Are we in scope of NIS2?
About 48 percent of companies underestimate their own regulatory exposure. That is not negligence but a consequence of the design: there is no official decision and no list you would appear on — the classification is a self-assessment, and anyone who skips it has effectively made it anyway. This check leads to a defensible answer in three steps.
Three steps. In this order.
The steps build on each other: without a sector there is no scope — with a sector, size decides, and above both stand the special cases.
Sector
Does your actual activity map to one of the 18 sectors? What counts is what you do — not what you call yourself.
Size
Headcount, revenue, and balance sheet total — including affiliated companies. This is where most misjudgments arise.
Special case
Some entities are covered regardless of size. That check skips step 2 entirely.
Supply chain
Even a clear “no” does not end here: the requirements still arrive through customer contracts.
The 18 sectors.
Annex 1 of the BSIG lists eleven sectors of high criticality, Annex 2 seven further critical sectors. Classification follows the activity actually performed.
| Sectors of high criticality (Annex 1) | Other critical sectors (Annex 2) | |
|---|---|---|
| Utilities | Energy · Drinking water · Wastewater | Waste management |
| Transport & logistics | Transport and traffic · Space | Postal and courier services |
| Finance | Banking · Financial market infrastructures | — |
| Health & government | Healthcare · Public administration | Research |
| IT & digital | Digital infrastructure · Management of ICT services (B2B) | Digital service providers |
| Industry | — | Chemicals · Food · Manufacturing |
Two rows deserve particular attention: management of ICT services (B2B) explicitly captures managed service providers and managed security service providers — the IT services industry is itself regulated for the first time. And manufacturing is broader than it sounds: it covers, among others, automotive, mechanical engineering, electrical engineering, and medical and data processing equipment.
The thresholds — and how companies miscalculate them.
The calculation follows the EU's SME definition. Meeting either of the two conditions is enough to cross the threshold.
| Classification | Employees | Revenue and balance sheet total | Consequence |
|---|---|---|---|
| Essential | 250 or more | or more than €50M revenue and more than €43M balance sheet total | Proactive supervision, up to €10M or 2% of revenue |
| Important | 50 or more | or more than €10M revenue and balance sheet total | Reactive supervision, up to €7M or 1.4% of revenue |
| Below the thresholds | fewer than 50 | and below | No direct duty — check the supply chain |
The most common calculation error: affiliated companies count toward the total. Anyone with partner or group companies adds their headcount and revenue proportionally or in full. A company with twelve employees can slide into scope through its parent — and usually does not know it.
When size plays no part.
For certain entities the size threshold is irrelevant. Anyone in these categories is in scope with a single employee.
Trust services and name infrastructure
Qualified trust service providers, top-level domain registries, and DNS service providers are covered regardless of size — they carry functions whose failure reaches far beyond their own organization.
Telecommunications
Providers of publicly available telecommunications networks and services are subject to their own size-independent rules — telecommunications law applies on top here.
Critical infrastructure and federal bodies
KRITIS operators and federal administration bodies fall under the law regardless of thresholds — and face additional, tightened requirements on top.
Sole provider in the region
Anyone who is the only provider of a service essential to society or the economy can be covered below the thresholds too. This catch-all rule is regularly overlooked.
“Out of scope” is rarely the end of the story.
Even if all three steps lead to a clear no, the check is not finished. Section 30 BSIG explicitly obliges regulated companies to manage the security of their supply chain — and the only route there runs through requirements placed on their service providers.
- Do you supply companies from one of the 18 sectors?
- Do you have access to their systems, data, or unreleased material?
- Do your contracts already contain security, reporting, or audit clauses?
- Have you been sent a security questionnaire in recent months?
The four most common misjudgments.
Each of them leads to the same outcome: a company considers itself out of scope and is not.
“We're too small.”
The threshold sits at 50 employees, not 250 — and affiliated companies count toward it. Many mid-sized firms underestimate both at the same time.
“We're not critical infrastructure.”
NIS2 has left the KRITIS concept behind. The thresholds are many times lower, and with manufacturing an entire branch of the economy has been newly added.
“We haven't heard from the BSI.”
There is no notification. The classification is a self-assessment and the registration is something you must initiate yourself — silence from the authority is not a free pass, it is merely silence.
“We'll look at that when the time comes.”
The time has come. The law has applied since December 2025 with no transition period, and both registration deadlines have passed. Every further month without a check is a month of flying blind.
Questions about the scope check.
As of August 2026.
Do working students, part-time employees, and freelancers count toward the headcount?
The calculation uses annual work units under the EU's SME definition. Part-time employees and those employed for only part of the year count pro rata; classic self-employed contractors carrying their own commercial risk generally do not. More important than these details is the second step: for affiliated companies, the figures of partner and group companies are added proportionally or in full. This is exactly where companies miscalculate most often — a subsidiary with twelve employees may well fall within scope through its parent company.
We are an IT service provider. Are we automatically in scope?
Not automatically, but considerably more likely than before. The management of ICT services in the business-to-business space — that is, managed service providers and managed security service providers — is explicitly named in the BSIG as a sector of high criticality. If you also meet the size thresholds, you are covered. If you stay below them, the regulation does not apply to you directly, but it almost certainly reaches you through your customer contracts: your regulated clients must manage the security of their IT service providers and pass the requirements on.
Our agency works for an automotive group. Does NIS2 catch up with us?
Directly, almost never — marketing, design, and film production are not NIS2 sectors. Indirectly, very much so: your client is required to assess the security of its supply chain and passes that on through questionnaires and contract clauses. In the automotive industry this rarely comes alone — TISAX® is the established form of that evidence there anyway. For agencies with access to unreleased OEM material, both requirements amount to practically the same thing: a demonstrable level of security.
What happens if we misjudge our situation?
The classification is a self-assessment — there is no official decision confirming or denying that you are in scope. That is precisely what makes it risky: anyone who believes they are out of scope and is wrong has neither registered nor reported nor implemented measures, and all three omissions carry fines independently. This is why a result of “out of scope” also belongs in writing, with a date, the sector assessment, and the figures. If your size or business model changes, the assessment is run again.
Does NIS2 also apply in Austria and Switzerland?
As an EU member state, Austria transposes the NIS2 Directive into national law; the framework of sectors, size thresholds, registration, and reporting duties matches the German one, while deadlines and responsible authorities differ. As a non-EU country, Switzerland is not bound by the directive, but has had its own reporting duty for cyberattacks on critical infrastructure since 2025. For Swiss companies, NIS2 becomes relevant above all when they supply EU clients and have to meet their supply chain requirements.
Related
NIS2 Consulting
Registration, gap analysis against Section 30 BSIG, and evidence management.
External information security officer
Who carries the implementation when nobody in-house can take the role.
ISO 27001 checklist
The ISMS that already covers the bulk of the NIS2 requirements.
TISAX® checklist
The evidence the automotive industry asks for instead of a questionnaire.