All articles

Who does NIS2 actually apply to? A practical scope check for SMEs

6 min readNIS2ComplianceSecurity Operations

"Are we even in scope for NIS2?" is usually the first question we get, and it is often answered wrong in both directions. Some growing businesses assume they are exempt because they are not running a power grid or a telecom network. Others assume they are exempt because they are small — and then discover a larger customer has quietly made NIS2-equivalent security requirements a condition of the contract anyway.

Skip the legal text. Work through the four steps below in order — most readers will have a working answer by step 2, and everyone will have one by step 4.

Step 1 — Does your main activity match one of the listed sectors?

The directive lists sectors in two annexes. You do not need to read them — here they are in plain language, with the kind of business that typically sits in each.

Annex I — the higher-criticality sectors:

  • Energy: electricity, gas, oil, district heating and cooling, hydrogen
  • Transport: aviation, rail, shipping, road transport operators
  • Banking and financial-market infrastructure
  • Health: hospitals and care providers, pharmaceutical manufacturing, medical device manufacturers, EU reference laboratories
  • Drinking water and waste water utilities
  • Digital infrastructure: cloud providers, data centres, content delivery networks, internet exchange points, DNS providers, TLD registries, trust service providers, public telecom networks and services
  • ICT service management: managed service providers and managed security service providers — worth pausing on, since this is the category DRMX itself sits in
  • Public administration
  • Space

Annex II — the broader set of important sectors:

  • Postal and courier services
  • Waste management
  • Chemical manufacturing, production and distribution
  • Food production, processing and distribution
  • Manufacturing: medical devices and in-vitro diagnostics, computers/electronics/optics, electrical equipment, machinery, motor vehicles and trailers, other transport equipment
  • Digital providers: online marketplaces, online search engines, social networking platforms
  • Research organisations

If nothing above resembles what you actually do, go straight to Step 4 — sector and size won't put you in direct scope, but a customer contract still might.

If something matches, note whether it was an Annex I or Annex II sector and continue to Step 2.

Step 2 — Are you at least a medium-sized business?

Size is measured using the standard EU definition — broadly:

  • Small or micro (under 50 employees, and turnover and balance sheet total both under €10 million): generally outside direct scope, even in a listed sector.
  • Medium (50–249 employees, or turnover/balance sheet above €10 million but under the large-company thresholds): in scope if your sector matched in Step 1.
  • Large (250+ employees, or over €50 million turnover): in scope, and classified at the higher tier if in an Annex I sector.

Match your sector and size to get a first-pass answer:

Your sector Your size Likely classification
Annex I Large Essential entity
Annex I Medium Important entity (some can be designated essential due to systemic importance)
Annex II Medium or large Important entity
Either Small or micro Not in direct scope by size — check Steps 3 and 4 anyway

Step 3 — Are you one of the roles that's in scope regardless of size?

A short list of activities is in scope no matter how few people you employ: DNS providers, top-level domain registries, qualified trust service providers, and certain public electronic communications network or service providers. If that is literally what you do, size does not exempt you — go to your likely classification above based on sector alone.

Step 4 — Who are your biggest customers, and what do they operate?

This is the step that catches the most SMEs, including plenty who answered "no" to everything above. NIS2 requires essential and important entities to manage risk in their own supply chain. In practice, that requirement travels: it shows up as security questionnaires, MFA and patching evidence requests, and contract clauses aimed at their suppliers — regardless of whether those suppliers meet any legal threshold themselves.

If one or more of your largest customers operate in an Annex I or Annex II sector at medium size or above, treat yourself as indirectly obligated: you may have no registration duty, but you should expect to be asked to demonstrate the same operational controls, and it is worth getting ahead of that rather than reacting to the first questionnaire.

Your likely status, and what it means in practice

  • Essential entity — direct legal obligations, proactive supervision, registration required, the highest penalty band. Start with formal scoping and a compliance roadmap; this is not a "read the checklist and hope" situation.
  • Important entity — direct legal obligations, reactive (post-incident) supervision, registration required. Most 50–250 person SMEs that are in scope at all land here.
  • Indirectly obligated — no registration duty found in Steps 1–3, but a customer relationship that will demand the same controls in practice. Treat the operational requirements as real even though the legal label isn't.
  • Not currently in scope — none of the above applied. Worth re-checking if you grow past the size threshold, change activity, or take on a large regulated customer.

None of this replaces a proper scoping exercise — the size test in particular has enough nuance (group structures, connected enterprises, sector sub-definitions) that a self-check should narrow the question, not settle it. But it should tell you which of the four boxes to start from.

Belgium specifics

NIS2 was transposed into Belgian law by the Act of 26 April 2024, in force since 18 October 2024. The Centre for Cybersecurity Belgium (CCB) is the supervisory authority, and registration happens through the Safeonweb@work platform.

If your organisation was in scope from the start, registration was due by 18 March 2025 (18 December 2024 for digital-sector entities) — that window has passed, but it does not disappear: if you cross the threshold later, through growth or a change in activity, you register as soon as you are in scope. Essential entities were expected to complete a first conformity assessment by 18 April 2026, and those choosing certification under CyFun® or ISO/IEC 27001 face a further deadline of 18 April 2027.

Where this usually lands

Whether an organisation turns out to be an essential entity, an important entity, or simply a supplier that a regulated customer expects to behave like one, the operational answer converges on the same set of controls: identity and access management, patched and encrypted devices, tested backups, a workable incident process, and supplier oversight — the areas we walk through in our operational checklist for NIS2.

If Steps 1–4 above left you unsure which box you're in, a short scoping exercise is usually enough to settle it — a normal starting point before deciding what, if anything, needs to change.