NIS 2 Directive: which sectors are concerned?
Find out whether your organisation falls under the NIS 2 Directive and, if so, whether it is an essential or an important entity.
On 10 November 2022, Members of the European Parliament adopted the NIS 2 Directive (Network and Information Security 2), which aims to strengthen cybersecurity requirements for European companies. It builds on the NIS Directive, adopted six years earlier, which had not been enough to cope with the rise in cyberattacks across Europe. For a better understanding of the move from NIS to NIS 2, you can refer to this blog post.
One of the main changes concerns the scope of the entities covered by the new directive, which is much broader. Who falls under the NIS 2 Directive?
The organisations covered by NIS 2
ALocation of the organisation
According to Article 2 of the official text, the directive only concerns organisations that provide their services or carry out their activities within the EU. Each country is then responsible for the organisations providing a service or carrying out an activity on its territory. For example, the transposition of NIS 2 in Belgium, already adopted on 26 April 2024 and known as the Law establishing a framework for the cybersecurity of network and information systems of general interest for public security, only concerns Belgian companies.
BSize of the organisation
NIS 2 will apply to all organisations considered to be medium-sized or large enterprises within the meaning of Commission Recommendation 2003/361/EC of 6 May 2003.
Under this method, a company's size is assessed not only by its number of employees but also by its annual turnover. A medium-sized enterprise therefore meets at least one of the following two conditions:
- at least 50 full-time staff;
- at least €10 million in total annual turnover.
However, this size criterion will not be a necessary condition in two special cases. Regardless of their size, entities belonging to either of these two types of organisation will necessarily fall under NIS 2:
- digital infrastructure providing certain services (DNS services, top-level domain name registries, qualified trust services, public electronic communications networks, public electronic communications services, publicly available electronic communications services);
- public administration (central and regional government).
CServices provided
The European text lists in its annexes all the sectors to which the directive will apply. Annex I defines the “sectors of high criticality” and Annex II the “other critical sectors”:
- Energy electricity, district heating and cooling, oil, gas, hydrogen
- Transport air, rail, water, road
- Banking
- Financial market infrastructures
- Health
- Drinking water
- Waste water
- Digital infrastructure
- Public administration
- Space
- Postal and courier services
- Waste management
- Manufacture, production and distribution of chemicals
- Production, processing and distribution of food
- Manufacturing
- Digital providers
- Research
These three criteria therefore make it possible to determine whether an organisation will be subject to the European text. If you want to be sure whether or not your organisation falls under the directive, ANSSI has made an online simulator available to check.
A distinction between essential entities (EEs) and important entities (IEs)
Article 3 of the directive distinguishes between two types of regulated entities according to their level of criticality.
- Essential entities (EEs): large enterprises within the meaning of the Recommendation of 6 May 2003 (more than 250 employees and/or more than €50 million in turnover) that belong to the “sectors of high criticality” (defined above), as well as the two special cases of digital infrastructure and public administrations.
- Important entities (IEs): medium-sized enterprises within the meaning of the Recommendation of 6 May 2003 that belong to the “sectors of high criticality”, as well as medium-sized and large enterprises that belong to the “other critical sectors”.
- Location Met
- Size Met
- Services provided Met
ANSSI (the National Cybersecurity Agency of France) will use this distinction to adapt the requirements and make them proportionate to what is at stake for each of these two categories. It will also play a role in setting penalties, which will differ between the two categories. Penalties for essential entities will be more severe and may reach up to 2% of a company's turnover, compared with 1.4% for important entities.
A significant increase in the number of organisations concerned under the new directive
The directive brings about “a real change in terms of volume”. The previous NIS Directive only covered 7 sectors of activity, split between operators of essential services (OES) and digital service providers (DSPs). With the new distinction between essential and important entities, 18 sectors of activity will now be affected.
In France, there are thought to be around 600 types of entities, according to estimates by Yves Verhoeven, ANSSI's Deputy Director for Strategy. This could represent 10,000 different entities in total in France.
Around 600 different types of entities will be concerned, including administrations of all sizes and companies ranging from SMEs to CAC 40 groups.
Given this considerable scale, many organisations will have to prepare for the directive's entry into force in their own country. The text, already transposed in several countries (Croatia, Belgium and Hungary), must be transposed in every Member State of the European Union by October 2024. Even though the French law should a priori allow a period for achieving compliance, European companies must now anticipate and prepare for the implementation of this text to avoid the significant penalties it provides for.
Summary
Precise criteria
Three criteria must be met for the NIS 2 Directive to apply to an entity: operating in the EU, being a medium-sized enterprise (with some exceptions) and providing a service considered critical according to the directive's official list.
Two different types of entities
All entities covered by NIS 2 are divided into essential entities and important entities: a distinction that will lead to differentiated requirements and penalties.
A considerable scale
NIS 2 will lead to a drastic increase in the number of companies concerned compared with NIS, with up to 10,000 entities in France.
Sources (10)
- EUR-Lex — Directive (EU) 2022/2555 of the European Parliament and of the Council
- Phinasoft — From NIS to NIS 2
- Justel (fgov.be) — Justel database
- EUR-Lex — Recommendation 2003/361/EC (32003H0361)
- Grant Thornton — Enjeux et points clés de la directive NIS 2
- Orange Cyberdefense — Tout savoir sur les changements de la nouvelle directive NIS 2
- ANSSI — La directive NIS
- ANSSI — MonEspaceNIS2 : Suis-je concerné ?
- ANSSI — Directive NIS 2 : ce qui va changer pour les entreprises et l'administration françaises
- ANSSI — MonEspaceNIS2: home page
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.