Skip to content

Does NIS2 Apply to You? A Two-Minute Answer

Sector, size, and the exceptions that catch small firms anyway. A plain decision path to know if you're in scope - and what to do the day you are.

Hallway with one open and one closed door

Short answer

Applicability depends on sector and size thresholds, with exceptions and contractual flow-down that can still catch small suppliers. Get a two-minute decision path before you buy a full ISMS.

Decision path

Identify sector list position, check size thresholds, check special entity types, then check customer contracts for NIS2 flow-down even if the law itself does not name you.

Flow-down is how small suppliers get NIS2-shaped requirements without appearing on the main list.

Readers skimming does nis2 apply to you often stop at definitions. The part that prevents incidents is the verification step after the change - and the habit of re-checking after the next deploy that touches the same layer.

If you are out of scope

You may still need the same baseline controls for customers and insurers.

Out of scope is not a free pass on basic hygiene - it only changes who can fine you for missing paper.

Common failure mode for does nis2 apply to you: staging looks fine, production still serves the old config because a CDN, load balancer, or second vhost was never updated. Always verify the hostname customers hit.

If you are in scope

Start with ownership, inventory, and incident reporting clocks before you buy a GRC platform.

Evidence of real controls beats a tool login nobody uses.

If this section on does nis2 apply to you becomes a recurring ticket, automate the check. Manual one-offs rot; a post-deploy assertion or weekly grade keeps the control honest.

What to do this week

  1. Map your sector and size against the current thresholds.
  2. Read top customer contracts for security flow-down language.
  3. Decide: in scope / out of scope / unsure (then counsel).
  4. If in scope or flow-down: name an owner this week.

Scope first. Spend second.

Run a free security grade on your domain · Pricing

Update log (1)

2026-06-04Editorial form rewrite for length and uniqueness.

Sources + verification

Practical guidance based on mainstream browser behavior, common reverse-proxy configuration, and widely published RFCs and vendor docs. Verify on your own stack with curl, browser devtools, and a re-scan after each change.

Keep reading

Compliance NIS2 for small teams, in plain terms 2026-04-28 Compliance NIS2 Checklist for Small Business (10 Steps) 2026-06-03 Compliance GDPR Art. 32: What "Appropriate Security" Means 2026-06-09