Skip to content
All Blogs

There are two ways into NIS2 scope. Most organisations only check one.

Published
There are two ways into NIS2 scope. Most organisations only check one.
There are two ways into NIS2 scope. Most organisations only check one.
9:02


TL;DR

  • NIS2 scope is not just a sector-and-size question; supply chain obligations can pull you in even if the directive does not apply directly.
  • The EU deadline was 2024, but national laws, registration windows and enforcement activity are landing through 2025 and 2026.
  • Essential and important entities face the same Article 21 security obligations; the main difference is supervision model and maximum penalty.
  • Organisations selling into EU critical sectors should expect NIS2-driven contract clauses, questionnaires, and evidence requests from customers.
  • 6clicks helps teams confirm obligations, map Article 21 to existing controls, collect evidence continuously, and manage supplier risk in one place.

Why this is urgent

The EU deadline was 2024. The obligations that actually bind you only went live in 2025 and 2026, which is exactly why this is a 2026 problem.

 

17 October 2024 was the date Member States were supposed to have NIS2 in national law. Most missed it. NIS2 is a directive, so it creates no direct obligations until each country passes its own statute, and that has only happened recently:

 

  • The national laws are going live now. Germany's law took effect on 6 December 2025 with no transition period, its registration window running into 2026. Luxembourg transposed in May 2026. Roughly two-thirds of Member States now have laws in force, with more following through 2026. For most organisations, "the deadline" is a national go-live date in 2025–2026, not the 2024 EU date.
  • 2026 is when enforcement starts biting. The European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU in July 2026 for late transposition. Now that supervisory regimes are live, legal commentators describe 2026 as the year the first NIS2 enforcement actions begin. For essential entities, regulators can inspect and audit without waiting for an incident, fines can reach €10m or 2% of global turnover, and under Article 20, senior management is personally accountable.
  • The supply chain is already asking. In-scope organisations must manage supplier risk under Article 21(2)(d), so contract clauses, security questionnaires and evidence requests are landing on vendors right now, whether or not those vendors are directly in scope.
  • Compliance takes time to build. The ten Article 21 measures demand evidence they work in practice, continuously, and not a one-off document. Standing up controls, collecting evidence, and proving effectiveness is a multi-month program, so starting after your national law goes live, or after the first audit request, is already behind.

 

The first step is knowing whether, and how, NIS2 applies to you. The rest of this page walks you through it.

 

Step 1: Which Annex is your sector in?

Annex I. Sectors of high criticality Annex II. Other critical sectors

Energy (electricity, district heating and cooling, oil, gas, hydrogen)
Transport (air, rail, water, road)
Financial market infrastructures
Health
Drinking water
Waste water
Digital infrastructure
ICT service management (B2B)
Public administration
Space

 

 

 

Postal and courier services

Waste management

Banking
Chemicals (manufacture, production, distribution)

Food (production, processing, distribution)
Manufacturing (medical devices, electronics, electrical equipment, machinery, motor vehicles, other transport equipment)

Digital providers (online marketplaces, search engines, social platforms)

Research organisations


Note:
Not in either column? Go to Step 4. You may still be in scope.

Step 2: What size are you?

  Annex I sector Annex II sector
Large (250+ staff, or turnover above €50m and balance sheet above €43m) Essential entity Important entity
Medium (50 to 249 staff, or turnover above €10m) Important entity Important entity
Below medium Check Step 4 Check Step 4

Step 3: What the classification actually changes

 

  Essential Important
Supervision Proactive. Regulators can inspect and audit without an incident Reactive. Supervision follows evidence of non-compliance or an incident
Maximum fine €10m or 2% of global annual turnover, whichever is higher €7m or 1.4% of global annual turnover, whichever is higher
Security obligations Same ten measures under Article 21 Same ten measures under Article 21
Reporting obligations Same. Early warning at 24 hours, notification at 72 hours, final report at one month Same

 

Note: The obligations are identical. Only the supervision model and the penalty ceiling differ. Being classified as important is not a lighter compliance burden.

Step 4: In scope regardless of size

Size thresholds do not apply if any of these are true:

 

  • You provide public electronic communications networks or services
  • You are a trust service provider
  • You are a TLD name registry or DNS service provider
  • You are the sole provider in a Member State of a service essential to economic or societal activity
  • Disruption to your service could significantly affect public safety, security, or health
  • Disruption could cause significant systemic risk, particularly across borders
  • You are designated a critical entity under the CER Directive
  • You are a public administration entity

Step 5: The supply chain test

Not in scope directly? Your customers still are.

 

Article 21(2)(d) requires in-scope organisations to manage security risks in their supply chain and across supplier relationships. In practice, that obligation moves down the chain as contract clauses, security questionnaires, and evidence requests.

 

If you sell into energy, health, transport, public administration, or digital infrastructure in the EU, NIS2 will reach you through procurement whether or not it reaches you through the annexes.

Step 6: Where your obligations actually come from

NIS2 is a directive, not a regulation. It takes effect through each Member State's national law, and transposition has been uneven. Your specific thresholds, registration deadlines, and reporting channels are set by the country you operate in, not by the directive text.

 

Operating across several Member States means several sets of national rules.


Scope tells you whether the obligations apply. Article 21 tells you what they are. Ten security measures, each requiring evidence that they work in practice, with management personally accountable for approving and overseeing them under Article 20. See how the ten Article 21 measures map to ISO 27001 controls you may already have.


How 6clicks helps you get NIS2-ready

Scope is step one. 6clicks runs the rest. Once you know whether you are an essential entity, an important entity, or pulled in through the supply chain, the work is proving you meet the ten Article 21 measures, and keeping that evidence current. 6clicks brings scoping, controls, evidence, and reporting in one place.

 

What NIS2 asks for How 6clicks helps
Confirm your classification and obligations Built-in Content Library with NIS2 mapped alongside ISO 27001, DORA, CMMC and more, so you assess once and reuse across frameworks
Implement the ten Article 21 security measures Prebuilt control sets and dedicated registers to assign owners, track implementation and close gaps against Article 21
Show the measures work in practice 6clicks iGRC (Intelligent GRC) moves you from point-in-time compliance to continuous assurance: automated evidence collection through no-code integrations, an evidence register with freshness alerts that flag stale evidence before an audit does, and Hailey AI validating evidence against each test and reasoning across linked controls, assets, and frameworks via the GRC Knowledge Graph, with management oversight and visibility through configurable dashboards for Article 20 accountability
Meet 24h / 72h / 1 month reporting deadlines Incident management workflows to log, triage, and report within statutory timeframes
Manage supply chain risk (Art. 21(2)(d)) Centralized third-party register with vendor assessments and security scanning to push and evidence requirements down the chain
Operate across several Member States Sovereign GRC infrastructure that runs where your data lives, with reusable assessments across entities and regions

 

See how 6clicks maps the ten Article 21 measures to controls you may already have. 
Speak with our team.
Ready to transform GRC with 6clicks?

Let’s show you how it works for your team.

awards-mobile-v3