Guide

Does NIS2 Apply to My Company? A Size-Cap and Sector Checklist for US Businesses With EU Operations

The Kopik team10 min read

NIS2 applies to your company if two things are true at the same time: your activity is one of the entity types listed in Annex I or Annex II of Directive (EU) 2022/2555, and you are at least a medium-sized enterprise under the EU SME definition, meaning roughly 50 or more staff or more than EUR 10 million in both turnover and balance sheet. Below that size you are generally out, unless you fall into one of the categories NIS2 covers regardless of size, such as DNS service providers, top-level domain registries, trust service providers or telecom providers. Here is the checklist, step by step, with the article references you will need to show your legal team.

Why a US company needs to run this test

NIS2 is an EU directive addressed to the Member States, which turn it into national law. Under Article 2(1), it covers entities of an Annex I or II type that meet the size cap "and which provide their services or carry out their activities within the Union." For a US-headquartered group, that usually means one of three situations: you own an EU subsidiary that operates in a covered sector; you sell a covered digital service (cloud, data center, managed IT, online marketplace) to EU customers without being established in the EU; or you are a supplier to EU companies that are in scope and will push NIS2 requirements down to you by contract.

The first two can make you directly subject to the rules. The third does not, but Article 21(2)(d) requires in-scope entities to address "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers", so expect questionnaires and contract clauses either way. The NIS2 knowledge base indexes the directive, its 2024 Implementing Regulation and the Commission's guidance, so you can check each step below against the source text.

Step 1: Is your activity listed in Annex I or Annex II?

The annexes define the sectors. Annex I covers the sectors of high criticality; Annex II covers other critical sectors. The Commission's Q&A summarizes them as follows.

NIS2 sectors (Directive (EU) 2022/2555, Annexes I and II)

Annex I: sectors of high criticalityAnnex II: other critical sectors
Energy (electricity, district heating and cooling, oil, gas, hydrogen)Postal and courier services
Transport (air, rail, water, road)Waste management
Banking and financial market infrastructuresManufacture, production and distribution of chemicals
Health, including manufacture of pharmaceutical productsProduction, processing and distribution of food
Drinking water and waste waterManufacturing: medical devices, computers and electronics, electrical equipment, machinery, motor vehicles, other transport equipment
Digital infrastructure (IXPs, DNS, TLD registries, cloud, data centers, CDNs, trust services, public electronic communications)Digital providers: online marketplaces, online search engines, social networking platforms
ICT service management, business-to-business (managed service providers, managed security service providers)Research organizations
Public administration and space

The annexes are more precise than this summary. Food, for instance, covers "food businesses which are engaged in wholesale distribution and industrial production and processing", and waste management excludes "undertakings for whom waste management is not their principal economic activity". Read the exact entry for your subsector before concluding.

Step 2: Apply the size cap correctly

NIS2 does not define company size itself. Article 2(1) points to Commission Recommendation 2003/361/EC, and only entities that "qualify as medium-sized enterprises" under it, "or exceed the ceilings for medium-sized enterprises", are covered by default. The thresholds in Article 2 of the Annex to that Recommendation are:

  • SME ceiling (upper limit of medium-sized): fewer than 250 persons, and annual turnover not exceeding EUR 50 million and/or annual balance sheet total not exceeding EUR 43 million.
  • Small enterprise: fewer than 50 persons, and annual turnover and/or annual balance sheet total not exceeding EUR 10 million.
  • Microenterprise: fewer than 10 persons, and annual turnover and/or annual balance sheet total not exceeding EUR 2 million.

Because of the "and/or", the financial test is passed if either the turnover or the balance-sheet figure stays under its ceiling. A company with 40 employees and EUR 8 million in turnover is therefore a small enterprise and, in principle, outside NIS2, even in an Annex I sector. The same company with 60 employees is medium-sized and in scope.

Three counting rules that change the answer

  1. Headcount is in annual work units. Article 5 of the Recommendation counts part-time and seasonal staff as fractions, and includes employees, owner-managers and partners active in the business. Apprentices and students on vocational training contracts are excluded.
  2. Group data is added. Under Article 6(2), the data of linked enterprises (for example, a parent holding a majority of voting rights) is added at 100%, and partner enterprises (a holding of 25% or more) are added in proportion. A 40-person EU subsidiary of a large US group can therefore be above the cap on paper.
  3. Status changes slowly. Under Article 4(2), crossing a ceiling only changes your category if it happens over two consecutive accounting periods.

The group-data rule has a NIS2 safety valve

Recital 16 of NIS2 lets Member States take into account the degree of independence of a subsidiary from its partner or linked enterprises, in particular in the network and information systems it uses and the services it provides. Where appropriate, they can treat it as below the cap if it would be on its own data alone. Whether your EU country uses this option is a national transposition question: check the national law, not just the directive.

One more detail: NIS2 switches off Article 3(4) of the Recommendation's Annex, the rule that a company 25% or more controlled by public bodies cannot be an SME. For NIS2, those companies are sized like any other.

Step 3: Check the entities covered regardless of size

Article 2(2) to (4) brings in entities that would otherwise be too small. If you are small but in one of these categories, the size cap does not help you:

  • providers of public electronic communications networks or publicly available electronic communications services;
  • trust service providers;
  • top-level domain name registries and DNS service providers;
  • entities providing domain name registration services (Article 2(4));
  • entities identified as critical entities under Directive (EU) 2022/2557 (the CER Directive);
  • entities a Member State identifies because they are the sole national provider of an essential service, or because a disruption could significantly affect public safety, security or health, create a significant systemic risk, or because they are critical at national or regional level;
  • certain public administration entities of central government, and some at regional level.

