
Someone in your legal team forwarded you an email with "NIS2" in the subject line, you skimmed it for four seconds, and now it's sitting in a folder labeled "deal with later." I get it. Regulation reading is nobody's idea of a fun Tuesday.
But here's the thing. NIS2 isn't one of those directives you can quietly ignore until it goes away. It doesn't go away. It's the EU's biggest cybersecurity shake-up since 2016, and it's already reshaping how tens of thousands of companies across Europe think about risk, incident response, and who picks up the phone when something breaks at 2am.
So let's cut through the legal fog. In this piece, I'm going to walk you through exactly who must comply with the NIS2 cybersecurity regulation, who's exempt, and how to figure out, quickly, which camp you're in. No jargon. No 40-page PDFs. Just the stuff you actually need to know.
NIS2, short for the second Network and Information Security Directive (that's Directive (EU) 2022/2555 if you want to sound clever in a boardroom), is the European Union's answer to a simple but uncomfortable question: what happens when a hospital, a power grid, or a bank gets hacked?
The answer, historically, has been "not enough." The original NIS Directive from 2016 tried to fix this, but it had gaps you could drive a truck through. Inconsistent enforcement. Vague scope. Countries interpreting the rules however they liked.
NIS2 closes those gaps. It widens the net, sharpens the teeth, and puts actual consequences behind non-compliance. Think of it as GDPR's tougher, less forgiving cousin, except this one cares about your servers instead of your cookie banners.
Here's where most people get tripped up. NIS2 doesn't just apply to power plants and government agencies anymore. It's expanded to cover an estimated 160,000+ entities across the EU, up from roughly 10,000 under the original directive. That's not a typo. That's a fifteen-fold jump.
The directive sorts organizations into two buckets: essential entities and important entities. Both are in scope. Both have obligations. The difference mostly comes down to how strictly they're supervised and how big the fines can get if things go sideways.
Think of it like a nightclub with two lines. Everyone gets in, but the essential entities are the VIPs, watched more closely, checked more often, and treated with a lot less patience if they misbehave.
Both categories face real obligations. Neither gets to shrug and say "we're only important, not essential, so we're fine." That's not how this works.
If you're wondering whether your industry made the list, here's the short version. NIS2 covers 18 sectors total, roughly double what the original directive covered.
High-criticality sectors (typically essential entities):
Other critical sectors (typically important entities):
If you spotted your industry up there, congratulations (or condolences, depending on how prepared you are). If you didn't, don't relax just yet. Keep reading, because scope isn't only about industry.
This is probably the question keeping most SME founders up at night, so let's tackle it head-on.
The general rule is that NIS2 applies to medium and large organizations in the sectors listed above. Specifically, that means companies with:
If you're a genuinely small operation, say, ten people running a niche logistics tool out of a co-working space in Lisbon, you're likely exempt from NIS2's direct obligations.
But (and this is a big but), there's a catch. NIS2 also drags in smaller companies through a side door: supply chain requirements. If you're a tiny vendor supplying software, hardware, or services to a large essential or important entity, that bigger company is now required to vet your security practices as part of its own compliance. So even if NIS2 doesn't technically apply to you directly, your biggest client might start asking you uncomfortable questions about your firewall setup.
There are also exceptions to the exception. Some sectors, like DNS providers, trust service providers, and certain telecom operators, are in scope regardless of size, because the risk they pose is considered too critical to leave to a headcount threshold.
I like simple tests, so here's one. Ask yourself these four questions:
If you answered yes to even one of these, it's worth having a proper conversation with your compliance or IT security lead. Sooner rather than later.
Once you're confirmed as in scope, NIS2 asks for a handful of concrete things. I won't drown you in Article 21 legalese, but here's the gist:
And the penalties aren't symbolic. Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher. That's GDPR-level money, and regulators across the EU are already signaling they intend to use it.
People often lump these two together, and while they're cousins in spirit, they're not the same animal.
If you're already GDPR-compliant, you have a head start, but NIS2 is not just GDPR with a new coat of paint. It's a separate obligation with its own teeth.
Does NIS2 apply to small businesses? Generally, no, unless you're in a handful of high-risk categories like DNS or trust services, or you supply a larger company that is in scope. Size thresholds exist, but they're not a guaranteed shield.
What's the real difference between essential and important entities? Mostly the level of regulatory oversight. Essential entities get checked proactively and regularly. Important entities tend to get checked only after something goes wrong. Both face real obligations either way.
Can my company be in scope even if I'm not in one of the 18 sectors? It's uncommon, but it can happen indirectly through supply chain requirements if a large customer needs you to meet certain security standards to keep doing business with them.
Is compliance optional if I think the fines won't apply to me? I wouldn't bet on that. Regulators across the EU are actively enforcing NIS2 in 2026, and "we didn't think it applied to us" isn't holding up well as a legal defense.
Here's the honest truth. NIS2 isn't designed to punish businesses for existing. It's designed to make sure that when something goes wrong (and eventually, something always does), the fallout doesn't spiral into a continent-wide mess. If you run critical infrastructure, handle sensitive services, or even just supply someone who does, this regulation has your name on it somewhere.
The smartest move isn't to panic. It's to get clarity. Figure out where you stand, map your obligations, and build a plan before a regulator, or worse, a breach, forces your hand.
So, where do you land? If you're still unsure whether NIS2 applies to your business, don't leave it to guesswork. Talk to your compliance lead, run the self-check above, and start the conversation this week, not after the next headline about a fine makes you wish you had.





