01Home02Services03About us04Pricing05Vacancies06Contact
Security & NIS2

Does my company fall under NIS2? The decision tree

3 August 2026 · 6 min read

Does my company fall under NIS2? Work through the decision tree based on your sector, your size and your role in the chain, and know where you stand by the end.

Max HoltropBy Max Holtrop

"Does my company actually fall under NIS2?" It is the question we get most often. And rightly so, because the new legislation is not equally clear for everyone. In this article we walk through a decision tree with you step by step, so that by the end you have a well-founded answer. Note: this is a practical guide, not legal advice. For full certainty we are happy to take a look with you.

What was NIS2 about again?

NIS2 is a European directive that obliges organisations to have their digital resilience demonstrably in order. The idea: the more our society runs on digital systems, the more important it is that those systems are well secured. What NIS2 exactly involves, you read in NIS2 for SMEs.

Whether you fall under it depends on three things: your sector, the size of your organisation and your role in the chain. We go through them.

Step 1: does your sector fall under NIS2?

NIS2 distinguishes "essential" and "important" sectors. Think of energy, drinking water, transport, healthcare, digital infrastructure, government services, waste management, production of certain goods, post and food.

  • Are you in such a sector? Continue to step 2.
  • Are you clearly outside it? Then the chance is small that NIS2 applies to you directly. Still, step 3 is relevant.

Step 2: how big is your organisation?

NIS2 is basically aimed at medium-sized and large organisations. The rule of thumb: from about 50 employees or an annual turnover and balance sheet total above 10 million euros.

  • Are you above that threshold and in a designated sector? Then you most likely fall under NIS2.
  • Are you below it? Then the main rule usually does not apply. But there are exceptions, and step 3 can still throw a spanner in the works.

Step 3: do you supply an organisation that falls under it?

This is the catch. Even if you are small yourself, NIS2 can affect you via the chain. Organisations that fall under NIS2 must also have the security of their suppliers in order. If you supply services or software to such a party, they will impose requirements on you.

  • Do you supply larger, regulated organisations? Count on them asking you for security measures, whether or not you formally fall under NIS2.
  • Do you only work for small clients? Then the chain obligation is less acute, but good security remains sensible.

Essential or important: does that make a difference?

If you fall under NIS2, there is a further distinction: essential or important organisations. The difference is mainly in the supervision. For essential organisations the regulator may also check in advance and actively; for important organisations that happens more often afterwards, prompted by an incident or signal.

For the measures you have to take, it makes little difference in practice: both categories must have their security demonstrably in order. So do not get lost in the question of exactly which box you fall into, but focus on the basics: those must be in place either way.

The outcome: now what?

Do you come out of the decision tree with "yes, probably" or "maybe via the chain"? Then it is smart to start now. Getting the basics in order takes time, and waiting until enforcement starts is too late. A good first step is our NIS2 checklist for SMEs: ten concrete steps to get going with.

And do you come out with "probably not"? Even then, strong security is not a luxury. The measures NIS2 asks for are simply good IT management.

Want to know for sure where you stand?

Want a well-founded answer to the question of whether your organisation falls under NIS2, and what needs to happen then? Schedule a no-obligation consultation. We go through your situation and give you clarity. Read more about our approach on NIS2 compliance.

← Back to news

Frequently asked questions

Good to know

Does my company fall under NIS2 if I have fewer than 50 employees?

Usually not on the basis of the main rule, which starts around 50 employees or 10 million euros in turnover. But you can still be affected via the chain, if you supply an organisation that does fall under NIS2.

Which sectors fall under NIS2?

Among others energy, drinking water, transport, healthcare, digital infrastructure, government, waste management, certain production, post and food. NIS2 divides these into essential and important sectors.

Can NIS2 affect me via my customers?

Yes. Organisations that fall under NIS2 must also safeguard the security of their suppliers. If you supply such a party, they will impose security requirements on you, even if you are small yourself.

What should I do if I fall under NIS2?

Start with the basics: secure sign-in, phishing protection, updates, backups and an incident plan, and record your measures. Our NIS2 checklist for SMEs helps you get going step by step.

Questions about this?

Want to spar with a specialist?

Curious what this means for your organisation? Book a no-obligation consult — we’re happy to think along.

Book a consultation →