Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk When should a company assume it is in…
Governance, Ownership & Risk

When should a company assume it is in scope of NIS2 even if it is not a large enterprise?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: Governance, Ownership & Risk

A company should assume possible NIS2 scope when it operates in a high criticality or other critical sector and meets the relevant size thresholds, or when sector-specific exceptions apply. Some entities are in scope regardless of size, and national authorities can also designate additional entities if service disruption could affect public safety, security, or health.

When a Non-Large Business Should Still Treat NIS2 as a Possibility

NIS2 scope is not decided by headcount alone. A company may need to treat itself as potentially in scope if it operates in an essential or important sector, falls within a size threshold, or sits inside a category that is covered regardless of size. The key mistake is assuming that “small” automatically means “out.” The legal test is activity, sector, and in some cases national designation, not just employee count.

That matters because scope uncertainty changes governance decisions early: who owns the assessment, whether contracts and incident processes need review, and whether the company should prepare for regulatory obligations before a formal determination. The NIS2 Directive is the authoritative starting point, but companies still need to map the legal text to their actual business model and operating footprint. In practice, many organisations discover NIS2 exposure only after a customer, regulator, or sector adviser asks for a formal scope assessment.

The practical question is not “Are we a large enterprise?” but “Do we perform a service or function that the directive treats as materially important, or that a national authority can designate because disruption would matter?”

How NIS2 Scope Is Assessed in Practice

NIS2 scope is usually assessed by starting with the company’s activity, then checking the sector list, then checking whether size thresholds apply, and finally testing whether any exception or designation rule changes the result. That sequence matters because a company can be in scope even when it is not large, and a company can also be out of scope on size but still in scope because the sector is specifically covered.

For practitioners, the useful approach is to document three things: what the company actually does, where it does it, and which legal entity or service line performs the regulated activity. That distinction matters when a group has multiple subsidiaries, outsourced operations, or shared service arrangements. A small operating company can be exposed even if the parent group is much larger, and the opposite can also be true.

National implementation also matters. NIS2 is an EU directive, but the precise designation process and supervisory expectations can vary by member state. That means a company should not rely on a generic “not large enough” assumption without checking local transposition rules and any sector guidance from competent authorities. For that reason, the legal text should be read alongside the relevant national guidance, not in isolation.

  • Check whether the company belongs to an Annex sector or a sector covered by national implementation.
  • Separate the regulated entity from the wider corporate group.
  • Review whether the activity is performed directly or through a supplier, affiliate, or shared service model.
  • Test whether size thresholds apply at entity level or whether an exception removes the size filter.

When the business model is highly interdependent, scope analysis should also consider whether a service interruption would create broader safety or public-interest consequences. That is where designation risk becomes relevant. This guidance breaks down when a company’s legal structure, cross-border footprint, or regulated service model is not clearly mapped to a single operating entity.

Scope Traps, Exceptions, and Edge Cases That Change the Answer

Tighter scope analysis often increases compliance effort, but it reduces the risk of missing an entity that is legally covered despite being operationally small.

One common edge case is the small specialist provider that supports a covered sector through a critical service chain. Another is the company that is below the usual threshold but falls into a category that remains in scope because the service is strategically important or because national rules add more entities. There is also a governance trap where teams look only at corporate size and ignore whether a particular subsidiary, branch, or regulated offering is the real subject of the law.

There is no single universal shortcut here. The consensus position is that size is a filter, not a complete answer. The non-consensus area is how aggressively companies should pre-classify themselves when their status is ambiguous. NHI Management Group’s view is that ambiguous cases should be treated as provisional scope until the legal and sector tests are completed, because the downside of delayed classification is usually worse than the cost of an early review.

Companies should also remember that “in scope” is not only about current operations. Mergers, new services, and sector expansion can bring a previously exempt business into scope without any obvious change in headcount. If the business model is changing, the scope question should be reopened rather than reused from last year’s compliance review. In practice, the most expensive mistakes happen when teams assume yesterday’s size profile still answers today’s regulatory question.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIS2 provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
NIS2Article 2 — ScopeDefines which entities fall under NIS2, including size and sector conditions.
Article 3 — Essential and important entitiesCovers entity categories and designation logic that can apply beyond simple size tests.
Annex I — High-criticality sectorsLists sectors where companies may be in scope even when they are not large enterprises.
Recommendation — Map each legal entity and service line to Article 2 before assuming exclusion. Test whether the entity meets essential or important status, including any designation triggers. Check Annex I sectors first when assessing whether a smaller company is in scope.

Practitioner Guidance

What to prioritise: Treat scope as a legal-entity and activity question first, not a finance or HR question. The right first step is to identify which entity actually delivers the service, then test that entity against sector and threshold rules.

What to verify: Verify whether any sector-specific rule removes the size test, and whether a national authority can designate the entity even if it is not large. If the answer is unclear, do not collapse the uncertainty into an “out of scope” assumption.

Decision rule: If the company provides a service that would be materially disruptive if interrupted, or if the entity sits in a covered sector with special treatment, move to formal scope review rather than waiting for a threshold confirmation.

Practitioner takeaway: The safest operating assumption is not that small companies are exempt, but that scope depends on the regulated activity and the legal entity carrying it out.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org