So a 30-person DNS resolution provider cannot rely on its size: Article 3(1)(b) makes "qualified trust service providers and top-level domain name registries as well as DNS service providers, regardless of their size" essential entities.

Step 4: Essential or important entity?

Once you are in scope, Article 3 sorts you into one of two categories. The obligations on cybersecurity measures (Article 21) and incident reporting (Article 23) are the same for both; what changes is supervision and the fine ceiling.

Default classification under Article 3

Your situationClassification
Annex I type, above the medium-sized ceilings (large)Essential
Qualified trust service provider, TLD registry, DNS service provider (any size)Essential
Public electronic communications provider that is medium-sizedEssential
Annex I type, medium-sizedImportant
Annex II type, medium-sized or largeImportant
Entity identified by a Member State under Article 2(2)(b) to (e)Essential or important, as the Member State decides

Essential entities are subject to the supervisory powers of Article 32, including on-site inspections, random checks and regular and targeted security audits. Important entities face ex post supervision under Article 33, triggered when the authority is "provided with evidence, indication or information" of non-compliance. Maximum fines differ too: Article 34 requires Member States to provide for at least EUR 10 million or 2% of total worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher in each case.

Step 5: Check sector-specific rules, jurisdiction and registration

Three last checks complete the picture for a US group:

  • Sector-specific EU law. Under Article 4, where another EU act imposes at least equivalent cybersecurity or reporting requirements, the matching NIS2 provisions do not apply. The Commission's 2023 guidelines list DORA, Regulation (EU) 2022/2554, as such an act for financial entities.
  • Which country supervises you. As a rule, the Member State where you are established. But DNS providers, cloud and data center providers, CDNs, managed service and managed security service providers, online marketplaces, search engines and social networks fall under the Member State of their main establishment in the EU (Article 26). If you offer those services in the EU without an establishment there, Article 26(3) requires you to designate a representative in one of the Member States where you offer services.
  • Registration. Member States had to establish a list of essential and important entities by 17 April 2025 (Article 3(3)). Entities provide at least their name, address, contact details including email addresses, IP ranges and telephone numbers, sector and subsector, and the Member States where they provide in-scope services, and must notify changes within two weeks.

Common mistakes, and what is still moving

  • Counting only the EU subsidiary's own staff without checking the linked-enterprise rule of Article 6(2) of the SME Recommendation.
  • Assuming "small" means out when the activity is DNS, a TLD registry, trust services or electronic communications.
  • Reading only the directive. The directive sets minimum rules; Article 5 lets Member States go further, and some Member States may also include local public administration or education institutions (Article 2(5)).
  • Assuming every country has transposed. The deadline was 17 October 2024 (Article 41). On 7 May 2025 the Commission sent reasoned opinions to 19 Member States for failing to notify full transposition, and its transposition page, as consulted on 2 October 2026, reports that on 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice. Check the national status on the Commission's transposition tracker before relying on a national law.

This article describes Directive (EU) 2022/2555 as adopted. Any proposal to amend it is outside the sources indexed in the base and is not the law until adopted, so do not plan around it. If you want to test edge cases, you can ask the base questions such as "A small manufacturer in an Annex I sector with 40 employees and EUR 8 million turnover: does NIS2 apply to it?" and get an answer with the citation.

Check your NIS2 scope against the official texts

Ask the NIS2 knowledge base about your sector, size and group structure and get answers citing the directive, the SME Recommendation and the Commission's guidance.

This article explains the rules; it is not legal advice. For a scope decision, read the directive on EUR-Lex and the national transposing law of each country where you operate.

Frequently asked questions

Does NIS2 apply to small businesses?

Generally not. Article 2(1) covers entities that are at least medium-sized under Recommendation 2003/361/EC. Small enterprises (fewer than 50 persons and turnover and/or balance sheet of EUR 10 million or less) are out, except for categories covered regardless of size, such as DNS service providers, TLD registries, trust service providers, electronic communications providers, domain name registration services, or entities a Member State specifically identifies.

What is the employee threshold for NIS2?

The medium-sized category starts at 50 persons and the SME category ends below 250. Headcount is measured in annual work units under Article 5 of the SME Recommendation, and the financial ceilings (EUR 10 million for small; EUR 50 million turnover and/or EUR 43 million balance sheet for medium) also matter.

Does NIS2 apply to US companies?

It applies to in-scope entities that provide their services or carry out their activities within the Union (Article 2(1)). A US company's EU subsidiary in a covered sector can be in scope. Certain digital service providers not established in the EU but offering services there must designate a representative in the EU under Article 26(3).

What is the difference between an essential and an important entity?

Both must implement the Article 21 measures and report significant incidents under Article 23. Essential entities are subject to the supervisory regime of Article 32, including regular audits, and fines of at least EUR 10 million or 2% of worldwide turnover; important entities face ex post supervision (Article 33) and fines of at least EUR 7 million or 1.4%.

Do parent company numbers count for the NIS2 size cap?

Under Article 6(2) of the SME Recommendation's Annex, linked enterprises' data is added at 100% and partner enterprises' data proportionally. Recital 16 of NIS2 lets Member States take a subsidiary's independence into account, so check how the relevant national law applies it.

Get the Kopik newsletter

New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.

By subscribing you agree to receive our newsletter. We never share your address.