NIS2 for small companies: are you actually in scope?
NIS2 (Directive (EU) 2022/2555) applies to organizations in its Annex I and Annex II sectors that are at least medium sized, which usually means 50 or more staff, or annual turnover and balance sheet total both above EUR 10 million. Size is not the whole test: providers of public electronic communications networks and services, trust service providers, TLD name registries and DNS service providers are in scope at any size, and member states can designate individual entities or widen the sector list beyond the directive minimum. The directive does not bind you directly. Your national transposition does, and it decides your register, your regulator, who receives an incident report and what the penalties look like. Essential and important entities work from the same article 21 security measures; the difference is that essential entities face proactive supervision while important entities are supervised after something goes wrong. Article 20 also puts a personal duty on management bodies to approve the risk management measures, oversee them, and take training.
Short answer: NIS2 reaches you if you operate in one of its listed sectors and you are at least a medium sized company, which in practice means 50 or more staff. There is a second door in, and it is the one that catches small teams: a few categories are in scope at any size, including a two person internet provider. And the part almost everyone gets wrong at first is that the directive itself does not bind you. Your country's version of it does, and those national laws differ on deadlines, registers and regulators.
That last point is why generic NIS2 advice tends to fall apart right at the moment it would become useful. Here is the scope test, in the order we would run it.
The directive is not the law you have to follow
NIS2 is Directive (EU) 2022/2555. A directive tells member states what to legislate. It is not something you comply with directly. Every EU country writes its own transposition, and that national act is what a regulator enforces against you. The transposition deadline set in the directive has already passed, and countries have moved at very different speeds since.
For a small company that means three practical things:
- The security measures are close to identical everywhere, because they all come from article 21 of the directive.
- Everything procedural is national: which register you file with, who your regulator is, which authority receives an incident report, what the penalty ceilings are.
- Several countries widened the sector list beyond the directive minimum, so "we read the EU annexes and we are out" is not a complete answer.
Start with your own country's act. If you cannot find it, that is itself useful information about how far along your member state is.
The two part scope test
Part one: your sector
NIS2 sorts in scope organizations across two annexes. Annex I holds sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (business to business), public administration and space. Annex II holds other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing of certain products, digital providers and research.
Two entries catch far more software companies than founders expect. Digital infrastructure includes cloud computing service providers, data centre service providers, content delivery networks, DNS service providers and TLD name registries. ICT service management covers managed service providers and managed security service providers. If you run infrastructure for other businesses, read those definitions properly instead of assuming they only mean hyperscalers.
Part two: your size
If you are in a listed sector, size decides whether you are caught. NIS2 borrows the EU definition of a medium sized enterprise, so the working reading is 50 or more staff, or annual turnover and balance sheet total both above EUR 10 million. Below that, you are generally out.
Generally. Which brings us to the part that matters most for the people who read this blog.
The exceptions that put tiny companies in scope
Size is not the whole test. Some organizations are in scope no matter how small they are, and the directive names them:
- providers of public electronic communications networks, or of publicly available electronic communications services
- trust service providers
- TLD name registries and DNS service providers
A one person internet service provider is in scope. So is a two person trust service provider. There is no size floor for these.
Beyond that named list, a member state can pull you in individually: if you are the sole provider in that country of a service essential for critical societal or economic activity, if disruption of your service could significantly affect public safety, security or health, or if you are judged critical because of your specific importance at national or regional level. Public administration entities are handled separately by each country.
So the honest version of the size rule is this. Below the threshold you are probably out, unless you sit in one of the named any size categories, or your national law reaches further than the directive minimum.
Ready to Streamline Your Compliance?
Discover how AuditBadger can simplify your compliance management process.
Essential or important: what actually changes?
In scope organizations get sorted into essential entities and important entities, mostly by sector and size. It is worth being precise about what that distinction does.
It barely changes your security obligations. Both classes work from the same article 21 measures.
What it changes is supervision. Essential entities face proactive oversight, meaning a regulator can inspect and audit before anything has gone wrong. Important entities face reactive oversight, meaning attention arrives after an incident or after a credible signal that you are not compliant. Maximum fines also differ between the two classes, with the ceilings set in national law.
