NetOpsKit

NIS2 Applicability Checker

Find out whether your organisation falls under the EU NIS2 Directive and whether it would be an essential or important entity.

How to use this tool

Answer five short questions: whether you provide services in the EU, your sector, your headcount, and your turnover and balance sheet. The checker applies the EU size rules (Recommendation 2003/361) and the sector lists in Annex I and Annex II of Directive (EU) 2022/2555, then tells you whether you are likely in scope and in which category. Everything runs in your browser. Group structures (linked and partner enterprises) change the size calculation, and each Member State transposes the Directive into its own law, so treat the result as a first indication and confirm with your national authority.

Worked example

A managed service provider with 120 employees and EUR 18M turnover is in "ICT service management (B2B)" (Annex I). With 50-249 staff it is a medium enterprise, so it is likely an important entity. At 260 employees it would be large, so likely an essential entity.

Frequently asked questions

Who does NIS2 apply to?

Medium-sized and large entities in the sectors listed in Annex I and Annex II of Directive (EU) 2022/2555 that provide services or carry out activities in the EU. Some entity types, such as DNS service providers, TLD registries, trust service providers and providers of public electronic communications networks or services, are in scope regardless of size.

Does NIS2 apply to managed service providers?

Yes. Managed service providers and managed security service providers are listed in Annex I under ICT service management (B2B), subject to the size criteria. The Commission has also adopted Implementing Regulation (EU) 2024/2690 with detailed measures for certain digital infrastructure and ICT service management providers.

What is the difference between essential and important entities?

Both must meet the same Article 21 risk-management and Article 23 reporting duties. The differences are mainly in supervision (essential entities can be supervised proactively, important entities mainly after an incident or evidence of non-compliance) and in the minimum fine ceilings Member States must provide: at least EUR 10 million or 2% of worldwide turnover for essential, EUR 7 million or 1.4% for important entities.

Is NIS2 directly applicable like GDPR?

No. NIS2 is a directive, so each Member State transposes it into national law and sets details such as the competent authority and reporting channel. Check your national cybersecurity authority for the rules that apply to you.

Stuck on something this page doesn't cover?

Tell us the problem in your own words. We use these reports (anonymously) to decide which guides to write. No account, name or email needed. Do not include passwords or customer data.