
Blog Post
The Cybersecurity Directive That Reached Ten Times More Entities
September 27, 2026
The headline change in Europe's network security directive is scope. Directive (EU) 2022/2555 reaches an estimated hundred and sixty thousand entities across eighteen sectors, roughly ten times what its predecessor covered.
The more consequential change is who decides. Under the previous regime a member state identified operators of essential services individually, through an assessment of criticality and dependency. The process was removed, and the tests are now self-applying, so nobody writes to tell an organization it is in scope.
What Changed About the Mechanism?
The classification moved from the regulator to the entity, which is a structural change rather than an expansion.
The earlier directive designated operators of essential services through a national process that weighed criticality, dependency and potential impact, and treated digital service providers as a narrow separate category. The current directive eliminates that distinction and classifies every in-scope organization as essential or important on the strength of two facts, being the sector it operates in and its size.
Which Explains the Awareness Figures
Around forty percent of newly in-scope organizations were not aware of their obligations as the transposition deadline passed. Read as negligence that is surprising, and read as a consequence of the design it is not, since no notification exists for the absence to be a failure of.
Is It a Directive or a Regulation?
A directive, and this distinction does more work here than anywhere else in the current European cyber framework.

The operational resilience regulation and the product security regulation apply directly and read the same in every member state. A directive requires transposition into national law, so the text that determines whether an organization is in scope is the national implementation rather than the European instrument. Reading the directive alone can produce the wrong answer.
Which Multiplies the Problem
Most member states missed the transposition deadline, so national texts arrived late, unevenly, and with local variation. An organization established in several countries has to apply several tests, and may be in scope in one jurisdiction and outside it in another on identical facts.
Where Is the Test Harder Than It Looks?
Three places, and none of them is the sector list everybody publishes.
- The digital infrastructure category: Expansive enough to capture cloud services, data centers, content delivery and managed service providers, many of which were outside the previous regime entirely.
- The size test: Two thresholds applied with either-or logic on headcount or financial figures, so a small team with substantial revenue qualifies.
- The national text: Which governs, and which may reach further than the directive's own lists.
Managed service providers deserve particular attention, because an organization providing technology services to others may be in scope for that activity while believing itself an ordinary business in an unlisted sector.
Does Failing to Self-Identify Help?
No, and it removes the only defense that would otherwise be available.
.png)
Obligations attach on the strength of the tests rather than on any recognition of them, and competent authorities retain the power to identify and designate organizations that should be in scope. So the position of an organization that never assessed itself is not neutrality, it is an unassessed exposure discovered by somebody else.
What Is the Defensible Position?
Having applied the test and recorded the reasoning, which is available whatever the conclusion. An organization that assessed itself and concluded it sits outside scope has a documented determination to produce. One that never looked has nothing, and the difference matters more than the conclusion does.
How Much Turns on Essential Versus Important?
Less than the classification effort suggests, which is worth knowing before spending time on the wrong question.
Both categories face the same substantive risk management measures. What differs is the supervision regime, with proactive supervision applying to one and largely ex-post supervision to the other, and the penalty ceilings differ accordingly. Misclassifying between the two is therefore a less serious error than missing scope altogether.
Which Reorders the Work
Establishing whether you are in scope at all is the high-value determination. Refining which tier applies matters for supervision planning and does not change what has to be implemented, and accountability under the directive lands on management in both tiers.
What Does the Supply Chain Requirement Add?
A second route into scope in practice, even where the direct test does not reach you.
In-scope entities have to address supply chain security as part of their required measures, so they ask their suppliers to demonstrate things. An organization outside scope that supplies several in-scope customers will face those requirements contractually rather than through supervision.
Which Makes the Determination Commercially Useful
A supplier able to state its own position, with reasoning, answers a customer questionnaire in an afternoon. One that cannot spends weeks and looks unprepared, and what a supplier arrangement has to specify is the process that request arrives through.
What Does an In-Scope Entity Owe?
Ten categories of risk management measure and a reporting obligation, which is worth stating because scope discussion frequently stops before it.
