Guide

Does NIS2 Apply to My Organisation? A Scope Checklist for UK Businesses Serving the EU

The Kopik team9 min read

NIS2 is an EU directive, so it does not govern a UK business's domestic activity. It can still apply to your organisation if you provide services or carry out activities within the EU in one of the sectors listed in Annex I or II of Directive (EU) 2022/2555 and you are at least medium-sized under the EU SME definition (in short, 50 or more staff, or turnover and balance sheet both above EUR 10 million). Some digital providers are caught regardless of size, and certain UK-based digital service providers with no EU establishment must appoint an EU representative. This checklist walks through each test with the article references.

First, what NIS2 is (and is not) for a UK organisation

Directive (EU) 2022/2555 is addressed to the EU Member States (Article 46), which transpose it into national law. It replaces the original NIS Directive, (EU) 2016/1148, repealed with effect from 18 October 2024 (Article 44). This article covers the EU regime only: UK domestic cyber-security rules are not among the sources indexed in the NIS2 knowledge base, so nothing here should be read as a statement about UK law.

For a UK group, the EU regime typically bites in three ways: through an EU subsidiary or branch operating in a covered sector; through digital services offered into the EU from the UK (cloud, data centre, managed IT, online marketplace and similar services); or indirectly, as a supplier to EU organisations that are in scope. The last case does not make you a regulated entity, but Article 21(2)(d) obliges in-scope entities to manage supply chain security, "including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers", so the requirements will reach you through contracts.

Test 1: Are you in an Annex I or Annex II sector?

The Commission's Q&A on the directive groups the sectors into two lists. In short:

  • Annex I, sectors of high criticality: energy (electricity, district heating and cooling, oil, gas and hydrogen); transport (air, rail, water and road); banking; financial market infrastructures; health, including the manufacture of pharmaceutical products; drinking water; waste water; digital infrastructure (internet exchange points, DNS service providers, TLD name registries, cloud computing, data centre services, content delivery networks, trust services, public electronic communications); ICT service management, business-to-business (managed service providers and managed security service providers); public administration; and space.
  • Annex II, other critical sectors: postal and courier services; waste management; chemicals; food; manufacturing of medical devices, computers and electronics, electrical equipment, machinery and equipment, motor vehicles, trailers and semi-trailers and other transport equipment; digital providers (online marketplaces, online search engines, social networking platforms); and research organisations.

Read the precise annex wording for your subsector. Food, for example, is limited to "food businesses which are engaged in wholesale distribution and industrial production and processing", and the annexes exclude businesses for which some activities, such as waste management, are "not their principal economic activity".

Test 2: Are you at least medium-sized?

Article 2(1) borrows the size categories of Commission Recommendation 2003/361/EC. The ceilings, from Article 2 of its Annex:

EU enterprise size categories (Recommendation 2003/361/EC)

CategoryStaff headcountTurnover and/or balance sheet total
MicroFewer than 10Not exceeding EUR 2 million
SmallFewer than 50Not exceeding EUR 10 million
Medium (upper SME ceiling)Fewer than 250Turnover not exceeding EUR 50 million and/or balance sheet not exceeding EUR 43 million

NIS2 covers entities that qualify as medium-sized "or exceed the ceilings for medium-sized enterprises". Small and micro enterprises are out by default. Note the "and/or": the financial condition is satisfied if either the turnover or the balance sheet figure is within the ceiling.

How to count, especially within a group

  1. Annual work units. Article 5 of the Recommendation counts part-time and seasonal workers as fractions; apprentices and students on vocational training contracts are not counted, nor is maternity or parental leave.
  2. Latest approved accounts. Article 4(1) uses the figures of the latest approved accounting period, with turnover calculated excluding VAT and other indirect taxes.
  3. Linked and partner enterprises. Under Article 6(2), 100% of the data of linked enterprises (for example, a parent holding a majority of the voting rights) is added, and the data of partner enterprises (25% or more holdings) is added pro rata. A small EU subsidiary of a large UK group may therefore exceed the ceilings on group figures.
  4. Two-year buffer. Article 4(2): crossing a ceiling only changes your status if it happens over two consecutive accounting periods.

Group subsidiaries: the independence option

Recital 16 of NIS2 allows Member States to take into account how independent an entity is from its partner or linked enterprises, notably in terms of the network and information systems it uses and the services it provides. Where appropriate, they may treat it as below the size cap if its own data alone would put it there. Whether and how this is used depends on the national transposing law of the Member State concerned.

Test 3: Are you caught regardless of size?

Article 2(2) to (4) sets aside the size cap for several categories. The most relevant for UK technology and telecoms businesses are:

  • providers of public electronic communications networks or publicly available electronic communications services;
  • trust service providers;
  • top-level domain name registries and DNS service providers;
  • entities providing domain name registration services;
  • entities a Member State identifies as the sole provider of an essential service, or whose disruption could significantly affect public safety, public security or public health, or induce significant systemic risk, or which are critical at national or regional level;
  • entities identified as critical entities under the Critical Entities Resilience Directive, (EU) 2022/2557.

