NIS2

NIS2: Are you in scope? Seven questions for a quick self-assessment

DEAuf Deutsch lesen →
23. Juni 2026 GARION NIS2

The NIS2 directive significantly broadens cybersecurity obligations — across more sectors and far more organisations than its predecessor. Many companies simply do not know whether they are in scope. These seven questions support an honest first self-assessment. They do not replace a legal review, but they locate where you stand.

Seven questions on scope

  1. Which sector do you operate in? NIS2 distinguishes „essential“ and „important“ entities — from energy, transport and health to digital services, postal services, waste management and food.
  2. How large is your organisation? As a rough threshold, 50 employees or EUR 10 million annual turnover. Below that, NIS2 usually does not apply — with exceptions.
  3. Is there a special status? Some entities fall under NIS2 regardless of size, for example critical infrastructure or the sole provider of a service.
  4. Are you part of a supply chain? Even if you are not directly regulated, the requirements are often passed down contractually by your customers.
  5. Which EU countries are you active in? NIS2 is transposed nationally; thresholds and deadlines can differ in detail.
  6. Do you have reporting and response processes? NIS2 requires an early warning of significant incidents within 24 hours — which presupposes prepared procedures.
  7. Is leadership involved? The directive explicitly places responsibility on management, including a duty to undergo training.

What the answers mean

Several „yes“ answers across the first three questions is a clear signal to examine scope seriously. But even a „no“ does not fully release anyone from the topic: through the supply chain (question 4), NIS2 requirements are effectively passed on — as a contract clause, an audit question, a condition for doing business.

From assessment to readiness

A self-assessment is the start, not the goal. The next step is to lay the NIS2 measures from Article 21 — risk management, incident handling, business continuity, supply-chain security, encryption, access control — against your current state and make the gaps visible.

This is exactly where the GARION NIS2 module fits in: it structures the self-assessment, documents the rationale behind each judgement, and makes the readiness status visible per area of measures. The result is a traceable state of preparation on which a well-founded decision — ideally with professional support — can be built.


Note: GARION supports preparation for the EU AI Act and related frameworks. GARION is not a substitute for legal advice, conformity assessment or certification.