Step 1: Identify your sector and service
NIS2 applies through listed sectors and entity types. Do not describe the business only as software, consulting, healthcare, logistics, or IT. Describe the actual services you provide, who depends on them, and whether they connect to an essential or important sector.
For Dutch organizations, NCSC guidance starts with sector and size. Other countries may use different portals, competent authorities, and sector guidance, so use the official source for the country where the entity operates.
- What services do you provide?
- Which customers depend on those services?
- Do you provide digital infrastructure, ICT service management, cloud, data center, managed security, health, transport, energy, public administration, finance, or other listed services?
- Are you a direct provider, supplier, processor, subcontractor, or internal support entity?
Step 2: Check size criteria and exceptions
NIS2 often uses a size-cap approach for covered sectors, but there are exceptions. Some entities can be included because of the criticality of the service rather than ordinary company size. Group structure can also matter where linked enterprises affect employee count, turnover, or balance-sheet analysis.
This is where many SMBs need care. A small company may be outside direct scope, indirectly affected by customers, or covered because of a specific service. The scope note should show how the conclusion was reached.
| Scope question | What to record |
|---|---|
| Sector | Which NIS2 sector or national category might apply. |
| Service | The service that could make the entity essential or important. |
| Size | Employee count, turnover, balance sheet, and linked-company assumptions. |
| Country | National implementation, authority, portal, and local guidance used. |
| Exception | Any special inclusion, exclusion, or service-specific rule reviewed. |
| Supplier role | Whether customers pass NIS2 requirements down contractually. |
Step 3: Separate direct scope from customer pressure
A company can be outside direct legal scope and still face NIS2 pressure. If you supply a covered customer, that customer may ask for security policies, incident notification commitments, supplier assurance, access control evidence, backup evidence, or vulnerability handling information.
That distinction matters. Direct legal scope needs legal and authority-specific handling. Customer pressure needs a clear security-readiness response. Both need facts, but the owner, deadline, and risk may be different.
Step 4: Keep a scope decision record
A scope decision should not live only in someone's memory. Keep a short record showing the facts reviewed, sources used, assumptions made, people involved, and date of review. Update it when services, markets, customers, corporate structure, or national guidance change.
- Business and legal entity reviewed.
- Sector and service categories considered.
- Country and authority guidance checked.
- Direct-scope conclusion and rationale.
- Indirect customer or supplier pressure noted.
- Next review trigger and owner.
Where Framework-Pro helps
Framework-Pro does not decide whether a company is legally in scope for NIS2. It can help after the scope discussion by turning customer or framework pressure into practical policies, control mapping, evidence placeholders, and readiness tasks.
That is useful when the conclusion is not just yes or no, but we need to prepare better security documentation because customers will ask.
This checklist is general information, not legal advice. Use official national guidance and qualified advisers for final scope decisions.
Quick FAQ
How do I know if NIS2 applies to my company?
Start by checking sector, service type, size criteria, national implementation rules, special exceptions, and supplier relationships. Use official national guidance and legal advice for the final answer.
What is the difference between an essential and important entity?
The labels distinguish categories of covered organizations and supervision. The exact classification depends on sector, size, service type, and national implementation.
Can a small supplier be affected by NIS2?
Yes. Even if not directly in scope, a small supplier may receive NIS2-related security questions from covered customers.
What should a NIS2 scope checklist produce?
It should produce a short decision record: entity, sector, services, size assumptions, country guidance, conclusion, indirect pressure, owner, and review date.
Official sources used
These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.
