Blog Post

The Cybersecurity Directive That Reached Ten Times More Entities

September 27, 2026

Table of Contents

The headline change in Europe's network security directive is scope. Directive (EU) 2022/2555 reaches an estimated hundred and sixty thousand entities across eighteen sectors, roughly ten times what its predecessor covered.

‍

The more consequential change is who decides. Under the previous regime a member state identified operators of essential services individually, through an assessment of criticality and dependency. The process was removed, and the tests are now self-applying, so nobody writes to tell an organization it is in scope.

‍

What Changed About the Mechanism?

‍

The classification moved from the regulator to the entity, which is a structural change rather than an expansion.

‍

The earlier directive designated operators of essential services through a national process that weighed criticality, dependency and potential impact, and treated digital service providers as a narrow separate category. The current directive eliminates that distinction and classifies every in-scope organization as essential or important on the strength of two facts, being the sector it operates in and its size.

‍

Which Explains the Awareness Figures

‍

Around forty percent of newly in-scope organizations were not aware of their obligations as the transposition deadline passed. Read as negligence that is surprising, and read as a consequence of the design it is not, since no notification exists for the absence to be a failure of.

‍

Is It a Directive or a Regulation?

‍

A directive, and this distinction does more work here than anywhere else in the current European cyber framework.

‍

Regulatory landscape table listing each applicable regime with its jurisdiction, who it applies to and the assessed exposure level
A per-jurisdiction record is the only workable shape where the scope test lives in national law rather than in a single European text.

The operational resilience regulation and the product security regulation apply directly and read the same in every member state. A directive requires transposition into national law, so the text that determines whether an organization is in scope is the national implementation rather than the European instrument. Reading the directive alone can produce the wrong answer.

‍

Which Multiplies the Problem

‍

Most member states missed the transposition deadline, so national texts arrived late, unevenly, and with local variation. An organization established in several countries has to apply several tests, and may be in scope in one jurisdiction and outside it in another on identical facts.

‍

Where Is the Test Harder Than It Looks?

‍

Three places, and none of them is the sector list everybody publishes.

‍

  • The digital infrastructure category: Expansive enough to capture cloud services, data centers, content delivery and managed service providers, many of which were outside the previous regime entirely.
  • The size test: Two thresholds applied with either-or logic on headcount or financial figures, so a small team with substantial revenue qualifies.
  • The national text: Which governs, and which may reach further than the directive's own lists.

‍

Managed service providers deserve particular attention, because an organization providing technology services to others may be in scope for that activity while believing itself an ordinary business in an unlisted sector.

‍

Does Failing to Self-Identify Help?

‍

No, and it removes the only defense that would otherwise be available.

‍

Peer incident view filtered by industry, country and revenue band showing comparable events at similar organizations
Sector and size are the two facts the scope test turns on, and they are the same two facts a peer comparison is built from.

Obligations attach on the strength of the tests rather than on any recognition of them, and competent authorities retain the power to identify and designate organizations that should be in scope. So the position of an organization that never assessed itself is not neutrality, it is an unassessed exposure discovered by somebody else.

‍

What Is the Defensible Position?

‍

Having applied the test and recorded the reasoning, which is available whatever the conclusion. An organization that assessed itself and concluded it sits outside scope has a documented determination to produce. One that never looked has nothing, and the difference matters more than the conclusion does.

‍

How Much Turns on Essential Versus Important?

‍

Less than the classification effort suggests, which is worth knowing before spending time on the wrong question.

‍

Both categories face the same substantive risk management measures. What differs is the supervision regime, with proactive supervision applying to one and largely ex-post supervision to the other, and the penalty ceilings differ accordingly. Misclassifying between the two is therefore a less serious error than missing scope altogether.

‍

Which Reorders the Work

‍

Establishing whether you are in scope at all is the high-value determination. Refining which tier applies matters for supervision planning and does not change what has to be implemented, and accountability under the directive lands on management in both tiers.

‍

What Does the Supply Chain Requirement Add?

‍

A second route into scope in practice, even where the direct test does not reach you.

‍

In-scope entities have to address supply chain security as part of their required measures, so they ask their suppliers to demonstrate things. An organization outside scope that supplies several in-scope customers will face those requirements contractually rather than through supervision.

‍

Which Makes the Determination Commercially Useful

‍

A supplier able to state its own position, with reasoning, answers a customer questionnaire in an afternoon. One that cannot spends weeks and looks unprepared, and what a supplier arrangement has to specify is the process that request arrives through.

‍

What Does an In-Scope Entity Owe?

‍

Ten categories of risk management measure and a reporting obligation, which is worth stating because scope discussion frequently stops before it.

‍

The measures cover risk analysis and system security policy, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, assessment of effectiveness, basic hygiene and training, cryptography, access control and asset management, and authentication. Alongside those sits a staged incident reporting duty on tight timelines.

‍

Which Is Where the Cost Sits

‍

Assessment of effectiveness is the one organizations underestimate, since it requires demonstrating that measures work rather than that they exist. A policy is cheap to write and expensive to evidence continuously, and verifying continuously rather than annually is the difference between the two positions.

‍

Management Carries It Personally

‍

Management bodies are directly accountable for approving and overseeing the measures, with authorities able to impose temporary bans on individuals from managerial functions in cases of serious negligence. A personal ban is a materially different accountability structure from a corporate penalty, and what directors need to see applies the same reasoning on the AI side.

‍

What Should Be Established?

‍

Four things, and the first two are the determination itself.

‍

Which sectors the organization operates in as the national transposition defines them rather than as the directive lists them. Whether the size test is met, applying the either-or logic rather than assuming both conditions are needed. Whether any activity constitutes a managed service to third parties, since that is the commonly missed route. Then the same exercise per country of establishment, because the answer can differ. Cyber risk quantification gives the measures a value once scope is settled, and the determination has to come first.

‍

Nobody Writes to Tell You

‍

The scope expansion to roughly a hundred and sixty thousand entities is the headline, and the mechanism change matters more, because the previous regime had member states identify operators individually and the current one applies sector and size tests that nobody administers on your behalf. Around forty percent of newly in-scope organizations were unaware of their obligations, which follows from the design rather than from carelessness. It is a directive rather than a regulation, so the governing text is the national transposition and an organization in several countries applies several tests. Failing to self-identify removes the defense rather than the obligation, since authorities retain designation power. The high-value determination is also whether you are in scope at all rather than which tier applies. Kovrr's cyber risk quantification prices the measures once that is settled.

‍

To see the exposure behind the measures the directive requires, book a demo with our risk experts.

Shalom Bublil

Kovrr Co-founder & Chief Product Officer

NIS2 Scope FAQs

Speak to an Expert

How many entities are in scope of NIS2?

Does anyone tell you if you are in scope of NIS2?

Is NIS2 a directive or a regulation?

What are the NIS2 size thresholds?

What happens if you fail to self-identify under NIS2?

What is the difference between essential and important entities under NIS2?