The measures cover risk analysis and system security policy, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, assessment of effectiveness, basic hygiene and training, cryptography, access control and asset management, and authentication. Alongside those sits a staged incident reporting duty on tight timelines.
Which Is Where the Cost Sits
Assessment of effectiveness is the one organizations underestimate, since it requires demonstrating that measures work rather than that they exist. A policy is cheap to write and expensive to evidence continuously, and verifying continuously rather than annually is the difference between the two positions.
Management Carries It Personally
Management bodies are directly accountable for approving and overseeing the measures, with authorities able to impose temporary bans on individuals from managerial functions in cases of serious negligence. A personal ban is a materially different accountability structure from a corporate penalty, and what directors need to see applies the same reasoning on the AI side.
What Should Be Established?
Four things, and the first two are the determination itself.
Which sectors the organization operates in as the national transposition defines them rather than as the directive lists them. Whether the size test is met, applying the either-or logic rather than assuming both conditions are needed. Whether any activity constitutes a managed service to third parties, since that is the commonly missed route. Then the same exercise per country of establishment, because the answer can differ. Cyber risk quantification gives the measures a value once scope is settled, and the determination has to come first.
Nobody Writes to Tell You
The scope expansion to roughly a hundred and sixty thousand entities is the headline, and the mechanism change matters more, because the previous regime had member states identify operators individually and the current one applies sector and size tests that nobody administers on your behalf. Around forty percent of newly in-scope organizations were unaware of their obligations, which follows from the design rather than from carelessness. It is a directive rather than a regulation, so the governing text is the national transposition and an organization in several countries applies several tests. Failing to self-identify removes the defense rather than the obligation, since authorities retain designation power. The high-value determination is also whether you are in scope at all rather than which tier applies. Kovrr's cyber risk quantification prices the measures once that is settled.
To see the exposure behind the measures the directive requires, book a demo with our risk experts.
NIS2 Scope FAQs
Speak to an ExpertHow many entities are in scope of NIS2?
An estimated hundred and sixty thousand across eighteen sectors, according to ENISA's investments reporting, which is roughly ten times what the predecessor directive covered. The scope figure is the headline change, while the more consequential one is that the classification mechanism moved, since the earlier regime had member states identify operators of essential services individually and the current one applies self-applying sector and size tests.
Does anyone tell you if you are in scope of NIS2?
No, and that is the design rather than an implementation failure. The earlier directive designated operators of essential services through a national process weighing criticality, dependency and impact. The current directive eliminated that and classifies every in-scope organization as essential or important on the strength of its sector and its size, so no notification exists. Around forty percent of newly in-scope organizations were unaware of their obligations as the transposition deadline passed.
Is NIS2 a directive or a regulation?
A directive, and the distinction matters more here than anywhere else in the European cyber framework. A regulation applies directly and reads the same in every member state, while a directive requires transposition into national law, so the text determining whether an organization is in scope is the national implementation rather than the European instrument. Most member states missed the transposition deadline, so national texts arrived late and with local variation.
What are the NIS2 size thresholds?
Two thresholds applied with either-or logic rather than requiring both conditions. Medium enterprises are those at fifty or more employees or ten million euro or more in turnover, and large enterprises at two hundred and fifty or more employees or fifty million euro or more. Because the logic is either-or, a small team with substantial revenue qualifies, and the national transposition governs the final answer.
What happens if you fail to self-identify under NIS2?
The obligations still attach, and competent authorities retain the power to identify and designate organizations that should be in scope. So the position of an organization that never assessed itself is not neutrality but an unassessed exposure discovered by somebody else. The defensible position is having applied the test and recorded the reasoning, which is available whatever the conclusion turns out to be.
What is the difference between essential and important entities under NIS2?
Less than the classification effort suggests. Both categories face the same substantive risk management measures, and what differs is the supervision regime, with proactive supervision applying to one and largely ex-post supervision to the other, alongside different penalty ceilings. Misclassifying between the two is therefore a less serious error than missing scope altogether, which reorders where the effort belongs.




