NIS 2 Directive: which sectors are concerned?

Find out whether your organisation falls under the NIS 2 Directive and, if so, whether it is an essential or an important entity.

Clément Rose · 7 min read
Illustration: a miniature city of sector buildings connected to a shield
DOES NIS 2 APPLY TO ME? 3 CRITERIA
Location within the EU
Size medium or large
Services listed sector
Organisation in scope ESSENTIAL or IMPORTANT

On 10 November 2022, Members of the European Parliament adopted the NIS 2 Directive (Network and Information Security 2), which aims to strengthen cybersecurity requirements for European companies. It builds on the NIS Directive, adopted six years earlier, which had not been enough to cope with the rise in cyberattacks across Europe. For a better understanding of the move from NIS to NIS 2, you can refer to this blog post.

One of the main changes concerns the scope of the entities covered by the new directive, which is much broader. Who falls under the NIS 2 Directive?

01

The organisations covered by NIS 2

THREE CRITERIA TO MEET LOCATION · SIZE · SERVICES PROVIDED
A · LOCATION MET
Services provided in the EU
OR
Activities carried out in the EU
Within the European Union
B · SIZE MET
Headcount≥ 50 staff
Turnover≥ €10M
at least one of the two thresholds
Medium-sized or large enterprise
C · SERVICES MET
Energy ANNEX I
Health ANNEX I
Research ANNEX II
Sector listed in an annex
The organisation falls under NIS 2 THEN CLASSIFIED AS ESSENTIAL ENTITY IMPORTANT ENTITY

ALocation of the organisation

According to Article 2 of the official text, the directive only concerns organisations that provide their services or carry out their activities within the EU. Each country is then responsible for the organisations providing a service or carrying out an activity on its territory. For example, the transposition of NIS 2 in Belgium, already adopted on 26 April 2024 and known as the Law establishing a framework for the cybersecurity of network and information systems of general interest for public security, only concerns Belgian companies.

BSize of the organisation

NIS 2 will apply to all organisations considered to be medium-sized or large enterprises within the meaning of Commission Recommendation 2003/361/EC of 6 May 2003.

Under this method, a company's size is assessed not only by its number of employees but also by its annual turnover. A medium-sized enterprise therefore meets at least one of the following two conditions:

  • at least 50 full-time staff;
  • at least €10 million in total annual turnover.

However, this size criterion will not be a necessary condition in two special cases. Regardless of their size, entities belonging to either of these two types of organisation will necessarily fall under NIS 2:

  • digital infrastructure providing certain services (DNS services, top-level domain name registries, qualified trust services, public electronic communications networks, public electronic communications services, publicly available electronic communications services);
  • public administration (central and regional government).

CServices provided

The European text lists in its annexes all the sectors to which the directive will apply. Annex I defines the “sectors of high criticality” and Annex II the “other critical sectors”:

ANNEX I
Sectors of high criticality
  • Energy electricity, district heating and cooling, oil, gas, hydrogen
  • Transport air, rail, water, road
  • Banking
  • Financial market infrastructures
  • Health
  • Drinking water
  • Waste water
  • Digital infrastructure
  • Public administration
  • Space
ANNEX II
Other critical sectors
  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing
  • Digital providers
  • Research

These three criteria therefore make it possible to determine whether an organisation will be subject to the European text. If you want to be sure whether or not your organisation falls under the directive, ANSSI has made an online simulator available to check.

02

A distinction between essential entities (EEs) and important entities (IEs)

Article 3 of the directive distinguishes between two types of regulated entities according to their level of criticality.

  • Essential entities (EEs): large enterprises within the meaning of the Recommendation of 6 May 2003 (more than 250 employees and/or more than €50 million in turnover) that belong to the “sectors of high criticality” (defined above), as well as the two special cases of digital infrastructure and public administrations.
  • Important entities (IEs): medium-sized enterprises within the meaning of the Recommendation of 6 May 2003 that belong to the “sectors of high criticality”, as well as medium-sized and large enterprises that belong to the “other critical sectors”.
Does NIS 2 apply to me? INDICATIVE
Do you provide your services or carry out your activities in the EU?
Do you fall under one of the two special cases?
Which sector do you operate in?
What size is your organisation?
RESULT
Essential entity
Large enterprise in a sector of high criticality (Annex I).
  • Location Met
  • Size Met
  • Services provided Met
PENALTIES Up to 2% of turnover
Indicative tool: it only applies the criteria and thresholds cited in this article (Article 3 of the directive, Recommendation 2003/361/EC). To check your organisation's situation, use ANSSI's simulator.

ANSSI (the National Cybersecurity Agency of France) will use this distinction to adapt the requirements and make them proportionate to what is at stake for each of these two categories. It will also play a role in setting penalties, which will differ between the two categories. Penalties for essential entities will be more severe and may reach up to 2% of a company's turnover, compared with 1.4% for important entities.

03

A significant increase in the number of organisations concerned under the new directive

The directive brings about “a real change in terms of volume”. The previous NIS Directive only covered 7 sectors of activity, split between operators of essential services (OES) and digital service providers (DSPs). With the new distinction between essential and important entities, 18 sectors of activity will now be affected.

In France, there are thought to be around 600 types of entities, according to estimates by Yves Verhoeven, ANSSI's Deputy Director for Strategy. This could represent 10,000 different entities in total in France.

A CHANGE OF SCALE SECTORS OF ACTIVITY CONCERNED
NIS 7 sectors · OES and DSPs
NIS 2 18 sectors · EEs and IEs
sectors of activity affected by NIS 2, compared with 7 under NIS
types of entities in France, according to ANSSI
different entities in total in France, according to MonEspaceNIS2

Around 600 different types of entities will be concerned, including administrations of all sizes and companies ranging from SMEs to CAC 40 groups.

Yves Verhoeven Deputy Director for Strategy, ANSSI

Given this considerable scale, many organisations will have to prepare for the directive's entry into force in their own country. The text, already transposed in several countries (Croatia, Belgium and Hungary), must be transposed in every Member State of the European Union by October 2024. Even though the French law should a priori allow a period for achieving compliance, European companies must now anticipate and prepare for the implementation of this text to avoid the significant penalties it provides for.

Summary

01

Precise criteria

Three criteria must be met for the NIS 2 Directive to apply to an entity: operating in the EU, being a medium-sized enterprise (with some exceptions) and providing a service considered critical according to the directive's official list.

02

Two different types of entities

All entities covered by NIS 2 are divided into essential entities and important entities: a distinction that will lead to differentiated requirements and penalties.

03

A considerable scale

NIS 2 will lead to a drastic increase in the number of companies concerned compared with NIS, with up to 10,000 entities in France.

Written by Clément Rose Phinasoft

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.