Subject matter, scope, essential and important entities
Who NIS2 binds: the sectors of Annexes I and II filtered by the size-cap rule, the categorical inclusions regardless of size, and the split between essential and important entities that drives the supervision regime.
Article 1 — Subject matter
Verbatim from EUR-Lex (Directive (EU) 2022/2555 (NIS2) 02022L2555-20221227), via the Publications Office Cellar API.
1. This Directive lays down measures that aim to achieve a high common level of cybersecurity across the Union, with a view to improving the functioning of the internal market.
- (a) obligations that require Member States to adopt national cybersecurity strategies and to designate or establish competent authorities, cyber crisis management authorities, single points of contact on cybersecurity (single points of contact) and computer security incident response teams (CSIRTs);
- (b) cybersecurity risk-management measures and reporting obligations for entities of a type referred to in Annex I or II as well as for entities identified as critical entities under Directive (EU) 2022/2557;
- (c) rules and obligations on cybersecurity information sharing;
- (d) supervisory and enforcement obligations on Member States.
Article 2 — Scope
Verbatim from EUR-Lex (Directive (EU) 2022/2555 (NIS2) 02022L2555-20221227), via the Publications Office Cellar API.
1. This Directive applies to public or private entities of a type referred to in Annex I or II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, and which provide their services or carry out their activities within the Union.
Article 3(4) of the Annex to that Recommendation shall not apply for the purposes of this Directive.
2. Regardless of their size, this Directive also applies to entities of a type referred to in Annex I or II, where:
- (a) services are provided by:
- (b) the entity is the sole provider in a Member State of a service which is essential for the maintenance of critical societal or economic activities;
- (c) disruption of the service provided by the entity could have a significant impact on public safety, public security or public health;
- (d) disruption of the service provided by the entity could induce a significant systemic risk, in particular for sectors where such disruption could have a cross-border impact;
- (e) the entity is critical because of its specific importance at national or regional level for the particular sector or type of service, or for other interdependent sectors in the Member State;
- (f) the entity is a public administration entity:
- (i) of central government as defined by a Member State in accordance with national law; or
- (ii) at regional level as defined by a Member State in accordance with national law that, following a risk-based assessment, provides services the disruption of which could have a significant impact on critical societal or economic activities.
3. Regardless of their size, this Directive applies to entities identified as critical entities under Directive (EU) 2022/2557.
4. Regardless of their size, this Directive applies to entities providing domain name registration services.
- (a) public administration entities at local level;
- (b) education institutions, in particular where they carry out critical research activities.
6. This Directive is without prejudice to the Member States’ responsibility for safeguarding national security and their power to safeguard other essential State functions, including ensuring the territorial integrity of the State and maintaining law and order.
7. This Directive does not apply to public administration entities that carry out their activities in the areas of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences.
8. Member States may exempt specific entities which carry out activities in the areas of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences, or which provide services exclusively to the public administration entities referred to in paragraph 7 of this Article, from the obligations laid down in Article 21 or 23 with regard to those activities or services. In such cases, the supervisory and enforcement measures referred to in Chapter VII shall not apply in relation to those specific activities or services. Where the entities carry out activities or provide services exclusively of the type referred to in this paragraph, Member States may decide also to exempt those entities from the obligations laid down in Articles 3 and 27.
10. This Directive does not apply to entities which Member States have exempted from the scope of Regulation (EU) 2022/2554 in accordance with Article 2(4) of that Regulation.
11. The obligations laid down in this Directive shall not entail the supply of information the disclosure of which would be contrary to the essential interests of Member States’ national security, public security or defence.
12. This Directive applies without prejudice to Regulation (EU) 2016/679, Directive 2002/58/EC, Directives 2011/93/EU ( ^1 ) and 2013/40/EU ( ^2 ) of the European Parliament and of the Council and Directive (EU) 2022/2557.
13. Without prejudice to Article 346 TFEU, information that is confidential pursuant to Union or national rules, such as rules on business confidentiality, shall be exchanged with the Commission and other relevant authorities in accordance with this Directive only where that exchange is necessary for the application of this Directive. The information exchanged shall be limited to that which is relevant and proportionate to the purpose of that exchange. The exchange of information shall preserve the confidentiality of that information and protect the security and commercial interests of entities concerned.
