NIS2 knowledge base

Am I a NIS2 entity? A first board-level assessment

NIS2 scope is determined by the statutory entity type, sector, size criteria and specific exceptions or designations. A broad industry label or customer relationship is a useful clue, but not the final legal conclusion.

Step 1: identify the statutory sector and entity type

Start with the annexes to the Dutch Cybersecurity Act. They list sectors and, within those sectors, specific types of entities. Healthcare providers, food manufacturers, selected manufacturers, transport entities, postal services and waste-management organisations are examples, each with its own statutory wording.

Describe what the legal entity actually does and match those activities with the wording of the Act. The commercial label used by the organisation may be broader or narrower than the legal category.

Step 2: assess size and category

For many entity types, employee numbers and financial thresholds influence whether the organisation is an essential or important entity. Apply the applicable enterprise rules carefully, especially within groups, partnerships and complex structures.

Record the data source, calculation date and conclusion. This turns a preliminary scope view into a traceable management decision.

Step 3: consider exceptions and designation

Some organisations fall within scope regardless of size, and public authorities or other entities may be designated under specific conditions. Sector legislation and the nature of the service can also affect the analysis.

Where the conclusion remains uncertain, obtain focused legal or sector-specific advice and set a review date. An open point can be managed well when ownership and follow-up are explicit.

Supplier requirements are a different route

Supplying an essential or important entity does not automatically make the supplier a NIS2 entity. Customers can, however, impose security, incident, continuity, evidence and audit requirements because their own supply-chain risk must be managed.

Keep the two questions separate: are we directly in statutory scope, and which requirements reach us through contracts and the operational chain?

Document the assessment at board level

The board should be able to see the activities assessed, relevant entity types, size calculation, exceptions, dependencies, conclusion and remaining assumptions. Review the assessment when activities, structure, size or legislation change.

Frequently asked questions

Does working for a NIS2 customer make us a NIS2 entity?

No. Direct scope follows from the Act. A customer can still pass relevant security and continuity requirements through the contract.

Can a small organisation be in scope?

Yes. Certain entity types and designations can apply regardless of the usual size rule, so the specific statutory route must be checked.

Who should approve the scope assessment?

Management should own and document the conclusion, supported by legal, compliance, security and sector expertise where needed.

Discuss scope and assumptions with the board

Training helps directors understand the scope assessment, separate statutory duties from customer requirements and record follow-up clearly.

Discuss the appropriate training route