If you land in the important category rather than essential, the work is the same. The difference is who knocks, and when.
What to do this week if you think you are in scope
- Find your national act, not the directive. Deadlines, registration duties and the reporting authority all live there.
- Check the registration duty first. Several categories of digital provider have to register with a national authority, and registration is a separate obligation from the security measures. It also tends to be the one with a hard date attached.
- Read article 21 once, properly. Ten measure areas: risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development and maintenance including vulnerability handling, procedures to assess whether your measures actually work, cyber hygiene and training, cryptography, human resources security with access control and asset management, and multi factor authentication with secured communications where appropriate.
- Note the management duty. Article 20 puts the obligation on management bodies to approve the risk management measures and oversee their implementation, and requires them to take training. That is a named person, not a department.
- Inventory what you already have. If you have done ISO 27001 Annex A work, a large share of article 21 is already sitting in your ISMS under different names.
That last point deserves its own post, and it has one coming in this series.
Where we are on NIS2, honestly
We build compliance tooling for small teams, so the useful thing we can tell you is exactly what we support rather than a marketing claim.
Our NIS2 support is early access, switched on per account after a conversation. We started with the Polish transposition, because that is where our first design partners are, and we built it in Polish. The measure catalog is statute general, so it fits any organization working from article 21. The scope classifier is not: it currently encodes the Polish rules for electronic communications providers, which means it answers well for a Polish ISP and does not answer for a Polish manufacturer.
We would rather say that plainly than let you discover it after signing up. If you need another country modelled, tell us which one and you will get a real answer about timing instead of a maybe.
Our own route here was ISO first. We certified AuditBadger using AuditBadger, SOC 2® Type II, with no external consultants, and the ISMS underneath that is what makes an article 21 conversation short. If you are earlier than that, the lean version of governance, risk and compliance is a better first read than any directive. And if you are still deciding which framework to put first, SOC 2 or ISO 27001 is the fork most small teams hit long before NIS2 becomes their problem.
More on the ten measures, the reporting clocks and what carries over from ISO on our NIS2 page.
Frequently asked questions
Does NIS2 apply to small companies with fewer than 50 employees? +
NIS2 generally excludes companies below 50 employees, but critical exceptions exist. DNS service providers, trust service providers, TLD name registries, and public electronic communications providers are in scope at any size—even a two-person internet service provider must comply. Additionally, member states can designate any company as essential regardless of size if it's the sole provider of a critical service in that country.
What sectors are covered under NIS2 directive scope? +
NIS2 covers high-criticality sectors (Annex I) including energy, transport, banking, health, digital infrastructure, and ICT service management, plus other critical sectors (Annex II) like postal services, waste management, chemicals, food, and digital providers. Cloud computing providers, data centre operators, managed service providers (MSPs), and managed security service providers (MSSPs) are specifically included, catching many more software companies than expected.
How does AuditBadger help with NIS2 compliance for small teams? +
AuditBadger's AI-assisted GRC platform helps small teams prepare for NIS2 security requirements by managing controls, evidence, policies, risks, vendors, and incidents in one organized workspace. Since NIS2 security measures align closely with ISO 27001 and SOC 2 frameworks, AuditBadger's existing compliance workflows, AI-powered policy drafting, and evidence tracking support NIS2 readiness for just $250/month with unlimited users.
What's the difference between the NIS2 directive and national transposition laws? +
The NIS2 directive (EU 2022/2555) itself is not directly enforceable—it tells member states what to legislate. Each EU country writes its own national transposition law that you must actually comply with, and these national laws differ on registers, regulators, incident reporting authorities, and penalty structures. While security measures from Article 21 remain similar across countries, all procedural requirements are determined by your specific country's version of the law.
Can managed service providers and MSPs be in scope for NIS2 at any size? +
Managed service providers (MSPs) and managed security service providers (MSSPs) fall under ICT service management in Annex I, so they're typically in scope if they meet the medium-size threshold (50+ employees or €10M+ turnover). However, a member state can designate even a small MSP as essential if it's the sole critical provider in that country, and some national transpositions have widened the sector definitions beyond the EU minimum.