A 30-person DNS provider is therefore not exempt: under Article 3(1)(b), qualified trust service providers, TLD name registries and DNS service providers are essential entities "regardless of their size".

Test 4: Essential or important, and who supervises you

Under Article 3(1), essential entities include Annex I entities that exceed the medium-sized ceilings, the size-independent digital infrastructure providers above, medium-sized public electronic communications providers, central government bodies and entities identified by Member States. Every other in-scope Annex I or II entity is an important entity (Article 3(2)). In practice: a large Annex I entity is essential; a medium-sized Annex I entity or any Annex II entity is important unless a Member State designates otherwise.

The security duties (Article 21) and incident reporting duties (Article 23) apply to both. The difference lies in supervision (the full set of Article 32 powers, including regular audits and random checks, for essential entities; ex post measures under Article 33 for important entities) and in fines: Member States must provide maximum fines of at least EUR 10 million or 2% of total worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher (Article 34).

The EU representative rule for UK-based digital providers

For DNS service providers, TLD registries, domain registration services, cloud computing and data centre providers, CDNs, managed service and managed security service providers, online marketplaces, search engines and social networks, jurisdiction follows the main establishment in the Union (Article 26(1)(b)). If such a provider is not established in the EU but offers services there, Article 26(3) requires it to designate a representative established in one of the Member States where it offers services; it then falls under that Member State's jurisdiction. Without a representative, any Member State where it provides services may take legal action against it.

Recital 116 explains when a non-EU provider is "offering services within the Union". Mere accessibility of a website or email address is not enough, but factors such as using a language or currency generally used in one or more Member States with the possibility of ordering services in that language, or mentioning customers or users in the EU, can make the intention apparent.

Test 5: Registration, sector rules and national status

  • Registration. Member States had to establish a list of essential and important entities by 17 April 2025 (Article 3(3)). The Commission's guidelines on Article 3(4) list the minimum data: name, address and up-to-date contact details including email addresses, IP ranges and telephone numbers, sector and subsector, and the Member States where in-scope services are provided. Changes must be notified within two weeks.
  • Digital providers' registry. The Article 27 categories also had to submit their main establishment, other EU establishments or EU representative, and IP ranges by 17 January 2025, and must report changes within three months.
  • Sector-specific EU acts. Under Article 4, an EU act with at least equivalent requirements displaces the matching NIS2 provisions. The Commission's 2023 guidelines name DORA for financial entities.
  • Transposition status. Member States had to transpose by 17 October 2024 (Article 41). The Commission sent reasoned opinions to 19 Member States on 7 May 2025, and its transposition page, as consulted on 2 October 2026, reports the referral of Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026. Check the Commission's tracker for the countries you serve.

This guide describes the directive as adopted in 2022. Proposals to amend NIS2 fall outside the base's sources and are not law unless and until adopted. To test your own facts, you can put questions to the base such as "We're a small DNS resolution provider with only 30 employees: can we really be exempt from NIS2 because of our size?" and receive an answer with the cited passage.

Test your NIS2 scope against the source texts

Ask the NIS2 knowledge base about your sector, size, group structure or EU representative duty, with answers citing the directive and the Commission's guidance.

This is an explanation of the EU rules, not legal advice. The authoritative text is Directive (EU) 2022/2555 on EUR-Lex, read together with the national law of each Member State concerned.

Frequently asked questions

Does NIS2 apply to UK companies?

NIS2 is EU law addressed to the Member States. It can reach UK groups through EU subsidiaries in covered sectors, and UK-based providers of certain digital services offered in the EU must designate an EU representative under Article 26(3). UK domestic rules are outside the scope of the base.

Is my small business exempt from NIS2?

Usually, yes: small and micro enterprises fall below the size cap of Article 2(1). The exceptions are listed in Article 2(2) to (4), including electronic communications providers, trust service providers, TLD registries, DNS service providers, domain name registration services and entities specifically identified by a Member State.

What counts as a medium-sized enterprise for NIS2?

The Recommendation 2003/361/EC definition: fewer than 250 staff and turnover not exceeding EUR 50 million and/or balance sheet not exceeding EUR 43 million, while not being small (fewer than 50 staff and EUR 10 million or less). Entities above those medium ceilings are also covered.

Do we need an EU representative for NIS2?

Only if you are one of the Article 26(1)(b) digital providers (for instance a cloud, data centre, managed service or managed security service provider), are not established in the EU, and offer services in the EU. The representative must be established in a Member State where you offer services.

Which Member State supervises a group operating in several EU countries?

As a rule, each Member State where the entity is established. Article 26 sets exceptions: certain digital providers fall under the Member State of their main EU establishment, telecoms providers under the Member State where they provide services, and public administration under the Member State that established them.

Get the Kopik newsletter

New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.

By subscribing you agree to receive our newsletter. We never share your address.