Scope and applicability

Does your organisation fall within the scope of NIS2?

The scope is determined by the type of activity and by the size of the enterprise. Answer three short questions to get an indicative assessment and see which ground applies.

Indicative check

A short scope check

The check runs entirely in your browser. We do not send, store or analyse the answers.

1. Which sector does the organisation work in?
2. How large is the organisation?
3. Does any of the special grounds apply? (optional)

Answer the first two questions to see an indicative result.

The check is indicative and runs entirely in your browser - we neither transmit nor store the answers. The final determination of essential and important entities is made by the competent authorities under a methodology adopted by the Council of Ministers (Art. 4a).

Annex I

Sectors of high criticality

  • Energyelectricity, district heating and cooling, oil, natural gas, hydrogen
  • Transportair, rail, water, road
  • Banking sectorcredit institutions
  • Financial market infrastructuresoperators of trading venues, central counterparties
  • Healthhealthcare providers, research activity and manufacturing of medicinal products
  • Drinking watersuppliers of drinking water
  • Waste watercollection, disposal and treatment
  • Digital infrastructureinternet exchange points, DNS, top-level domain name registries, cloud computing services, data centre services, content delivery networks, trust services
  • Management of ICT services (business-to-business)providers of managed services and managed security services
  • Spaceoperators of ground-based infrastructure
Annex II

Other critical sectors

  • Postal and courier servicesproviders of postal services
  • Waste managementundertakings carrying out waste management
  • Chemicalsmanufacture, production and distribution
  • Foodproduction, processing and distribution
  • Manufacturingmedical devices, computers and electronics, electrical equipment, machinery, transport vehicles
  • Digital service providersonline marketplaces, search engines, social networking platforms
  • Researchresearch organisations

Size criteria

The threshold that brings the organisation into scope

Source: SME Act, Art. 3 (amended, State Gazette No. 70 of 2024, in force from 1 January 2026)

Enterprise categories by size
CategoryStaffTurnover and/or assets
Medium-sized enterprisefewer than 250 peopleup to 50 million euro in turnover and/or up to 43 million euro in assets
Small enterprisefewer than 50 peopleup to 10 million euro in turnover and/or up to 10 million euro in assets
Micro enterprisefewer than 10 peopleup to 2 million euro in turnover and/or up to 2 million euro in assets
01

How the scope is determined

The scope is determined by two conditions taken together: the type of activity must be among those listed in Annex I or Annex II, and the size of the enterprise must reach the set threshold. Either condition on its own is not sufficient.

Next, it is determined whether the entity is essential or important. Essential entities are from the Annex I sectors and exceed the upper threshold for a medium-sized enterprise. Entities from Annex I or II that do not meet the criteria for essential are considered important (Art. 4a(2)).

The competent authorities determine the essential and important entities under a methodology adopted by the Council of Ministers, and notify the Minister of Electronic Governance. The organisation's own assessment is therefore the start of the process, not its final decision.

02

Special grounds, independent of sector

The Act provides grounds for inclusion that do not follow only from sector and size. They are checked separately, because they are often missed in the initial review.

  • Providers of public electronic communications networks or services that meet the criteria for a medium-sized enterprise (Art. 4a(1)(3)).
  • Public and private entities whose disruption could have a significant impact on the services provided.
  • Entities that are critical because of their specific importance at national or regional level for a particular sector.
  • Public and private entities that are the sole provider of a service on which the maintenance of critical activities depends.
  • Educational institutions with critical research activity.
  • Persons exercising public functions, and organisations providing administrative services electronically.
03

What follows after the assessment

Once the scope is clear, the work begins with an assessment of the current state against the requirements and with documenting the findings. The most common gap is not the absence of measures, but the absence of evidence that the measures have been adopted, applied and reviewed.

In practice this means: the scope is recorded and approved, the answers are supported by documents, the gaps have an owner and a deadline, and the result goes through a review by a second person. The platform supports exactly this sequence.

The information is a summary of public regulatory sources and supports discussion, but it is not legal advice and does not replace a review of the specific circumstances.

Legal basis for reference: the Cybersecurity Act, State Gazette No. 17 of 13 February 2026.

Next step

Check scope and assessment in one place.

In the demonstration we will determine scope, connect the evidence to the answers, and follow one gap through to the verified action.

Request a demo