NIS2 guideNIS2 scope checklist

Is your company in scope for NIS2? Start with a practical checklist.

NIS2 scope questions can get complicated quickly. A good first pass does not try to replace legal advice. It helps the business collect the right facts before asking whether it is an essential entity, an important entity, an indirect supplier, or outside direct scope.

Framework-ProUpdated August 2026
Key points

What to remember before you act.

  • Start with sector and service type before looking at controls.
  • Check size criteria, special cases, and connected company structure.
  • National implementation matters, including the relevant authority and registration process.
  • Suppliers can be affected even when they are not directly in scope.
  • Keep a written scope decision record with sources and assumptions.

Step 1: Identify your sector and service

NIS2 applies through listed sectors and entity types. Do not describe the business only as software, consulting, healthcare, logistics, or IT. Describe the actual services you provide, who depends on them, and whether they connect to an essential or important sector.

For Dutch organizations, NCSC guidance starts with sector and size. Other countries may use different portals, competent authorities, and sector guidance, so use the official source for the country where the entity operates.

  • What services do you provide?
  • Which customers depend on those services?
  • Do you provide digital infrastructure, ICT service management, cloud, data center, managed security, health, transport, energy, public administration, finance, or other listed services?
  • Are you a direct provider, supplier, processor, subcontractor, or internal support entity?

Step 2: Check size criteria and exceptions

NIS2 often uses a size-cap approach for covered sectors, but there are exceptions. Some entities can be included because of the criticality of the service rather than ordinary company size. Group structure can also matter where linked enterprises affect employee count, turnover, or balance-sheet analysis.

This is where many SMBs need care. A small company may be outside direct scope, indirectly affected by customers, or covered because of a specific service. The scope note should show how the conclusion was reached.

Scope questionWhat to record
SectorWhich NIS2 sector or national category might apply.
ServiceThe service that could make the entity essential or important.
SizeEmployee count, turnover, balance sheet, and linked-company assumptions.
CountryNational implementation, authority, portal, and local guidance used.
ExceptionAny special inclusion, exclusion, or service-specific rule reviewed.
Supplier roleWhether customers pass NIS2 requirements down contractually.

Step 3: Separate direct scope from customer pressure

A company can be outside direct legal scope and still face NIS2 pressure. If you supply a covered customer, that customer may ask for security policies, incident notification commitments, supplier assurance, access control evidence, backup evidence, or vulnerability handling information.

That distinction matters. Direct legal scope needs legal and authority-specific handling. Customer pressure needs a clear security-readiness response. Both need facts, but the owner, deadline, and risk may be different.

Step 4: Keep a scope decision record

A scope decision should not live only in someone's memory. Keep a short record showing the facts reviewed, sources used, assumptions made, people involved, and date of review. Update it when services, markets, customers, corporate structure, or national guidance change.

  • Business and legal entity reviewed.
  • Sector and service categories considered.
  • Country and authority guidance checked.
  • Direct-scope conclusion and rationale.
  • Indirect customer or supplier pressure noted.
  • Next review trigger and owner.

Where Framework-Pro helps

Framework-Pro does not decide whether a company is legally in scope for NIS2. It can help after the scope discussion by turning customer or framework pressure into practical policies, control mapping, evidence placeholders, and readiness tasks.

That is useful when the conclusion is not just yes or no, but we need to prepare better security documentation because customers will ask.

This checklist is general information, not legal advice. Use official national guidance and qualified advisers for final scope decisions.

Quick FAQ

How do I know if NIS2 applies to my company?

Start by checking sector, service type, size criteria, national implementation rules, special exceptions, and supplier relationships. Use official national guidance and legal advice for the final answer.

What is the difference between an essential and important entity?

The labels distinguish categories of covered organizations and supervision. The exact classification depends on sector, size, service type, and national implementation.

Can a small supplier be affected by NIS2?

Yes. Even if not directly in scope, a small supplier may receive NIS2-related security questions from covered customers.

What should a NIS2 scope checklist produce?

It should produce a short decision record: entity, sector, services, size assumptions, country guidance, conclusion, indirect pressure, owner, and review date.

Official sources used

These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.

Framework-Pro

After the scope check, turn security pressure into structured work.

Framework-Pro helps teams create tailored policy drafts, control maps, readiness tasks, and evidence placeholders based on business context and selected controls.