infrastructure. You are expected to assess the security of your direct suppliers and service providers and to reflect that assessment in your contracts — notification duties on the provider side, defined responsibilities, and an exit path. Cloud computing services and data centre services are themselves listed under digital infrastructure in Annex I, so many providers are in scope in their own right. That does not transfer to you: a provider's compliance covers the provider's layer, and the configuration, identities and data on top of it remain yours.
When you request evidence from a provider, ask for artefacts rather than statements: the audit report and its scope, the certificate with its statement of applicability, the processing locations, the subcontractor list. centron holds an unqualified BSI C5:2020 Type 1 attestation for ccloud³ / Managed Cloud as well as ISO/IEC 27001, ISO 9001 and ISO 14001 certifications; the corresponding documents are the basis for an assessment, not the marketing summary of them.
Matching infrastructure at centron
Security by default: cloud firewalls filter traffic before it reaches the instance, managed centrally. Explore cloud firewalls →
What happens if you ignore NIS2?
Article 34 of Directive (EU) 2022/2555 requires member states to provide administrative fines with a maximum of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4 % for important entities, whichever amount is higher in each case.
The fines are the visible part. The supervisory powers matter more in day-to-day terms: authorities can order security audits at the entity's expense, issue binding instructions, require that customers be informed of a threat, and require that non-compliance be made public. For essential entities, the directive also provides for the temporary suspension of an authorisation and for a temporary prohibition on individuals exercising management functions, as measures of last resort after other enforcement has failed. Because member states set the national levels and procedures themselves, the applicable figures and powers must be read in the national law, not in the directive.
What are the NIS2 deadlines?
The directive's own dates are fixed; the national dates are not uniform across the EU.
| Date | Event |
|---|---|
| 16 January 2023 | Directive (EU) 2022/2555 enters into force |
| 17 October 2024 | Deadline for member states to transpose NIS2 into national law |
| 18 October 2024 | The first NIS Directive ((EU) 2016/1148) is repealed |
| 17 April 2025 | Member states to establish their list of essential and important entities |
| National | Registration window and start of enforcement under the transposition law |
Several member states, Germany among them, did not meet the October 2024 transposition deadline, and the German NIS2UmsuCG completed its legislative process later. Because the date on which the German rules became applicable — and the length of the registration window attached to them — determines your actual timeline, check the current status directly with the BSI or the Bundesministerium des Innern rather than relying on any secondary summary, including this one. Note also that there is no general grace period built into the directive: obligations apply from the date the national law says they apply.
How does NIS2 relate to ISO 27001, BSI C5 and DORA?
NIS2 is law; ISO 27001 and BSI C5 are voluntary instruments that can supply the evidence the law expects. They do not substitute for each other, but they overlap substantially.
| Instrument | Type | Binds whom | Produces |
|---|---|---|---|
| NIS2 (Directive (EU) 2022/2555) | EU directive, via national law | Entities in listed sectors above the size cap | Legal obligations, supervision, fines |
| ISO/IEC 27001:2022 | International standard | Voluntary | Certificate for an information security management system |
| BSI C5:2020 | Criteria catalogue | Voluntary, cloud providers | Auditor attestation (Type 1 or Type 2) |
| DORA (Regulation (EU) 2022/2554) | EU regulation, directly applicable | Financial entities and their ICT providers | Directly binding ICT risk requirements |
An ISO/IEC 27001:2022 management system covers a large share of the Article 21 themes, which is why it is a common starting point — but certification is not a legal presumption of compliance, and the reporting, registration and management-liability duties have no ISO equivalent. BSI C5 is aimed one layer down: it is the usual evidence format when the supply chain duty requires you to assess a cloud provider. DORA applies to the financial sector and, as sector-specific EU law, takes precedence over the equivalent NIS2 requirements where its provisions are at least equivalent in effect; financial entities should establish which regime governs which obligation before building two parallel programmes. Separately, the Cyber Resilience Act governs products with digital elements on a timetable of its own, and Germany's KRITIS-Dachgesetz addresses physical resilience rather than cybersecurity. Check the applicability dates of both in their own texts.
Where do the binding statements come from?
Four sources carry authority for the claims on this page. The directive text itself is published on EUR-Lex, including the annexes that define the sectors. Your national transposition law is the instrument that actually binds you — for Germany, the BSI and the Bundesministerium des Innern publish the current status, and the BSI additionally offers guidance and an online scope check for the affectedness question. ENISA publishes technical implementation guidance on the Article 21 measures. The standards themselves — ISO/IEC 27001:2022, the BSI C5:2020 criteria catalogue — are the only reliable statement of what a certificate or attestation actually covers.
This guide describes criteria; it is not legal advice, and it does not establish whether your organisation is in scope. Where a threshold, a deadline or a classification decides something material for you, have it confirmed against the current national law by someone who can be held responsible for the answer.
The evidence centron provides for supplier assessments is collected in the Trust Center documents.
More on compliance
- BSI C5 Explained: Attestation, Type 1 and Type 2
- The CLOUD Act and Its Impact on European Companies
- DORA: What the Regulation Means for IT Providers
- ISO 27001: Requirements, Process and Effort
Testen Sie Ihr Setup auf ccloud³
Registrieren Sie sich in der ccloud³ und erhalten Sie 200 € Startguthaben für Ihr Projekt – z. B. für eine PostgreSQL-VM mit automatischen Backups.