14. Entities, the competent authorities, the single points of contact and the CSIRTs shall process personal data to the extent necessary for the purposes of this Directive and in accordance with Regulation (EU) 2016/679, in particular such processing shall rely on Article 6 thereof.
The processing of personal data pursuant to this Directive by providers of public electronic communications networks or providers of publicly available electronic communications services shall be carried out in accordance with Union data protection law and Union privacy law, in particular Directive 2002/58/EC.
Article 3 — Essential and important entities
Verbatim from EUR-Lex (Directive (EU) 2022/2555 (NIS2) 02022L2555-20221227), via the Publications Office Cellar API.
1. For the purposes of this Directive, the following entities shall be considered to be essential entities:
- (a) entities of a type referred to in Annex I which exceed the ceilings for medium-sized enterprises provided for in Article 2(1) of the Annex to Recommendation 2003/361/EC;
- (b) qualified trust service providers and top-level domain name registries as well as DNS service providers, regardless of their size;
- (c) providers of public electronic communications networks or of publicly available electronic communications services which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC;
- (d) public administration entities referred to in Article 2(2), point (f)(i);
- (e) any other entities of a type referred to in Annex I or II that are identified by a Member State as essential entities pursuant to Article 2(2), points (b) to (e);
- (f) entities identified as critical entities under Directive (EU) 2022/2557, referred to in Article 2(3) of this Directive;
- (g) if the Member State so provides, entities which that Member State identified before 16 January 2023 as operators of essential services in accordance with Directive (EU) 2016/1148 or national law.
2. For the purposes of this Directive, entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1 of this Article shall be considered to be important entities. This includes entities identified by Member States as important entities pursuant to Article 2(2), points (b) to (e).
3. By 17 April 2025, Member States shall establish a list of essential and important entities as well as entities providing domain name registration services. Member States shall review and, where appropriate, update that list on a regular basis and at least every two years thereafter.
4. For the purpose of establishing the list referred to in paragraph 3, Member States shall require the entities referred to in that paragraph to submit at least the following information to the competent authorities:
- (a) the name of the entity;
- (b) the address and up-to-date contact details, including email addresses, IP ranges and telephone numbers;
- (c) where applicable, the relevant sector and subsector referred to in Annex I or II; and
- (d) where applicable, a list of the Member States where they provide services falling within the scope of this Directive.
The entities referred to in paragraph 3 shall notify any changes to the details submitted pursuant to the first subparagraph of this paragraph without delay, and, in any event, within two weeks of the date of the change.
The Commission, with the assistance of the European Union Agency for Cybersecurity (ENISA), shall without undue delay provide guidelines and templates regarding the obligations laid down in this paragraph.
Member States may establish national mechanisms for entities to register themselves.
- (a) the Commission and the Cooperation Group of the number of essential and important entities listed pursuant to paragraph 3 for each sector and subsector referred to in Annex I or II; and
- (b) the Commission of relevant information about the number of essential and important entities identified pursuant to Article 2(2), points (b) to (e), the sector and subsector referred to in Annex I or II to which they belong, the type of service that they provide, and the provision, from among those laid down in Article 2(2), points (b) to (e), pursuant to which they were identified.
6. Until 17 April 2025 and upon request of the Commission, Member States may notify the Commission of the names of the essential and important entities referred to in paragraph 5, point (b).
Sources
Meta
All text above is reproduced verbatim from the EUR-Lex consolidated NIS2 Directive (CELEX 02022L2555-20221227), extracted mechanically via the Publications Office Cellar API — see tools/eur-lex/build_eu_nis2.py, whose verify mode confirms every source paragraph appears verbatim. Do not hand-edit. Of the corrigenda postdating the consolidation only OJ L 2023/90206 covers English, changing one word in Article 19(1) — not extracted here. Anchors: official ELI ids (e.g. {#art_21}, valid as EUR-Lex HTML fragments) plus derived paragraph/point anchors from printed labels (e.g. {#art_21-2-d}).