Are You in Scope for NIS2? Essential vs Important Entities Explained
If you run an Irish business and you have been putting off the NIS2 question, this is the article to read first. Working out your NIS2 scope is the single most important step, because everything else, the security measures, the reporting duties, the potential fines, only applies once you know whether you are caught. The trouble is that the scoping rules are genuinely fiddly, and a lot of owners assume they are too small to worry about. Many of them are wrong.
NIS2 is the Network and Information Security Directive, formally Directive (EU) 2022/2555. It replaced the original NIS1 regime and dramatically expanded both the sectors covered and the number of organisations pulled in. The EU transposition deadline was 17 October 2024, and Ireland is bringing it into force through national legislation, with the National Cyber Security Centre acting as the competent authority and national CSIRT.
Most Irish SMEs still think NIS2 is a big-utility or big-telecoms problem. In reality the directive reaches into manufacturing, food, chemicals, waste, digital providers, ICT service management and more, and it applies the moment you cross a size threshold in a covered sector. If you have never actually checked, you do not yet know your answer.
Start With the Sector, Not the Size
The first question is not how big you are. It is what you do. NIS2 divides covered sectors across two annexes, and your annex shapes how you are treated.
NIS2 splits the covered sectors into Annex I, described as sectors of high criticality, and Annex II, described as other critical sectors. Annex I covers energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management on a business to business basis, public administration and space. Annex II covers postal and courier services, waste management, the manufacture of chemicals, food production and distribution, manufacturing more broadly, digital providers and research.
If your activity does not sit in either annex, you are very likely outside the direct scope. If it does, keep going, because the size test comes next and it decides a great deal.
Then Apply the Size Test
NIS2 generally uses a size cap so that, as a rule, only medium and large organisations are directly regulated. Micro and small entities are usually outside the direct net, though there are important exceptions covered below.
The bandings borrow from the standard EU definitions. A useful way to hold them in your head:
| Size band | Rough thresholds | Typical treatment |
|---|---|---|
| Large | 250 or more staff, or turnover above EUR 50m and balance sheet above EUR 43m | Essential in Annex I sectors |
| Medium | 50 to 249 staff, or turnover of EUR 10m to 50m | Important in most sectors |
| Small or micro | Below the medium thresholds | Usually outside direct scope, exceptions apply |
So a large organisation in an Annex I sector is typically an essential entity. A medium organisation in an Annex I sector is typically an important entity. A medium or larger organisation in an Annex II sector is typically an important entity. That is the core of the scoping logic.
Essential vs Important: What Actually Differs
This is where people get confused, so it is worth being precise. The labels essential and important do not describe two different rulebooks. The core security obligations, the risk management measures and the incident reporting duties, are broadly the same for both.
What differs most is supervision. Essential entities face proactive oversight: regulators can inspect and audit them without needing a specific trigger. Important entities face reactive oversight: attention typically follows evidence that something has gone wrong. In practice essential status means a heavier, more anticipatory compliance relationship, while important status means you must still meet the measures but are supervised after the fact.
The financial exposure also differs. For essential entities the maximum fines run to EUR 10m or 2 per cent of total worldwide annual turnover, whichever is higher. For important entities the ceiling is EUR 7m or 1.4 per cent of worldwide annual turnover. Either figure is more than enough to concentrate a board's attention.
The Exceptions That Catch Small Firms
Here is the part that surprises people. Some entities are in scope regardless of size, because the service they provide is judged too critical to leave to the size test.
The clearest examples sit in digital infrastructure and trust services: providers of DNS services, top level domain name registries, and qualified and non qualified trust service providers can be caught even when they are small. Certain public administration bodies are treated similarly. If you provide one of these services, do not assume the medium threshold rescues you, because it may not apply to you at all.
The lesson is simple. Run the size test, but check the exceptions before you conclude you are safe.
The Supply Chain Flow-Down
Even if you are cleanly outside the direct scope, you are not necessarily off the hook. NIS2 places real weight on supply chain security, and in scope entities are expected to manage the risk their suppliers introduce.
In practice that means an essential or important customer will push security requirements down to you through contracts, questionnaires and audits. You may find yourself asked to demonstrate the same kinds of controls the directive expects, not because the regulator is knocking, but because your customer needs to satisfy their own obligations. For a lot of Irish SMEs, this contractual flow-down will be the way NIS2 actually shows up.
If you sell into energy, health, banking, public administration or any other covered sector, treat NIS2 as a commercial issue as much as a regulatory one.
A Simple Way to Reach Your Answer
You can get to a defensible view in four steps.
- Identify your sector and check whether it appears in Annex I or Annex II.
- Work out your size band using staff numbers and financial thresholds.
- Combine the two to land on essential, important, or out of direct scope.
- Separately, list your customers in covered sectors, because their requirements may reach you regardless.
Write the reasoning down. When a customer or the NCSC asks, a short documented rationale is far more convincing than a verbal "we looked into it".
Common Mistakes
The most frequent mistake is stopping at the size test. Owners see "medium and large only" and relax, without checking either the annexes or the regardless-of-size exceptions. Both can change the answer.
A second mistake is assuming that important status means the obligations are optional or lighter. They are not. The measures are largely the same as for essential entities; only the supervision style and the fine ceilings differ.
A third mistake is ignoring the supply chain entirely. Plenty of firms that are technically out of scope will still be contractually obliged to meet NIS2 style controls because they supply someone who is in. Treating "we are not directly regulated" as "we have nothing to do" is how organisations get caught flat-footed during a customer audit.
A final mistake is leaving scoping undocumented. If your conclusion lives only in someone's head, it cannot be relied on when it matters.
How ShieldIQ Helps With NIS2 Scoping
ShieldIQ takes the guesswork out of the scoping decision by walking you through sector, size band and the regardless-of-size exceptions, then producing a clear, documented view of whether you are likely essential, important, or out of direct scope. From there the platform maps the security measures you would need and tracks your progress against them, so you move from "are we in scope" to "here is our evidence" without hiring a full compliance team.