Step 1: identify the statutory sector and entity type
Start with the annexes to the Dutch Cybersecurity Act. They list sectors and, within those sectors, specific types of entities. Healthcare providers, food manufacturers, selected manufacturers, transport entities, postal services and waste-management organisations are examples, each with its own statutory wording.
Describe what the legal entity actually does and match those activities with the wording of the Act. The commercial label used by the organisation may be broader or narrower than the legal category.
Step 2: assess size and category
For many entity types, employee numbers and financial thresholds influence whether the organisation is an essential or important entity. Apply the applicable enterprise rules carefully, especially within groups, partnerships and complex structures.
Record the data source, calculation date and conclusion. This turns a preliminary scope view into a traceable management decision.
Step 3: consider exceptions and designation
Some organisations fall within scope regardless of size, and public authorities or other entities may be designated under specific conditions. Sector legislation and the nature of the service can also affect the analysis.
Where the conclusion remains uncertain, obtain focused legal or sector-specific advice and set a review date. An open point can be managed well when ownership and follow-up are explicit.
Supplier requirements are a different route
Supplying an essential or important entity does not automatically make the supplier a NIS2 entity. Customers can, however, impose security, incident, continuity, evidence and audit requirements because their own supply-chain risk must be managed.
Keep the two questions separate: are we directly in statutory scope, and which requirements reach us through contracts and the operational chain?
Document the assessment at board level
The board should be able to see the activities assessed, relevant entity types, size calculation, exceptions, dependencies, conclusion and remaining assumptions. Review the assessment when activities, structure, size or legislation change.
Frequently asked questions
Does working for a NIS2 customer make us a NIS2 entity?
No. Direct scope follows from the Act. A customer can still pass relevant security and continuity requirements through the contract.
Can a small organisation be in scope?
Yes. Certain entity types and designations can apply regardless of the usual size rule, so the specific statutory route must be checked.
Who should approve the scope assessment?
Management should own and document the conclusion, supported by legal, compliance, security and sector expertise where needed.
Discuss scope and assumptions with the board
Training helps directors understand the scope assessment, separate statutory duties from customer requirements and record follow-up clearly.
Discuss the appropriate training route